»¥ÁªÍø´úÀí°²È«Íø¹Ø¹¦ÄÜÐèÇóÎĵµ
2011Äê1ÔÂ
Ŀ ¼
Ò»¡¢ °²×°É豸¼°°²×°»·¾³ ........................................................................................ 4 1.1 ʵʩÉ豸Çåµ¥.................................................................................................... 4 1.2 ÊµÊ©ÍØÆÓ½á¹¹Í¼................................................................................................ 4 ¶þ¡¢ ʵʩ²½Öè ............................................................................................................ 4 2.1 ÎïÀíÁ¬½Ó............................................................................................................ 4 2.2 ³õʼIPµØÖ·ÅäÖà .............................................................................................. 4 2.3 Ô¶³Ì¹ÜÀíÈí¼þÅäÖÃ............................................................................................ 5 2.4 ÍøÂçÅäÖÃ............................................................................................................ 5 2.4.1 Adapter 1µØÖ·ÅäÖà .................................................................................... 6 2.4.2 ¾²Ì¬Â·ÓÉÅäÖà ............................................................................................ 6 2.4.3 ÅäÖÃÍâÍøDNS·þÎñÆ÷ ............................................................................... 8 2.4.4 ÅäÖÃÐéÄâIPµØÖ· ....................................................................................... 8 2.4.5 ÅäÖÃFail Over ............................................................................................ 9 2.5 ÅäÖôúÀí·þÎñ¶Ë¿Ú.......................................................................................... 11 2.6 ÅäÖñ¾µØÊ±ÖÓ.................................................................................................. 12 2.7 ÅäÖÃRADIUSÈÏÖ¤·þÎñ .................................................................................... 12 2.8 ÄÚÈݹýÂËÁÐ±í¶¨Òå¼°ÏÂÔØ.............................................................................. 15 2.9 ¶¨Ò岡¶¾É¨Ãè·þÎñÆ÷...................................................................................... 17 2.10 ´ø¿í¹ÜÀí¶¨Òå................................................................................................ 21 2.11 ²ßÂÔÉèÖÃ........................................................................................................ 22 2.11.1 ÅäÖÃDDOS¹¥»÷·ÀÓù ............................................................................ 22 2.11.2 ÉèÖÃȱʡ²ßÂÔΪDENY ......................................................................... 22 2.11.3 ÅäÖÃBlue Coat Anti-Spyware²ßÂÔ ........................................................ 23 2.11.4 ·ÃÎÊ¿ØÖƲßÂÔÅäÖÃ-VPM ....................................................................... 24
