Sie sind auf Seite 1von 118

BLUENET WEB SECURITY TRACK

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 1
AGENDA

Blue Coat Product Family Policy Management


Blue Coat SG Deployment Authentication Introduction
Blue Coat SG Initial Setup Authentication Realms
Blue Coat GUI Bluecoat Reporter
Content Filtering

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 2
BLUENET BLUECOAT PRODUCTS

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 3
PRODUCT LIST

Hardware Based Software Based

Blue Coat SG Blue Coat Reporter

Blue Coat AV Blue Coat WebFilter

Blue Coat K9
Blue Coat Director

Proxy Client
Packetshaper

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 4
BLUE COAT SG APPLIANCE

Enables enterprises to secure, control, and enhance


performance of networks

Deployed at different enterprise locations


Internet gateway
Edge of application delivery infrastructure
In the DMZ

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 5
BLUE COAT AV

Powerful defense against


Viruses and worms
Spyware and Trojans

Protects often overlooked back doors


Personal Web e-mail accounts
Web content or e-mail spam with Trojan or spyware
Browser-based file downloads that bypass existing virus-scanning
defenses

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 6
BLUE COAT AV DEPLOYMENT

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 7
WHAT IS DIRECTOR?

Centralizes Blue Coat SG management


Saves time and costs
Enables standardization of configuration and policy

Automates device-management tasks


Configuration and policy changes
Backups

Helps implement Application Delivery Network

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 8
DIRECTOR DEPLOYMENT

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 9
BLUE COAT REPORTER

Generate reports on a wide range of data


150+ pre-defined reports available
Reports can be customized

Schedule reports
At a specific time, periodically, or in real time

Export reports
In HTML by scheduled e-mails
In Excel-compatible format

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 10
BLUE COAT WEBFILTER

Hybrid Solution
Onbox database for Blue Coat SG
Optional service to categorize unrated URLs

Data Quality
About 71 categories
More than 50 languages
Consistency
Priority to most frequently requested resources

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 11
BLUE COAT SG
DEPLOYMENT

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 12
DEPLOYMENT OPTIONS

Explicit Proxy
Clients know there is a proxy in the path

Transparent Proxy
Clients do not know there is a proxy in the path

Reverse Proxy
Protects a web server from clients on the internet

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 13
EXPLICIT PROXY

Clients know there is a proxy in the path

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 14
TRANSPARENT PROXY

Clients do not know there is a proxy in the path

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 15
EXPLICIT: MANUALLY CONFIGURED

Simple High Maintenance


Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 16
TRANSPARENT: LAYER 4 SWITCH

Simple Initial Cost


Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 17
TRANSPARENT: CISCO WCCP

Simple Router Load


Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 18
TRANSPARENT: BLUE COAT SG BRIDGING

Simple Single Point of Failure


Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 19
TRANSPARENT: DEFAULT ROUTER

Simple Single Point of Failure


Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 20
DEPLOYMENT BEST PRACTICE

Firewall Rules
Source Destination Action
172.16.0.100 ANY ALLOW
172.16.1.10 25 ALLOW
ANY ANY DENY

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 21
EDGE DEPLOYMENT

Core Deployment Edge Deployment

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 22
REVERSE PROXY

The proxy is the Web server to clients

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 23
ACCELERATING WEB CONTENT

Web Server Farm

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 24
SECURING CORPORATE CONTENT

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 25
MIXED DEPLOYMENT

3
5
2

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 26
BLUECOAT SG
INITIAL SETUP

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 27
INITIAL SETUP ACCESS

Serial Console
Easy and reliable

LCD / Keypad
A built-in interface for proxy configuration (most models)

TCP/IP
Access reserved site https://proxysg.bluecoat.com:8083
Blue Coat SG200-X in bridging mode only

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 28
SERIAL ACCESS SETUP

Initial Setup Console Wizard


Network Interface Setup (Required)
Admin Account Setup (Required)
Restrict Access Setup (Optional)

Press the Esc key to exit the Wizard without saving any
changes

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 29
PASSWORD LEVELS

Create Administrator Account


Username and password are both case-sensitive
Both can be set to any alphanumeric value

Two login levels


Basic Access
Enable Access

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 30
FEATURES REQUIRING LICENSING

SGOS License Optional Add-on Licenses


Required
Encrypted Tap
Includes:
SGOS Content Filtering
HTTP, FTP, SOCKS Blue Coat WebFilter
ICAP SmartFilter
Others
Compression
P2P Instant Messaging
Premium Streaming Optional but free

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 31
LICENSING INSTALLATION OVERVIEW

