![]() |
![]() |
![]() |
Integrating Web Security with Check Point > Configuring Check Point products to work with Web Security solutions
|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
2.
|
If you have not already done so, create a network object (Manage > Network Objects > New > Node > Host) for the machine running Filtering Service.
|
3.
|
Select General Properties in the left column. The following dialog box appears.
|
Enter a descriptive name for the network object representing the Filtering Service machine, such as WebsenseFS (make a note of this name for later use).
Note: If your DNS is configured to resolve machines within your network, enter the Filtering Service machine's host name here. Then, for IP Address, you can click Get address to resolve the host name to its IP address automatically.
|
|
Note: If you entered a host name for Name, you can click Get address to find the machine's IP address automatically. See the description for Name, above, for more information.
|
|
5.
|
Click OK.
|
2.
|
Select Manage > Servers and OPSEC Applications.
|
3.
|
4.
|
Select the General tab in the OPSEC Application Properties dialog box.
|
Enter a descriptive name, such as Websense_ufp (make a note of this name for later use).
|
|
If you have not yet created this object, click New to create it. See Creating a network object for instructions.
|
|
Select Websense.
|
|
UFP is checked automatically when you select Websense as the Vendor, and.cannot be changed.
|
6.
|
Select the UFP Options tab.
|
7.
|
Check the Use early versions compatibility mode option (Backwards Compatibility in earlier versions).
|
![]() |
If Secure Internal Communication (SIC) is used, go to Establishing Secure Internal Communication to complete this section.
|
![]() |
If SIC is not used, select Clear (opsec).
|
8.
|
Click Get Dictionary.
|
9.
|
Click OK.
|
11.
|
Select Policy > Install to install the policy on the firewall.
|
1.
|
Open SmartDashboard and select Manage > Resources.
|
2.
|
3.
|
Select the General tab, and complete the items in the tab.
|
Enter a name for this URI Resource Object, such as Blocked_Sites.
|
|
Select Enforce URI capabilities.
|
|
Select UFP.
|
4.
|
Select the Match tab, and complete the items in the tab.
|
No caching is the recommended setting for most networks.
|
|
Mark the Blocked check box.
|
|
5.
|
Click OK.
|
7.
|
Select Policy > Install to install the policy on the firewall.
|
(NGX only) Enter a descriptive name for the rule, such as Websense Block.
|
|
In the Service with Resource dialog box, select HTTP. Under Resource, select Blocked_Sites from the drop-down menu. This object was created in Creating Resource Objects.
|
|
(NGX only) Enter a descriptive name for the rule, such as Websense Allow
|
|
For normal operation, set Track to None in the Websense rules. This disables logging in the Check Point product.
|
![]() |
Windows: C:\Program Files or Program Files (x86)\Websense\Web Security\bin
|
![]() |
Linux: /opt/Websense/bin
|
2.
|
Open the ufp.conf file in any text editor.
|
4.
|
Save and close the ufp.conf file.
|
![]() |
Windows: Use the Windows Services dialog box.
|
![]() |
Linux: Use the ./WebsenseAdmin restart command.
|
![]() |
Configure the OPSEC Application object for the Websense UFP Server to operate in early versions compatibility mode (previously known as backwards compatibility mode) for clear communication.
|
![]() |
1.
|
Open the SmartDashboard, and select Manage > Servers and OPSEC Applications.
|
2.
|
3.
|
Select the UFP Options tab.
|
4.
|
Select Use early versions compatibility mode (Backwards Compatibility in earlier versions).
|
5.
|
6.
|
Select Policy > Install to install the policy on the firewall. See Check Point product documentation for more information.
|
1.
|
Open the SmartDashboard, and select Manage > Resources.
|
2.
|
3.
|
4.
|
Select the Match tab.
|
5.
|
6.
|
7.
|
Close the Resources dialog box.
|
8.
|
Select Policy > Install to install the policy on the firewall. See the Check Point product documentation for more information.
|
![]() |
![]() |
![]() |
Integrating Web Security with Check Point > Configuring Check Point products to work with Web Security solutions
|