2.11.5 ²¡¶¾É¨Ãè²ßÂÔÅäÖà ................................................................................ 24 2.11.6 Óû§ÈÏÖ¤²ßÂÔÉèÖà ................................................................................ 26 2.11.7 ´ø¿í¹ÜÀí²ßÂÔ¶¨Òå ................................................................................ 28 2.11.8 Work_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå .............................................. 33 2.11.9 Management_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå .................................. 35 2.11.10 High_Level_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå .................................. 35 2.11.11 Normal_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå ......................................... 36 2.11.12 Temp_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå ............................................ 36 2.11.13 IEä¯ÀÀÆ÷°æ±¾¼ì²é²ßÂÔ ...................................................................... 40 2.11.14 DNS½âÎö²ßÂÔÉèÖà .............................................................................. 41
Ò»¡¢ °²×°É豸¼°°²×°»·¾³
1.1 ʵʩÉ豸Çåµ¥
Bluecoat°²È«´úÀíרÓÃÉ豸SG600£10һ̨£¬AV510-Aһ̨£¬BCWFÄÚÈݹýÂË£¬MCAFEE·À²¡¶¾,ÆóÒµ°æ±¨±íÄ£¿é¡£
1.2 ÊµÊ©ÍØÆÓ½á¹¹Í¼
BluecoatÉ豸SG600-10£3ÅäÖÃÓÚÄÚÍø£¬AV510-AÓëSG600-10Ö®¼äͨ¹ýICAPÐÒ齨Á¢Í¨ÐÅ¡£Á¬½Ó·½·¨ÓÐÒÔϼ¸ÖÖ£¬ÍøÂçʾÒâ½á¹¹ÈçÏÂͼ£º
ÅÔ·ģʽ£º
¶þ¡¢ ʵʩ²½Öè
2.1 ÎïÀíÁ¬½Ó
Á½Ì¨Bluecoat SG800£2µÄAdapter0_Interface 0ºÍAdapter1_Interface0ͨ¹ýÒÔÌ«ÍøË«½ÊÏßÁ¬½ÓÓÚÁ½Ì¨Radware CID½»»»»ú¡£
2.2 ³õʼIPµØÖ·ÅäÖÃ
ͨ¹ýÉ豸ǰ¿ØÖÆÃæ°å¿ÉÒÔÉèÖÃProxySG800-2µÄAdapter0_Interface0µÄµØÖ·Îª£º
µÚһ̨SG800£2£º191.32.1.9(IP)
255.255.255.224(Mask) 191.32.1.1(Default Gateway)
µÚ¶þ̨SG800£2£º191.32.1.11(IP)
255.255.255.224(Mask) 191.32.1.1(Default Gateway)
2.3 Ô¶³Ì¹ÜÀíÈí¼þÅäÖÃ
Bluecoat°²È«´úÀíרÓÃÉ豸ͨ¹ýIEä¯ÀÀÆ÷ºÍSSHÃüÁî½øÐйÜÀí£¬ä¯ÀÀÆ÷¹ÜÀí¶Ë¿ÚΪ8082£¬¹ÜÀíÓõÄPC»úÐè°²×°ÁËJavaÔËÐл·¾³¡£¹ÜÀí½çÃæµÄURLΪ£º
https://191.32.1.9:8082ºÍhttps://191.32.1.11:8082
2.4 ÍøÂçÅäÖÃ
ÔÚxxxxxÍøÂç»·¾³ÖУ¬(1)ProxySG800-2Á½¸ö¶Ë¿Ú¾ùÐèÅäÖÃIPµØÖ·£»(2)³ýȱʡ·ÓÉÖ¸Ïò·À»ðǽ£¬»¹ÐèÒ»Ìõ¾²Ì¬Â·ÓÉ£¬×÷ΪÄÚÍøÍ¨Ñ¶µÄ·ÓÉ£¬(3)ÅäÖÃÍâÍøDNS£¬ÒÔ±ãProxySGµ½»¥ÁªÍøµÄ·ÃÎÊ£¬(4) ÿ̨ÁíÍâÐèÒªÒ»¸öÐéÄâIPµØÖ·£¬×÷ΪÄÚ²¿Ô±¹¤