Log in to WebPower

Register Blue Coat SG Serial Number


Add licenses to your Blue Coat SG

Retrieve the license key

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 32
HANDS-ON SECTION

Blue Coat SG Initial Configuration

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 33
BLUECOAT SGOS
GRAPHICAL USER INTERFACE

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 34
MANAGEMENT CONSOLE CONFIGURATION

Starting point for most tasks with Blue Coat SG

Select options in left navigation bar

Use options to change configurations

Use options to create objects and parameters used to


create policy

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 35
MANAGEMENT CONSOLE
MAINTENANCE

Starting point for variety of maintenance tasks

Restart appliance, restore defaults, clear caches

Upgrade SGOS, license new features

Configure health monitoring, use diagnostic tools

Take disks offline, put them online

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 36
MANAGEMENT CONSOLE STATISTICS

Allows you to view statistics graphically

Statistics include
System usage
HTTP/FTP, CIFS, MAPI, and byte-caching history
Resources
Efficiency

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 37
HANDS-ON SECTION

Using the Blue Coat SG


Graphical User Interface

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 38
SERVICE FRAMEWORK

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 39
SERVICES TYPES

Proxy Services
Matches TCP ports to proxy types
Can be set to Bypass or Intercept

Console Services
Services Blue Coat SG administration
Can be Enabled or not

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 40
PROXY SERVICES LISTENER FEATURES

Destination Address
Defines the host or hosts to be intercepted by the proxy service
Multiple listeners can be defined for a proxy service
Modes: All, Transparent, Explicit, Destination

Port Range
Defines a port or port range to be intercepted by the service.

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 41
PROXY SERVICE ACTIONS

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 42
PROXY SERVICE ATTRIBUTES

Attributes define the default parameters for the proxy


service
Only apply when action is set to Intercept

Attributes vary for different proxy types


Dependent on protocol

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 43
SERVICES ATTRIBUTES

Attribute Description

Enable ADN Transmit the traffic over the ADN


connection, if available
Detect Protocol Recognize protocols tunneled over
others. Es: HTTPS over HTTP proxy
Early Intercept Proxy completes the TCP connection
setup with the client without having to
wait for the server response
Reflect Client IP Proxy connects to the OCS using as
source IP address the clients IP
Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 44
SERVICES PROCESSING

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 45
CONSOLE SERVICES

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 46
HANDS-ON SECTION

Configuring Services

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 47
WEB FILTERING

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 48
CONTENT FILTERING LOGICAL FLOW

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 49
CATEGORIZATION TECHNIQUES

Database Pros Dynamic Cat Pros


Accuracy (100%) Immediate coverage
Response time Scalability

Database Cons Dynamic Cat Cons


Small number of site Response time
Update time Accuracy (90%)

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 50
BLUE COAT WEB FILTER

Hybrid Solution
Onbox database for Blue Coat SG
Optional Service Component to categorize unrated URLs

Data Quality
Granular Categories
Consistency
Relevant URLs (feedback)
Immediate coverage for new sites (DRTR)

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 51
BLUE COAT WEBFILTER DETAILS

Features Quantity Comments


Languages 50 + Excellent quality
Categorized URL list is
Ratings 15 Million + growing daily

Includes spyware and


Categories 60+ malware

4,000 to 6,000 additional Highly accurate


Categorization unique URLs rated per day categorization of URLs
40+ Recognized languages Categorizes over 95% of
Dynamic Rating 10+ Categorized languages objectionable content

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 52
DYNAMIC CATEGORIZATION OVERVIEW

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 53
BLUE COAT WEBFILTER SERVICE POINTS

sp.cwfservice.net
DNS

Sacramento
London
Salt Lake City
Tokyo

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 54
BCWF COMPLETE WORKFLOW

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 55
LOCAL DATABASE

Custom Categories
Custom allowed list
Customer denied list
Internal URLs

Performance and Security


Hash list
Does not require VPM/Management Console Access

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 56
HANDS-ON SECTION

Content Filtering Configuration

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 57
HANDS-ON SECTION

Content Filtering Policy

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 58
POLICY MANAGEMENT

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 59
COMPANY POLICY ENFORCEMENT

Create Acceptable Usage Policy (AUP)

Create Web Authentication Layer(s)


Monitor user by login name

Create Web Access Layer(s)


Implement AUP

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 60
DEFAULT POLICY

Deny
Default option for Blue Coat SG
All network traffic received by the proxy is blocked

Allow
Network traffic is allowed through the proxy
Other policies can deny selected traffic

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 61
VPM OBJECTS

Trigger Objects
Source
Destination
Service
Time

Action Objects
Action
Track

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 62
POLICY TRANSLATION

XYZ Inc. employees may not visit the BBC Web site at
any time.

