
3
To log category information, select the Modify 'cs-uri' field checkbox and configure the necessary option
or rules on your appliance.
This option is available for backwards compatibility with McAfee Web Gateway 6.x appliances when
the ICAP(S) Server is configured. If you want to use this option with a McAfee Web Gateway 7.x
appliance, you need to configure a rule that adds outgoing ICAP headers with category and block
information for a policy. To configure rules and policies, see the McAfee Web Gateway product
documentation for your appliance.
Example modified cs-uri Microsoft ISA Server log field:
x-attr:"bu" x-filter-result:0 http://www.example.com
where:
x-attr:”bu” = category information
“bu” = the category (which is Business)
x-filter-result:0 = the action taken
0 = there was no action taken (such as block, warn, or allow)
4
To log connection debug information, select the Trace Connections checkbox. Information about what
the ICAP plugin receives from the McAfee Web Gateway appliance and returns to the Microsoft ISA
Server is logged to a file stored in the specified directory.
• This setting is not shared across an array. Configure this option on each member of
the array when you want debugging enabled on the other members.
• Enabling debugging on the plugin does not enable debugging on the ICAP server.
Logs stored in the directory are not automatically deleted. Each time the Trace connections option
is enabled (either through a service restart or disabling and then re-enabling it), a new file with a
GMT time stamp is created.
Configure host bypass
Configure the host names, IP addresses, or domain names that will bypass filtering so that requests to
those names and addresses are always allowed.
Task
1
Open the plugin settings:
a
In the Microsoft ISA Server management console, select Arrays | [your array] | Configuration | Add-ins,
then click the Web Filters tab.
b
Select the appropriate plugin.
c
Right-click the plugin and select Properties.
2
Click the Bypass List tab.
3
In the Hosts to bypass field, enter one host per line.
Enter an exact host name, IP address, or domain name using the examples below as guidelines.
Wildcards are not valid (entering *example.com or example.com does not include all example.com
domains).
3
ICAP plugin
Configure the ICAP plugin for a McAfee Web Gateway 7.x appliance
18
McAfee
®
Plugins for Microsoft ISA Server 1.4.0 Software Product Guide
Comentários a estes Manuais