µÄDNS½âÎö·þÎñÆ÷IPµØÖ·£»(5)¶ÔÐéÄâIPµØÖ·ÅäÖÃFail Over£¬µ±Ò»Ì¨ProxySGÍ£Ö¹¹¤×÷£¬ÆäÐéÄâIP½«Çл»µ½ÁíÍâһ̨¡£
2.4.1 Adapter 1µØÖ·ÅäÖÃ
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Adapter½øÈ룬ÔÚAdaptersÏÂÀ¿òÖÐÑ¡ÔñAdapter1£¬²¢ÔÚIP address for Interface 0ºÍ Subnet mask for Interface 0ÖÐÅäÖÃIPµØÖ·ºÍ×ÓÍøÑÚÂ룬ÈçÏÂͼʾ£º
µÚһ̨ProxySG800-2µÄIPµØÖ·Îª£º191.32.1.10£¬ÑÚÂ룺255.255.255.224 µÚ¶þ̨ProxySG800-2µÄIPµØÖ·Îª£º191.32.1.12£¬ÑÚÂ룺255.255.255.224 µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.4.2 ¾²Ì¬Â·ÓÉÅäÖÃ
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Routing½øÈ룬ÔÚ´°¿ÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñRouting£¬²¢ÔÚInstall Routing table fromÏÂÀ¿òÖÐÑ¡ÔñText Editor£¬ÈçÏÂͼʾ£º
µã»÷Install£¬²¢ÔÚµ¯³ö´°¿ÚÖÐÊäÈ뾲̬·ÓÉ£º 191.0.0.0 255.0.0.0 191.32.1.5 ÈçÏÂͼʾ£º
µã»÷InstallʹÅäÖÃÉúЧ¡£
2.4.3 ÅäÖÃÍâÍøDNS·þÎñÆ÷
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/DNS½øÈ룬ÈçÏÂͼʾ£º
µã»÷NewÔö¼ÓÍâÍøDNS·þÎñÆ÷IPµØÖ·£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.4.4 ÅäÖÃÐéÄâIPµØÖ·
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Advanced½øÈ룬ÔÚ´°¿ÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñVIPs£¬ÈçÏÂͼʾ£º
µã»÷NewÅäÖÃÐéÄâIPµØÖ·£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£ µÚһ̨ProxySG800-2µÄÐéÄâIPµØÖ·Îª£º191.32.1.13 µÚ¶þ̨ProxySG800-2µÄÐéÄâIPµØÖ·Îª£º191.32.1.14
2.4.5 ÅäÖÃFail Over
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Advanced½øÈ룬ÔÚ´°¿ÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñFailover£¬ÈçÏÂͼʾ£º
µã»÷NewÅäÖÃFailover×飬ÈçÏÂͼʾ£º
ÔÚµ¯³ö´°¿ÚÖУ¬Ñ¡ÔñExisting IP£¬²¢ÔÚÏÂÀ¿òÖÐÑ¡ÔñÒѶ¨ÒåµÄÐéÄâIPµØÖ·£º191.32.1.13£¨µÚһ̨ProxySG800£©£¬191.32.1.14£¨µÚ¶þ̨ProxySG800£©£¬ÔÚGroup SettingÖУ¬Ñ¡ÔñEnable£¬²¢ÔÚRelative PriorityÖÐÑ¡ÖÐMaster£¬µã»÷OKÍê³ÉÅäÖᣲ¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
µã»÷NewÅäÖÃÁíÒ»¸öFailover×飬ÈçÏÂͼʾ£º
ÔÚµ¯³ö´°¿ÚÖУ¬Ñ¡ÔñNew IP£¬Ö¸¶¨ÐéÄâIPµØÖ·£º191.32.1.14£¨µÚһ̨ProxySG800£©£¬191.32.1.13£¨µÚ¶þ̨ProxySG800£©£¬ÔÚGroup SettingÖУ¬Ñ¡ÔñEnable£¬µã»÷OKÍê³ÉÅäÖᣲ¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.5 ÅäÖôúÀí·þÎñ¶Ë¿Ú
ÔÚxxxxxÍøÂçÖÐProxySG½«ÌṩHTTP£¨80¶Ë¿Ú£©¡¢SOCKS£¨1080¶Ë¿Ú£©¡¢DNS(53¶Ë¿Ú)µÄ´úÀí·þÎñ£¬ÆäËüͨѶÈ磺MSN¡¢Á÷ýÌåµÈ¾ùͨ¹ýHTTP»òSOCKS´úÀíʵÏÖ¡£
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Services/Service Ports½øÈ룬ÈçÏÂͼʾ£º
