This procedure describes how to configure the blocked-by-proxy detection feature and feature options. The feature is disabled by default.
Prerequisites
The Network Security appliance is monitoring traffic that is filtered by a supported Web proxy product.
The Web proxy is configured to include an identifying text string at the top of the block page served to affected Web clients. You will need to configure the blocked-by-proxy detection feature to match this text string when it parses traffic.
Important
The text string that identifies Web proxy block pages must be unique across your network traffic.
Admin access to the Network Security appliance CLI.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable the appliance to detect traffic blocked by a Web proxy:
hostname (config) # swg scan block-by-proxy enable
Specify the unique text string that the Web proxy inserts at the top of the block pages it serves to affected Web clients. The Network Security appliance scans for this string to detect traffic that was blocked by the Web proxy.
The default match string is
__FIREEYE_BLOCK_BY_PROXY__. You must configure this setting to match the Web proxy block page. The following example configures the appliance to look for the string_BLUECOAT_BBP_:hostname (config) # swg scan block-by-proxy match-string _BLUECOAT_BBP_
(Optional) Configure a custom subject line for emailed notifications of blocking actions taken by the Web proxy.
The following example configures the custom subject line Blocked by BlueCoat to be used in place of the default subject line BLOCKED‑BY‑PROXY. Because the string includes spaces, it is enclosed in double quotation marks.
hostname (config) # fenotify preferences bbp subject-desc blocked "Blocked by BlueCoat"
(Optional) Configure a custom subject line for emailed notifications of blocking actions taken by the Network Security appliance.
The following example configures the custom subject line Blocked-by-FireEye to be used in place of the default subject line NOT‑BLOCKED‑BY‑PROXY:
hostname (config) # fenotify preferences bbp subject‑desc not‑blocked Blocked-by-FireEye
(Optional) Enable and configure a custom wait time for the blocked-by-proxy detection feature. The option is disabled by default, and the default wait time of 10 seconds is used.
hostname (config) # fenotify preferences bbp enable hostname (config) # fenotify preferences bbp max-time-wait 15
Verify your changes.
hostname (config) # show swg config hostname (config) # show fenotify preferences bbp
Save your changes.
hostname (config) # write memory
Example CLI Command Sequence
The following example shows the CLI commands that configure blocked-by-proxy detection and all options:
enable configure terminal swg scan block-by-proxy enable swg scan block-by-proxy match-string _BLUECOAT_BBP_ fenotify preferences bbp subject-desc blocked "Blocked by BlueCoat" fenotify preferences bbp subject-desc no-blocked Blocked-by-FireEye fenotify preferences bbp enable fenotify preferences bbp max-time-wait 15 show swg config show fenotify preferences bbp write memory