The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring blocked-by-proxy detection using the CLI

Prev Next

This procedure describes how to configure the blocked-by-proxy detection feature and feature options. The feature is disabled by default.

Prerequisites

  • The Network Security appliance is monitoring traffic that is filtered by a supported Web proxy product.

  • The Web proxy is configured to include an identifying text string at the top of the block page served to affected Web clients. You will need to configure the blocked-by-proxy detection feature to match this text string when it parses traffic.

    Important

    The text string that identifies Web proxy block pages must be unique across your network traffic.

  • Admin access to the Network Security appliance CLI.

To configure blocked-by-proxy configuration:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable the appliance to detect traffic blocked by a Web proxy:

    hostname (config) # swg scan block-by-proxy enable
  3. Specify the unique text string that the Web proxy inserts at the top of the block pages it serves to affected Web clients. The Network Security appliance scans for this string to detect traffic that was blocked by the Web proxy.

    The default match string is __FIREEYE_BLOCK_BY_PROXY__. You must configure this setting to match the Web proxy block page. The following example configures the appliance to look for the string _BLUECOAT_BBP_:

    hostname (config) # swg scan block-by-proxy match-string _BLUECOAT_BBP_
  4. (Optional) Configure a custom subject line for emailed notifications of blocking actions taken by the Web proxy.

    The following example configures the custom subject line Blocked by BlueCoat to be used in place of the default subject line BLOCKED‑BY‑PROXY. Because the string includes spaces, it is enclosed in double quotation marks.

    hostname (config) # fenotify preferences bbp subject-desc blocked "Blocked by BlueCoat"
  5. (Optional) Configure a custom subject line for emailed notifications of blocking actions taken by the Network Security appliance.

    The following example configures the custom subject line Blocked-by-FireEye to be used in place of the default subject line NOT‑BLOCKED‑BY‑PROXY:

    hostname (config) # fenotify preferences bbp subject‑desc not‑blocked Blocked-by-FireEye
  6. (Optional) Enable and configure a custom wait time for the blocked-by-proxy detection feature. The option is disabled by default, and the default wait time of 10 seconds is used.

    hostname (config) # fenotify preferences bbp enable
    hostname (config) # fenotify preferences bbp max-time-wait 15
  7. Verify your changes.

    hostname (config) # show swg config
    hostname (config) # show fenotify preferences bbp
  8. Save your changes.

    hostname (config) # write memory

Example CLI Command Sequence

The following example shows the CLI commands that configure blocked-by-proxy detection and all options:

enable
configure terminal
swg scan block-by-proxy enable
swg scan block-by-proxy match-string _BLUECOAT_BBP_
fenotify preferences bbp subject-desc blocked "Blocked by BlueCoat"
fenotify preferences bbp subject-desc no-blocked Blocked-by-FireEye
fenotify preferences bbp enable
fenotify preferences bbp max-time-wait 15
show swg config
show fenotify preferences bbp
write memory