ÆäÖУ¬SSH-Console£¨22£©¡¢Telnet-Console£¨23£©¡¢HTTP-Console£¨8081£©ÊÇΪϵͳ¹ÜÀíÌṩ·þÎñµÄ¶Ë¿Ú£¬¿ÉÒÔ¸ù¾ÝÍøÂç¹ÜÀíÒªÇóÑ¡ÔñÊÇ·ñ¿ª·Å£»DNS-Proxy£¨53£©¡¢HTTP£¨80£©ºÍSOCKS£¨1080£©±ØÐëEnable£¨Yes£©£¬²¢ÇÒ°üÀ¨ExplicitÊôÐÔ£¬HTTP£¨80£©ÐèÒª°üÀ¨TransparentÊôÐÔ¡£²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.6 ÅäÖñ¾µØÊ±ÖÓ
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/General/Clock½øÈ룬ÈçÏÂͼʾ£º
Ñ¡Ôñ±¾µØÊ±ÖÓ¶¨ÒåΪ£«8Çø£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.7 ÅäÖÃRadiusÈÏÖ¤·þÎñ
»¥ÁªÍø·ÃÎÊÓû§½«²ÉÓÃRadius½øÐÐÓû§ÈÏÖ¤£¬Óû§·Ö×éͨ¹ýRadiusµÄÊôÐÔ½øÐж¨Ò壬·Ö×éÓëÊôÐÔ¶ÔÓ¦¹ØÏµÈçÏ£º
¹¤×÷×é ¹ÜÀí×é ¸ß¼¶×é ÆÕͨ×é ÁÙʱ×é
Login(1) Framed(2) Call Back login(3) Call Back Framed(4) Outbound(5)
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Authentication/RADIUS½øÈ룬ÈçÏÂͼʾ£º
µã»÷NewÉú³ÉRADIUSÅäÖã¬ÔÚµ¯³ö´°¿ÚÖж¨ÒåRadius·þÎñÆ÷µØÖ·£¬ÈçÏÂͼʾ£º
ÆäÖУ¬Real Name¶¨ÒåΪRADIUS£¬Primary server hostÖж¨ÒåRADIUS·þÎñÆ÷IPµØÖ·£º191.32.1.22£¨Ôݶ¨£©£¬PortΪ1812£¬SecretΪRADIUSÖж¨ÒåµÄͨѶÃÜÂ룻µã»÷OKÍê³É¶¨Òå¡£²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
×¢£ºPortºÍSecretµÄ¶¨Ò屨ÐëÓëRADIUS·þÎñÆ÷Öж¨Òå±£³ÖÒ»Ö¡£
ÈçÐ趨Ò屸·ÝµÄRADIUS·þÎñÆ÷£¬ÔÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñRADIUS Servers£¬ÈçÏÂͼʾ£º
ÔÚAlternate Server¶¨ÒåÖУ¬¶¨Ò屸ÓõÄRADIUS·þÎñÆ÷IPµØÖ·£¬¼°Í¨Ñ¶ÃÜÂë¡£
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Authentication/Transparent Proxy½øÈ룬ÈçÏÂͼʾ£º
ÆäÖУ¬MethodÑ¡¶¨IP£¬ÔÚIP TTLÖж¨Òå240·ÖÖÓ£¨4¸öСʱ£©£¬Óû§ÈÏÖ¤Ò»´Î½«±£³Ö4Сʱ£»²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.8 ÄÚÈݹýÂËÁÐ±í¶¨Òå¼°ÏÂÔØ
ÔÚProxySGÖмÓÔØBlue Coat·ÖÀàÁбí×÷Ϊ»¥ÁªÍø·ÃÎÊ¿ØÖƼ°Anti-Spyware²ßÂԵĻù´¡¡£
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Content Filtering/Bluecoat½øÈ룬ÈçÏÂͼʾ£º
ÊäÈëÓû§Ãû/ÃÜÂ룬ѡÔñForce Full Update£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ£¬È»ºóµã»÷Download Now¿ªÊ¼ÏÂÔØ·ÖÀàÁбí¿â¡£
·ÖÀàÁбíÏÂÔØ½áÊøºó£¨µÚÒ»´ÎÏÂÔØ³¬¹ý80MbypesÊý¾Ý£¬ËùÐèʱ¼äÓëÍøÂçºÍ´ø¿íÓйأ©£¬¶¨Òå×Ô¶¯ÏÂÔØ¸üУ¬ÔÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñAutomatic Download£¬ÈçÏÂͼʾ£º
ÆäÖУºÑ¡ÔñÿÌìUTCʱ¼äÏÂÎç4:00£¨±¾µØÊ±¼äÍíÉÏ12:00£©×Ô¶¯ÏÂÔØ¸üУ¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
Æô¶¯¶¯Ì¬·ÖÀàģʽ£¬ÔÚÉϲ¿²Ëµ¥Ñ¡ÔñDynamic Categorization£¬ÈçÏÂͼʾ£º
Ñ¡ÔñEnable Dynamic CategorizationºÍCategorize dynamically in the background£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
Ñ¡¶¨Ê¹Blue Coat·ÖÀàÁбíÉúЧ£¬´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Content Filtering/General½øÈ룬ÈçÏÂͼʾ£º
Ñ¡¶¨Use Blue Coat Web Filter£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.9 ¶¨Ò岡¶¾É¨Ãè·þÎñÆ÷
¶ÔËùÓÐͨ¹ýProxySGµÄHTTP¡¢FTPͨѶ½øÐв¡¶¾É¨Ã裬²¡¶¾É¨Ãè·þÎñÆ÷²ÉÓÃMcAfee£¬ProxySGͨ¹ýICAPÐÒéʵÏÖÓëMcAfee²¡¶¾É¨Ãè·þÎñÆ÷ͨѶ¡£
