The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling and configuring blocked-by-proxy detection using the Web UI

Prev Next

Follow these steps to enable and configure blocked-by-proxy detection using the Web UI. The feature is disabled by default. The default Web proxy block page identifier (that the feature uses to find Web proxy block pages) is __FIREEYE_BLOCK_BY_PROXY__.

Note

The following customizations can be configured using the CLI only:

  • Custom subject lines for emailed notifications

  • Customized detection wait time

Prerequisites

  • The Network Security appliance is monitoring traffic that is filtered by a supported Web proxy product.

  • The Web proxy is configured to include an identifying text string at the top of the block page served to affected Web clients. You will need to configure the blocked-by-proxy detection feature to match this text string when it parses traffic.

    Important

    The text string that identifies Web proxy block pages must be unique across your network traffic.

  • Admin access to the Network Security appliance Web UI.

To enable and configure blocked-by-proxy detection:
  1. Choose Settings > Inline Operational Modes.

  2. To enable blocked-by-proxy detection, select the Enable Block By Proxy checkbox in the Block By Proxy Settings panel.

  3. To specify the text string that the appliance uses to detect traffic that was blocked by the Web proxy, change the text in the Match String field in the Block By Proxy Settings panel.

  4. Click Update.