The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing blocked-by-proxy detection configuration using the CLI

Prev Next

This topic describes how to view the blocked-by-proxy detection configuration settings.

  • To view the basic blocked-by-proxy detection settings, use the following command:

    show swg config
  • To view the option for custom wait and the option for custom subject lines for emailed notifications of blocked traffic events, use the following command:

    show fenotify preferences bbp

The following list describes the command output fields that pertain to blocked-by-proxy detection.

SWG Block-By-Proxy Enabled

This field displays no (disabled) or yes (enabled). By default, blocked-by-proxy detection does is disabled.

Use the swg block-by-proxy enable command to enable blocked-by-proxy detection.

Use the no swg block-by-proxy enable command to disable detection.

SWG Blocked‑by‑Proxy Match String

This field displays the text string that the blocked-by-proxy detection mechanism looks for to detect blocking actions by the Web proxy. The default setting is __FIREEYE_BLOCK_BY_PROXY__, but you must configure this setting to match the string used by the Web proxy.

Use the swg block-by-proxy match-string <text> command to specify the text string that the Web proxy has been configured to insert into block pages sent to affected Web clients.

Wait for Blocked‑by‑Proxy Confirmation

This field displays no (use the default wait time) or yes (use the specified custom wait time). This setting is disabled by default.

Use the fenotify preferences bbp enable command to enable a custom wait time.

Use the no fenotify preferences bbp enable command to use the default wait time.

Max Wait Time for Blocked-by-Proxy (sec)

This field displays the number of seconds that the blocked-by-proxy detection mechanism waits for confirmation of a Web proxy blocking action. The default wait time is 10 seconds.

You can use the fenotify preferences bbp max‑time‑wait <seconds> command to change the wait time to a value from 1 to 99.

Note

The value you configure for this setting is not used unless Wit for Blocked-by-Proxy Confirmation is enabled.

Email Subject Line Prefix for Blocked

This field displays the subject line used in emailed notifications of Infection Match or Malware Callback events that were blocked by the Web proxy. The default subject line is BLOCKED‑BY‑PROXY.

You can use the fenotify preferences bbp subject-desc blocked <text> command to change the text of the subject line. If <text> contains space characters, enclose the string within double quotation marks.

Email Subject Line Prefix for Non-Blocked

This field displays the subject line used in emailed notifications of Infection Match or Malware Callback events that were blocked but have not been confirmed as blocked by the Web proxy. The default subject line is NOT‑BLOCKED‑BY‑PROXY.

You can use the fenotify preferences bbp subject‑desc not‑blocked <text> command to change the text of the subject line. If <text> contains space characters, enclose the string within double quotation marks.

Prerequisites

  • Admin access to the Network Security appliance CLI.

To view blocked-by-proxy notification preferences:
  1. Go to CLI enable mode.

    hostname > enable
  2. View the basic configuration for blocked-by-proxy detection.

    In the following example, blocked-by-proxy detection is enabled and the Web proxy inserts the string "_BLUECOAT_BBP_" into block pages it sends to affected Web clients.

    hostname # show swg config
    FireEye Secure Web Gateway Configuration:
            SWG Scan Enabled:                no
            SWG scan malicious url lookback: 3600
            SWG scan callback url lookback:  3600
            SWG Block-By-Proxy Enabled:      yes
            SWG Block-By-Proxy match string: _BLUECOAT_BBP_
  3. View the complete configuration for blocked-by-proxy detection.

    In the following example, blocked-by-proxy detection is enabled and uses the match string _BlueCoat_BBP_ to identify block pages sent by the Web proxy. The option to use a custom wait time is enabled, and a wait time of 15 seconds is used in place of the default wait time of 10 seconds. Emailed notifications of blocking actions use customized subject lines.

    hostname # show fenotify preferences bbp 
    Block-by-proxy Related  Notification Settings:
    ===================================================
    FireEye Secure Web Gateway Configuration Related Settings:
    	  SWG Scan Enabled:                no
             SWG Block-By-Proxy Enabled:      yes
             SWG scan malicious url lookback: 3600
             SWG scan callback url lookback:  3600
             SWG Block-By-Proxy match string: _BLUECOAT_BBP_
    Wait for Blocked-By-Proxy Confirmation:                             yes
    Max Wait Time for Blocked-By-Proxy Confirmation (sec):               15
    EMail Subject Line Prefix for Blocked:              Blocked by BlueCoat
    EMail Subject Line Prefix for Non-Blocked:           Blocked-by-FireEye
    ===================================================