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/External Services/ICAP½øÈ룬µã»÷NewÉú³ÉICAP·þÎñÅäÖã¬ÈçÏÂͼʾ£º
ServiceÃûΪMcAfee_1ºÍMcAfee_2£¬Ñ¡Ôñ·þÎñÃûMcAfee_1£¬²¢µã»÷Edit£¬½øÈë·þÎñÅäÖô°¿Ú£¬ÈçÏÂͼʾ£º
ÔÚService URLÖУ¬¶¨Òåicap://10.32.0.15£¬²¢µã»÷Sense settings´ÓMcAfee»ñÈ¡²¡¶¾É¨Ãè²ÎÊýÅäÖ㬵ã»÷Register¶¨Òå½øÐн¡¿µ¼ì²é£¬µã»÷OKÍê³É¶¨Ò壬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
Ñ¡Ôñ·þÎñÃûMcAfee_2£¬²¢µã»÷Edit£¬Öظ´ÒÔÉϹý³Ì£¬²¢ÔÚService URLÖж¨Òåicap://10.32.0.16¡£
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/External Services/Serice-Group½øÈ룬½«Á½Ì¨McAfee·þÎñÆ÷¶¨ÒåΪһ¸öGroup£¬µã»÷NewÉú³ÉService GroupÅäÖÃÈçÏÂͼʾ£º
Service GroupÃû¶¨ÒåΪMcAfee_Group£¬µã»÷Edit½øÐзþÎñÆ÷×鶨Ò壬ÈçÏÂͼʾ£º
ͨ¹ýµã»÷New½«McAfee_1ºÍMcAfee_2¼ÓÈëMcAfee_GroupÖУ¬µã»÷Edit¿ÉÒԸıäGroup³ÉÔ±µÄÈ¨ÖØ£¬Ñ¡ÔñOKÍê³ÉÅäÖ㬲¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.10 ´ø¿í¹ÜÀí¶¨Òå
¸ù¾Ý´ø¿í¹ÜÀí²ßÂÔÒªÇ󣬶¨ÒåÆß¸ö´ø¿íÀ࣬ÆäÖÐWork_Group_Bandwidth¡¢Management_Group_Bandwidth¡¢High_Level_Group_Bandwidth¡¢
Normal_Group_Bandwidth¡¢Temp_Group_Bandwidth·Ö±ð¶ÔÓ¦¹¤×÷×é¡¢¹ÜÀí×é¡¢¸ß¼¶×é¡¢ÆÕͨ×é¡¢ÁÙʱ×éµÄ´ø¿í¹ÜÀíÒªÇó£¬Limit_App_Bandwidth¶ÔÓ¦¸ß´ø¿íÏûºÄÓ¦ÓõĴø¿í¹ÜÀí²ßÂÔ£¬Key_App_Bandwidth¶ÔÓ¦¹Ø¼üÓ¦ÓÃÍøÕ¾µÄ´ø¿í¹ÜÀí²ßÂÔ¡£
´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Bandwidth Mgmt./BWM Classes½øÈ룬µã»÷New¶¨Òå´ø¿íÀ࣬ÈçÏÂͼʾ£º
ÆäÖУ¬ÐèÑ¡ÖÐEnable Bandwidth Management£¬¶¨Òå´ø¿íÀ࣬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.11 ²ßÂÔÉèÖÃ
2.11.1 ÅäÖÃDDOS¹¥»÷·ÀÓù
ͨ¹ýTelnet¡¢SSH»òConsole½øÈëProxySGµÄÃüÁîÐйÜÀí½çÃæ£¬½øÈëenable״̬£¬Í¨¹ýÃüÁîconf t½øÈëÅäÖÃ״̬£¬Í¨¹ýÒÔÏÂÃüÁîÆô¶¯DDOS·ÀÓù£º
attack-detection client enable-limits
2.11.2 ÉèÖÃȱʡ²ßÂÔΪDENY
´ÓWeb¹ÜÀí½çÃæManagement Console/configuration/Policy/Policy Options½øÈëȱʡ²ßÂÔÉèÖã¬ÈçÏÂͼʾ£º
ÆäÖУ¬Ñ¡ÔñDENY£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£
2.11.3 ÅäÖÃBlue Coat Anti-Spyware²ßÂÔ
´ÓWeb¹ÜÀí½çÃæManagement Console/configuration/Policy/Policy Files½øÈëȱʡ²ßÂÔÉèÖã¬ÈçÏÂͼʾ£º
ÔÚInstall Local File FromµÄÏÂÀ¿òÖÐÑ¡ÔñLocal File£¬µã»÷Install£¬ÈçÏÂͼʾ£º
ÔÚµ¯³öµÄ´°¿ÚÖУ¬µã»÷ä¯ÀÀ£¬²¢Ñ¡¶¨Blue Coat·¢²¼µÄAnti-Spyware²ßÂÔ£¬Ñ¡ÔñInstall½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.4 ·ÃÎÊ¿ØÖƲßÂÔÅäÖÃ-VPM
·ÃÎÊ¿ØÖƲßÂÔͨ¹ýBlue CoatͼÊÓ»¯½çÃæVPM½øÐÐÅäÖ㬴ÓWeb¹ÜÀí½çÃæManagement Console/configuration/Policy/ Visual Policy Manager½øÈ룬²¢µã»÷Launch£¬¼´¿ÉÆô¶¯VPM½çÃæ£¬ÈçÏÂͼʾ£º
2.11.5 ²¡¶¾É¨Ãè²ßÂÔÅäÖÃ
¶¨Òå¶ÔËùÓÐͨ¹ýProxySGµÄÁ÷Á¿½øÐв¡¶¾É¨Ã裬ʹÓò¡¶¾É¨Ãè·þÎñÆ÷×éMcAfee_Group¡£