Simple Language
Who Where How When What
XYZ Employees BBC On web At any time May not visit

Blue Coat Language


Source Destination Service Time Action
ANY bbcworld.com ANY ANY DENY

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 63
POLICY TRANSLATION

XYZ Inc. employees may not visit any


travel related Web site at any time.

Simple Language
Who Where How When What
XYZ Employees Travel On web At any time May not visit

Blue Coat Language


Source Destination Service Time Action
ANY Travel ANY ANY DENY

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 64
POLICY TRANSLATION

The Engineering department may not visit any


gaming site during regular business hours.

Simple Language
Who Where How When What
Engineering Gaming On web M-F, 08-17 May not visit

Blue Coat Language


Source Destination Service Time Action
ENG Gaming ANY Mon-Fri, 08-17 DENY

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 65
XYZ INC. WEB ACCESS POLICY

Similar rules become a layer in the Web


Access Policy

Source Destination Service Time Action


ANY BBC ANY ANY DENY
ANY Travel ANY ANY DENY
ENG Gaming ANY Mon-Fri, 8-17 DENY
Layer

Web Access Policy

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 66
VPM RULES PRIORITY

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 67
VPM POLICY LAYERS

Admin Authentication SSL Access


Admin Access
Web
DNS Access
Authentication
SOCKS Authentication
Web Access
SSL Intercept
Web Content

Forwarding

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 68
VPM LAYERS PRIORITY

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 69
HANDS-ON SECTION

Creating Basic Policy

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 70
AUTHENTICATION

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 71
AUTHENTICATION AND SECURITY TYPES

Blue Coat SG Security


Console Access
Physical Access (front panel, serial port)

Blue Coat SG Authentication


Validate users before allowing access to protocols

Remote resources authentication requests

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 72
BLUE COAT SG SECURITY

Limit access to the Blue Coat SG appliance


Restrict access by IP address or IP ranges
Password to secure Setup Console
Require PIN to operate front panel
Password protect serial access

Role-based security
Use realm-based authentication
Granular permission selection

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 73
AVAILABLE SECURITY MEASURES

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 74
AUTHENTICATION

Policies based on users and groups

Granular Reporting

Manage Exceptions

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 75
EXPLICIT PROXY AUTHENTICATION

Proxy requires client to authenticate


HTTP 407 Response Proxy Authentication Required

Browser resends the request with users credentials


Credentials are sent with every request

Most browsers cache credentials as long as


the process is running

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 76
EXPLICIT PROXY AUTHENTICATION

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 77
AUTHENTICATION OPTIONS

Force Authenticate

Authenticate

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 78
REMOTE RESOURCES AUTHENTICATION

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 79
AUTHENTICATION REALM

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 80
AUTHENTICATION REALMS

IWA
Windows NT Domains and Active Directory

LDAP
Active Directory and other LDAP Databases

Sequence
List of authentication realms to be processed

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 81
IWA REALM

Basic Credentials
Username and password are sent base64 encoded
Least secure option

NTLM Credentials
Uses the Microsoft proprietary authentication
Medium security option

Kerberos Credentials
Uses Microsoft implementation of M.I.T Kerberos v5
Highly secure option

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 82
NTLM AUTHENTICATION

Provides secure authentication


Password is not transmitted over the network

Supports single sign-on


Requires compatible user agents

Widely used
Prevalence of Windows OS on desktops

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 83
NTLM AUTHENTICATION

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 84
BCAAA

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 85
NTLM AUTHENTICATION OVER HTTP

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 86
HANDS-ON SECTION

Authentication Configuration IWA

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 87
LDAP REALM

Lightweight Directory Access Protocol

LDAP can contain a wide range of information


Users, applications, devices, etc.

LDAP realm supports Basic and Basic over SSL

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 88
LDAP DIRECTORY INFORMATION TREE

DC=BlueCoat

C=US C=IT C=UK

OU=Groups OU=People OU=Applications OU=Locations OU=Locations

CN=Human resources UID=kelly.lee CN=Oracle CN=Milan

CN=Information Technology UID=joe.doe CN=Exchange CN=Turin

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 89
LDAP DISTINGUISHED NAME

DN: UID=kelly.lee, OU=people, C=IT, DC=BlueCoat

Additional objects for a DN


CN: Kelly Lee
GIVENNAME: Kelly
TEL: +39-347-555-2200

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 90
HANDS-ON SECTION

Authentication Configuration LDAP

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 91
SEQUENCE REALM

Credentials checked against multiple realms

LDAP, Local, or IWA realm in sequence

Ideal for mixed environments

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 92
SEQUENCE AUTHENTICATION

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 93
ACCESS LOGGING

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 94
ACCESS LOGGING

Track Web usage for


entire network
specific information on user
department usage patterns.

