This topic describes how to view the blocked-by-proxy detection configuration settings.
To view the basic blocked-by-proxy detection settings, use the following command:
show swg config
To view the option for custom wait and the option for custom subject lines for emailed notifications of blocked traffic events, use the following command:
show fenotify preferences bbp
The following list describes the command output fields that pertain to blocked-by-proxy detection.
SWG Block-By-Proxy Enabled
This field displays no (disabled) or yes (enabled). By default, blocked-by-proxy detection does is disabled.
Use the swg block-by-proxy enable command to enable blocked-by-proxy detection.
Use the no swg block-by-proxy enable command to disable detection.
SWG Blocked‑by‑Proxy Match String
This field displays the text string that the blocked-by-proxy detection mechanism looks for to detect blocking actions by the Web proxy. The default setting is __FIREEYE_BLOCK_BY_PROXY__, but you must configure this setting to match the string used by the Web proxy.
Use the swg block-by-proxy match-string <text> command to specify the text string that the Web proxy has been configured to insert into block pages sent to affected Web clients.
Wait for Blocked‑by‑Proxy Confirmation
This field displays no (use the default wait time) or yes (use the specified custom wait time). This setting is disabled by default.
Use the fenotify preferences bbp enable command to enable a custom wait time.
Use the no fenotify preferences bbp enable command to use the default wait time.
Max Wait Time for Blocked-by-Proxy (sec)
This field displays the number of seconds that the blocked-by-proxy detection mechanism waits for confirmation of a Web proxy blocking action. The default wait time is 10 seconds.
You can use the fenotify preferences bbp max‑time‑wait <seconds> command to change the wait time to a value from 1 to 99.
Note
The value you configure for this setting is not used unless Wit for Blocked-by-Proxy Confirmation is enabled.
Email Subject Line Prefix for Blocked
This field displays the subject line used in emailed notifications of Infection Match or Malware Callback events that were blocked by the Web proxy. The default subject line is BLOCKED‑BY‑PROXY.
You can use the fenotify preferences bbp subject-desc blocked <text> command to change the text of the subject line. If <text> contains space characters, enclose the string within double quotation marks.
Email Subject Line Prefix for Non-Blocked
This field displays the subject line used in emailed notifications of Infection Match or Malware Callback events that were blocked but have not been confirmed as blocked by the Web proxy. The default subject line is NOT‑BLOCKED‑BY‑PROXY.
You can use the fenotify preferences bbp subject‑desc not‑blocked <text> command to change the text of the subject line. If <text> contains space characters, enclose the string within double quotation marks.
Prerequisites
Admin access to the Network Security appliance CLI.
Go to CLI enable mode.
hostname > enable
View the basic configuration for blocked-by-proxy detection.
In the following example, blocked-by-proxy detection is enabled and the Web proxy inserts the string "
_BLUECOAT_BBP_" into block pages it sends to affected Web clients.hostname # show swg config FireEye Secure Web Gateway Configuration: SWG Scan Enabled: no SWG scan malicious url lookback: 3600 SWG scan callback url lookback: 3600 SWG Block-By-Proxy Enabled: yes SWG Block-By-Proxy match string: _BLUECOAT_BBP_
View the complete configuration for blocked-by-proxy detection.
In the following example, blocked-by-proxy detection is enabled and uses the match string
_BlueCoat_BBP_to identify block pages sent by the Web proxy. The option to use a custom wait time is enabled, and a wait time of 15 seconds is used in place of the default wait time of 10 seconds. Emailed notifications of blocking actions use customized subject lines.hostname # show fenotify preferences bbp Block-by-proxy Related Notification Settings: =================================================== FireEye Secure Web Gateway Configuration Related Settings: SWG Scan Enabled: no SWG Block-By-Proxy Enabled: yes SWG scan malicious url lookback: 3600 SWG scan callback url lookback: 3600 SWG Block-By-Proxy match string: _BLUECOAT_BBP_ Wait for Blocked-By-Proxy Confirmation: yes Max Wait Time for Blocked-By-Proxy Confirmation (sec): 15 EMail Subject Line Prefix for Blocked: Blocked by BlueCoat EMail Subject Line Prefix for Non-Blocked: Blocked-by-FireEye ===================================================