![]() |
![]() |
![]() |
Network Agent Quick Start : Configuring Network Agent
|
Websense Web Filter, Web Security, Web Security Gateway, and Web Security Gateway AnywhereUse TRITON - Web Security to configure Network Agent to recognize machines in your internal network, communicate with Filtering Service, monitor traffic from specified machines, log appropriate data, and more.To configure Network Agent settings in TRITON - Web Security, select the Settings tab of the left navigation pane, and then expand the Network Agent section.Refer to Planning Worksheet 1 for help in configuring Network Agent Global settings. All Network Agent instances in your network use these settings.
1.
2. Make sure that the Describe Your Network list includes all IP addresses in your network.
This information is not used to determine which machines are monitored for filtering. Instead, it allows Network Agent to ignore internal network communications while monitoring Internet traffic.An initial set of entries is provided by default. You can add additional entries, or edit or delete existing entries.Be sure to include all IP addresses that are part of your network, whether or not you want Network Agent to monitor traffic to or from the machine. Later, you will configure whether Network Agent monitors traffic to specific internal IP addresses, and specify which IP addresses are monitored for outgoing Internet traffic.IP address ranges in the list cannot overlap, and you cannot enter an individual IP address that falls within a range already in the list.
3. Use the Internal Traffic to Monitor list to specify internal IP addresses (included in the network definition list) for which you do want Network Agent to monitor connections from other internal IP addresses. You might include internal Web servers, for example, to help track access to internal resources.
![]()
Any requests sent from within the network to the specified internal machines is monitored by Network Agent. This traffic can be filtered and will appear in reports.
4. Use the Additional Settings options allow you to determine how often Network Agent calculates bandwidth usage, and whether and how often protocol traffic is logged:
Bandwidth calculation interval Enter a number between 1 and 300 to specify how frequently, in seconds, Network Agent should calculate bandwidth usage. An entry of 300, for example, indicates that Network Agent will calculate bandwidth every 5 minutes. Log protocol traffic periodically Mark this option to log protocol traffic for use in reports, and to enable the Logging interval field. Enter a number between 1 and 300 to specify how frequently, in minutes, Network Agent logs information about protocol traffic. An entry of 60, for example, indicates that Network Agent will write to the log file every hour.
5. When you are finished making changes, click OK to cache the changes. Changes are not implemented until you click Save All.Refer to Planning Worksheets 2 and 3 for help in configuring local settings. Only the selected Network Agent instance uses these settings.
1. Under Settings > Network Agent, highlight or click Global, and then select the IP address of the Network Agent instance that you want to configure. The IP address of the selected instance appears in the title bar at the top of the content pane.
2. Select the Filtering Service IP address that identifies the Filtering Service instance with which this Network Agent will communicate (Planning Worksheet 2). If Network Agent and Filtering Service are installed on the same machine, the local IP address is selected by default.
3. Indicate whether Network Agent should block or permit all requests If Filtering Service is not available.
4. (Version 7.6): Under IPv6 Configuration, whether or not to Permit all IPv6 traffic seen by this Network Agent instance. If your network does not use IPv6, leave the checkbox blank to block IPv6 traffic.If you choose to block IPv6 traffic, you can specify exceptions. Traffic coming from the IPv6 addresses and IPv6 traffic on the ports you specify will be ignored (permitted). All other IPv6 traffic is blocked.
![]()
To add an IPv6 address to the list, click Add, then enter the IPv6 address or range.
![]()
To specify ports on which IPv6 traffic should be ignored, enter one or more comma-separated port numbers in the Ports field.
5. Use the Proxies and Caches list to specify an proxy or cache machines that monitored machines use to access the Internet. This keeps Network Agent from identifying requests from both the client machine and the proxy or cache machine, which could result in duplicate log records or incorrect filtering.
6.
a. If Websense software is installed in integrated mode, indicate the Ports used for HTTP traffic in your network.If you have installed Websense software in standalone mode, all ports are monitored and the field is disabled.
b. If you want Network Agent to ignore traffic on specific ports, mark Configure this Network Agent instance to ignore traffic on the following ports, and then enter one or more ports.Do not make changes to the Debug Settings options unless directed to do so by Websense Technical Support.
7. Refer to Planning Worksheet 4 for help in configuring NIC settings. These settings determine which NIC is used for monitoring and which is used for blocking and communication with other Websense components. They also determine which IP addresses this Network Agent instance monitors, and how the agent responds to requests for non-HTTP protocols.
1. Click an entry in the Network Interface Cards list on the Local Settings page for the Network Agent instance that you are configuring.The NIC Information list provides a description of the selected network card.
2. Indicate whether or not to Use this NIC to monitor traffic.If the Network Agent machine has multiple NICs, you can configure more than one NIC to monitor traffic.
If Network Agent runs on a Linux machine with multiple NICs, the operating system determines in real-time which NIC to use for monitoring. Network Agent may sometimes use a NIC other than the one specified here.
![]()
If this NIC will be used for monitoring, click Configure, and continue with step 3.
3.
![]()
Use the Monitor List to identify which IP addresses (All, None, or Specific) this Network Agent instance monitors.If you select Specific, add the IP address ranges and individual IP addresses that this Network Agent should monitor.
![]()
Under Monitor List Exceptions, add any IP addresses within the monitored ranges that Network Agent should not monitor.
![]()
When you are finished making changes, click OK to return to the NIC Configuration page.
4. Indicate which NIC Network Agent should use as a Blocking NIC. This NIC is also used for communication with other Websense software components, and must have an IP address.
5. If you are using Websense software in standalone mode, the Integrations options are disabled. Continue with step 6.If you have integrated Websense software with a firewall, proxy, network appliance, or other product:
![]()
Select Log HTTP requests to improve accuracy in Websense reports.
![]()
Select Filter all requests not sent over HTTP ports to use Network Agent to filter only those HTTP requests not sent through the integration product.
6. Under Protocol Management, indicate whether Network Agent should be used to Filter non-HTTP protocol requests and Measure bandwidth by protocol.After configuring Network Agent, you may want to use a packet analyzer to ensure that the monitoring NIC is able to see traffic from all of the IP addresses that it is configured to monitor.Wireshark is a free, popular, open source network protocol analyzer, available for Windows and Linux systems from www.wireshark.org.
![]()
Review the more detailed network configuration information in the Deployment and Installation Center for your Websense software.
![]() |
![]() |
![]() |
Network Agent Quick Start : Configuring Network Agent
|