Blue Coat SG creates access logs for each type of protocol.

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 95
ACCESS LOGGING

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 96
PROTOCOLS SUPPORTING ACCESS LOGGING

Endpoint Mapper Proxy Peer-to-Peer( P2P)

FTP Real Media/Quick time

HTTP SOCKS

HTTPS Forward Proxy SSL

HTTPS Reverse Proxy TCP Tunnel

ICP Telnet

Instant Messaging (IM) Windows Media

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 97
PROTOCOLS AND DEFAULT LOGS

Protocol Default Log


Endpoint Mapper main
FTP
HTTP
TCP Tunnel
Telnet
HTTPS Reverse proxy
ICP,SOCKS no logging

Instant Messaging im

Peer-to-Peer p2p

Multimedia Streaming streaming

SSL, HTTPS ssl


Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 98
LOG FACILITY

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 99
SUPPORTED LOG FORMATS

Available log formats


NCSA Common
SQUID Compatible
ELFF
Smart Reporter
SurfControl
Websense
BC ReporterMain
BC ReporterSSL

Custom log formats


Create your own log format using format strings.

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 100
UPLOAD LOGS

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 101
CONTINUOUS UPLOAD

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 102
PERIODIC UPLOAD

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 103
LOG FILE ENCODING

Gzip
Text Access Logs
Text

Continuous Periodic
Upload Upload

Remote Server Remote Server

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 104
HANDS-ON SECTION

Access Logging

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 105
BLUECOAT REPORTER

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 106
REPORTER OVERVIEW

Analyzes Blue Coat SG access logs.

Presents data using pre-defined formats.

Runs as it owns Web server.

Access through Web interface.

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 107
REPORTER OVERVIEW

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 108
PROFILES

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 109
REPORTER LICENSING

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 110
REPORTER- STANDARD VERSION

Blue Coat Reporter Features Standard Version

Profile Creation Limited to five

Scalability Single processor only

Customizing Reports Limited

Formats Only default Blue Coat SG


formats

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 111
REPORTER- ENTERPRISE VERSION

Blue Coat Reporter Features Enterprise Version

Profile Creation Unlimited profile creation

Scalability Multiple processors

Customizing Reports Create, customize, edit


unlimited reports

Formats Permits use of custom


formats

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 112
SYSTEM REQUIREMENTS- HARDWARE

Total Reporting CPU RAM Drives Disk Operating


Users Days Storage Space System
<2000 1 month 1x P4 (2.8 GHz 2 GB Internal 15k RPM/RAID 0 Total amount of Windows XP and 2003
or faster) or SCSI Controller compressed servers, Red Hat
Xeon(2.8 GHz logs x 10 Linux
or faster)
<2000 2 months 1x P4 (2.8 GHz 2 GB Internal 15k RPM/RAID 0 Total amount of Windows XP and 2003
or faster) or SCSI Controller compressed servers, Red Hat
Xeon(2.8 GHz logs x 10 Linux
or faster)
<2000 3 months 2x Xeon (2.8 4 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux
2001 - 4000 1 month 2x Xeon (2.8 4 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux
2001 - 4000 2 months 2x Xeon (2.8 4 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux
2001 - 4000 3 months 4x Xeon (2.8 8 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 113
SYSTEM REQUIREMENTS- HARDWARE

Total Reporting CPU RAM Drives Disk Operating


Users Days Storage Space System
4001 - 6000 1 month 2 x Xeon(2.8 4 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux

4001 - 6000 2 months 4x Xeon(2.8 8 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux
4001- 6000 3 months 4x Xeon (2.8 8 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux
>6000 1 month 4x Xeon (2.8 8 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux
>6000 2 months 4x Xeon (2.8 8 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux
>6000 3 months 4x Xeon (2.8 8 GB Internal Dual 15k RPM/RAID 0 Total amount of Windows XP and 2003
GHz or faster) Channel SCSI compressed servers, Red Hat
logs x 10 Linux

Blue Coat Reporter sizing guide URL


http://download.bluecoat.com/release/Reporter/reporter-sizing.html

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 114
SYSTEM REQUIREMENTS

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 115
HANDS-ON SECTION

Creating Reporter Profiles and


Generating Reports

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 116
HANDS-ON SECTION

Real-Time Reporting

Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 117
Blue Coat Confidential Internal Use Only Copyright 2013 Blue Coat Systems Inc. All Rights Reserved. 118

Das könnte Ihnen auch gefallen