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Content Layer£¬Éú³ÉWebÄÚÈÝ¿ØÖƲßÂԲ㣬Ãû×Ö¶¨ÒåΪWeb AV£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬ActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Set ICAP Response Service£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÔÚUse ICAP response serviceµÄÏÂÀ¿òÖÐÑ¡ÔñMcAfee_Group£¬²¢Ñ¡¶¨Continure without further ICAP response£¬µã»÷OK£¬Í˵½ÉÏÒ»²ã£¬ÔÚ´°¿ÚÖÐÑ¡ÔñICAPResponseService1£¬²¢µã»÷OK£¬Íê³É¹æÔòÉèÖã»ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.6 Óû§ÈÏÖ¤²ßÂÔÉèÖÃ
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Authentication Layer£¬Éú³ÉWeb·ÃÎÊÓû§ÈÏÖ¤²ã£¬Ãû×Ö¶¨ÒåΪWeb_Radius_Auth£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬ActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Authenticate£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÔÚµ¯³öµÄ´°¿ÚÖУ¬RealmÀ¸Ñ¡¶¨radius(RADIUS)£¬ModeÖÐÑ¡¶¨Proxy IP£¬µã»÷OK£¬Í˵½ÉÏÒ»²ã£¬ÔÚ´°¿ÚÖÐÑ¡ÔñAuthenticate1£¬²¢µã»÷OK£¬Íê³É¹æÔòÉèÖã»ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd SOCKS Authentication Layer£¬Éú³ÉSOCKS·ÃÎÊÓû§ÈÏÖ¤²ã£¬Ãû×Ö¶¨ÒåΪSOCKS_Radius_Auth£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬ActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨SOCKS Authenticate£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÆäÖУ¬RealmÖÐÑ¡¶¨radius(RADIUS)£¬µã»÷OK£¬Í˵½ÉÏÒ»²ã£¬ÔÚ´°¿ÚÖÐÑ¡ÔñSOCKSAuthenticate1£¬²¢µã»÷OK£¬Íê³É¹æÔòÉèÖã»ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.7 ´ø¿í¹ÜÀí²ßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪBandwidth_Management£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Attribute£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÆäÖУ¬¶¨ÒåNameΪWork_Group£¬Authentication RealmÑ¡¶¨
RADIUS(RADIUS)£¬RADIUS AttributeÑ¡¶¨Login(1)£¬Ñ¡ÔñOK£¬Íê³ÉÊôÐÔ¶¨Òå¡£
ÖØ¸´ÒÔÉϹý³Ì·Ö±ð¶¨ÒåNameΪManagement_Group¡¢High_Level_Group¡¢Normal_Group¡¢Temp1_Group£¬Temp0_Group£¬Temp2_Group·Ö±ð¶ÔÓ¦RADIUS AttributeΪFramed(2)¡¢Call Back login(3)¡¢Call Back Framed(4)¡¢Outbound(5)¡¢NAS Prompt(7)¡¢Administrative(6)¡£
ÔÚµÚÒ»Ìõ¹æÔòµÄServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÆäÖУ¬Ñ¡¶¨P2PºÍAll P2P£¬²¢Ñ¡ÔñOK£¬Íê³É¶¨Òå¡£
ÔÚµÚÒ»Ìõ¹æÔòµÄDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨URL£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÔÚSimple MatchÖÐÖ¸¶¨¹Ø¼üÒµÎñµÄÓòÃû£¬Ñ¡ÔñAddÔö¼Ó¶¨Ò壬ѡÔñClose½áÊø¶¨Òå¡£
