Web Security All > Installing Web Security All components
|
Follow these instructions to perform a Web Security All installation which installs all Web Security management and core filtering components on one machine.
3.
4.
5.
6.
7.
8. When you click Finish in TRITON Infrastructure Setup.
10. If you are using Active Directory, the Computer Browser screen appears.See Computer Browser Screen for instructions.
11. On the Integration Option screen, select whether your Web Security deployment will be integrated with a third-party product.See Integration Option Screen for instructions.
If your subscription includes Web Security Gateway or Web Security Gateway Anywhere, select Websense Content Gateway as the integration product. Also, install Websense Content Gateway.
12.
a. On the Select Integration screen, select the product you want to integrate with.See Select Integration Screen for instructions
b.
13. On the Network Card Selection screen, select the network interface card (NIC) to be used by Network Agent.See Network Card Selection Screen for instructions.
14. If the Multiple Network Cards screen appears, select the NIC(s) to be used by Network Agent for monitoring.See Multiple Network Cards Screen for instructions.
15. On the Log Database Location screen, specify the location in which you want the Websense log database stored.See Log Database Location Screen for instructions.
16. On the Optimize Log Database Size screen, select options for optimizing the size of log database records.See Optimize Log Database Size Screen for instructions.
17. On the Filtering Feedback screen, choose whether to send categorization feedback to Websense, Inc.See Filtering Feedback Screen for instructions.
18. On the Web Security Gateway Anywhere Components screen, select whether you want to install Websense Web Security Gateway Anywhere components on this machine. Then click Next.
Install Web Security Gateway Anywhere Components: Select this option to install these components and then check the box for the components (Sync Service and/or Directory Agent) you want to install.
Do not install Web Security Gateway Anywhere Components: Select this option to not install these components.
19. On the Transparent User Identification screen, select whether to use Websense transparent identification agents to identify users and then click Next. This allows Websense software to apply user- or group-based filtering policies without prompting users for logon information.If Websense software is integrated with a third-party product (firewall, proxy server, cache, or network appliance) providing user authentication, a transparent identification agent may not be necessary.To transparently identify remote users accessing the network via VPN, use Websense RADIUS Agent. Later in this installation process, you will be given the option to install RADIUS Agent.
Use Logon Agent to identify users logging on to local machines: This option installs Websense Logon Agent on this machine. Logon Agent identifies users as they log onto Windows domains. Logon Agent is for use with Windows-based client machines on a network that uses Active Directory or Windows NT Directory.To use Logon Agent, you must modify the Group Policy on domain controllers so it launches a logon application (LogonApp.exe) as part of the logon script. Client machines must use NTLM (v1 or v2) when authenticating users (NTLMv1 only, in the case of Windows Server 2008; see note below).For instructions on configuring domain controllers and client machines to use Logon Agent, see Creating and running the script for Logon Agent.
Do not use Logon Agent in a network that already includes eDirectory Agent.
Use eDirectory Agent to identify users logging on via Novell eDirectory Server: This option installs eDirectory Agent on this machine. Use this agent for a network using Novell eDirectory. eDirectory Agent queries the eDirectory Server at preset intervals to identify users currently logged on.
Do not use eDirectory Agent in a network that already includes DC Agent or Logon Agent.
Do not install a transparent identification agent now: Select this option if
Websense software will be integrated with a third-party product that provides user authentication.
You want users to be prompted for logon information when they open a browser to access the Internet.
When integrated with Cisco products, Websense software cannot use Cisco Secure Access Control Server (ACS) for user authentication for more than 1 user domain. If there are multiple user domains, use a transparent identification agent instead.
20. On the Directory Service Access screen, supply a domain administrator account to access directory service information.See Directory Service Access Screen for instructions.
21. On the RADIUS Agent screen, select Install RADIUS Agent if you have remote users that are authenticated by a RADIUS server and then click Next. This allows Websense software to apply user- or group-based filtering policies on these remote users without prompting for logon information.
22. On the Pre-Installation Summary screen, verify the information shown.
23. Click Next to start the installation. An Installing progress screen is displayed. Wait for the installation to complete.
24. If you chose to install the ISA Server filtering plug-in, the Stop Microsoft Firewall Service screen appears. Do the following:
Leave the Websense installer running as you stop the Microsoft Firewall service. Then return to the installer and click Next to continue installation.
In order to correctly install the ISA Server filtering plug-in, the Microsoft Firewall Service must be stopped. Installation of the plug-in files and registration of the plug-in in the system registry cannot occur while the Microsoft Firewall Service has certain files locked. Stopping the Microsoft Firewall Service unlocks these files.To stop the Firewall service, go to the Windows Services management console (Administrative Tools > Services). Right-click Microsoft Firewall, and then select Stop. When the service has stopped, return to the Websense installer and continue the installation process. The Firewall Service may also be stopped from the ISA Server Management console or Command Prompt (using the command net stop fwsrv). See Microsoft's documentation for more information.
When the Microsoft Firewall service is stopped, ISA Server goes into lockdown mode. Depending on your network configuration, network traffic may be stopped. Typically, the Firewall service needs to be stopped for only a few minutes as the ISA Server filtering plug-in is installed and configured.The Websense ISAPI Filter has been configured, you can now start the Microsoft Firewall Service.To start the Firewall service, go to the Windows Services management console (Administrative Tools > Services). Right-click Microsoft Firewall, and then select Start. The Firewall Service may also be started from the ISA Server Management console or Command Prompt (using the command net start fwsrv). See Microsoft's documentation for more information.
25.
Web Security All > Installing Web Security All components
|