You can configure the Network Security appliance to check for new URL categories by using the appliance CLI or appliance Web UI:
A third-party URL categorization database allows you to control which websites and website categories can be whitelisted based on SSL interception. This database classifies a variety of URLs into different categories, such as careers, arts, sports, and shopping. Each entry in the URL set can include the URL and metadata (for example, URL categories and category groups). When the latest URL categories are downloaded from the third-party URL categorization database, you can enable the relevant whitelist categories to ensure that sensitive data from trusted websites is not decrypted.
You can specify how often the latest URL categories are downloaded from the third-party URL categorization database. You can also immediately download the latest URL categories from the third-party URL categorization database.
Note
You must whitelist the zvelo.com domain that is used for the third-party URL categorization database to support both HTTPS and DNS requests.
Automatic updates of URL categories are disabled by default.
Prerequisites
Administrator access to the Network Security appliance
Verify that the operational mode for inline deployment on a network port pair is configured by using the
show policymgr interfacescommand. For details about how to configure inline operational modes, see Configuring inline operational modes.You have imported the public and private keys for a trusted SSL interception CA certificate and an untrusted SSL interception CA certificate. For details about how to import the SSL CA certificate, see Importing an SSL CA certificate using the Web UI or Importing an SSL interception CA certificate using the CLI.
You have exported the public key issuer certificate that is trusted by a trusted public CA or that acts as an untrusted certificate. For details about how to export the public key for an SSL CA certificate, see Exporting an SSL CA certificate using the Web UI.
You have configured the inbound and outbound SSL interception connections that are part of the advanced SSL settings. For details about how to configure the advanced SSL settings, see Configuring advanced SSL settings for SSL Interception using the Web UI or Configuring advanced SSL settings for SSL interception using the CLI.