ÔÚµÚÒ»Ìõ¹æÔòµÄActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Manage Bandwidth£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÆäÖУ¬Name¶¨ÒåΪKey_App_Bandwidth£¬Limit Bandwidth onÖÐÑ¡¶¨Server SideºÍInbound£¬ÔÚBandwidth ClassÖÐÑ¡¶¨Key_App_Bandwidth£¬Ñ¡ÔñOKÍê³É¶¨Ò壻
ÖØ¸´ÒÔÉϹý³Ì£¬¶¨ÒåÃûNameΪLimit_App_Bandwidth_in£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪLimit_App_Bandwidth£»
¶¨ÒåÃûNameΪLimit_App_Bandwidth_out£¬ÊôÐÔΪServer Side Outbound£¬Bandwidth ClassΪLimit_App_Bandwidth£»
¶¨ÒåÃûNameΪWork_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪWork_Group_Bandwidth£»
¶¨ÒåÃûNameΪManagement_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪManagement_Group_Bandwidth£»
¶¨ÒåÃûNameΪHigh_Level_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪHigh_Level_Group_Bandwidth£»
¶¨ÒåÃûNameΪNormal_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪNormal_Group_Bandwidth£»
¶¨ÒåÃûNameΪTemp_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪTemp_Group_Bandwidth¡£
ÔÚVPM½çÃæµã»÷Add RuleÔö¼ÓÆßÌõ¹æÔò£¬×ܹ²°ËÌõ¹æÔò£¬
µÚÒ»Ìõ¹æÔò¶¨Ò壺ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñÒÔÉ϶¨ÒåµÄ¹Ø¼üÒµÎñURL£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñKey_App_Bandwidth£»
µÚ¶þÌõ¹æÔò¶¨Ò壺ÔÚServiceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñAll P2P£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñLimit_App_Bandwidth_in£»
µÚÈýÌõ¹æÔò¶¨Ò壺ÔÚServiceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñAll P2P£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñLimit_App_Bandwidth_out£»
µÚËÄÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñWork_Group_Bandwidth£»
µÚÎåÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñManagement_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñManagement_Group_Bandwidth£»
µÚÁùÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñHigh_Level_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñHigh_Level_Group_Bandwidth£»
µÚÆßÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñNormal_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñNormal_Group_Bandwidth£»
µÚ°ËÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñTemp_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñTemp_Group_Bandwidth¡£
Íê³É¶¨ÒåÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.8 Work_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪWork_Group_Policy£¬Í¨¹ýAdd RuleÔö¼ÓÁ½Ìõ¹æÔò¡£
ÔÚµÚÒ»Ìõ¹æÔòµÄServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÆäÖУ¬Ñ¡¶¨SOCKSºÍAll SOCKS£¬²¢Ñ¡ÔñOK£¬Íê³É¶¨Òå¡£
ÔÙÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡¶¨StreamingºÍAll Streaming¡£
ÔÚVPM²Ëµ¥Ñ¡ÔñAdd RuleÔö¼ÓÁ½Ìõ¹æÔò£¬¹²ÈýÌõ¹æÔò¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All SOCKS£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All Streaming£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚÈýÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.9 Management_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪManagement_Group_Policy¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñManagement_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.10 High_Level_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪHigh_Level_Group_Policy¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñHigh_Level_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.11 Normal_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪNormal_Group_Policy¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNormal_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All Streaming£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNormal_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.12 Temp1_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪTemp1_Group_Policy¡£
ÔÚµÚÒ»Ìõ¹æÔòµÄServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÆäÖУ¬Ñ¡¶¨FTPºÍAll FTP£¬²¢Ñ¡ÔñOK£¬Íê³É¶¨Òå¡£
ÔÚVPM²Ëµ¥Ñ¡ÔñAdd RuleÔö¼ÓËÄÌõ¹æÔò£¬¹²ÎåÌõ¹æÔò¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All SOCKS£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All Streaming£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚÈýÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All FTP£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚËÄÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨New£¬Ñ¡ÔñURL£¬¶¨ÒåSimple MatchÖÐÓòÃûΪpassport.com£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚÎåÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.13 Temp0_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪTemp0_Group_Policy¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp0_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.14 Temp2_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪTemp2_Group_Policy¡£
ÔÚVPM²Ëµ¥Ñ¡ÔñAdd RuleÔö¼Ó¶þÌõ¹æÔò£¬¹²ÈýÌõ¹æÔò¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp2_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All SOCKS£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp2_Group£¬ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨New£¬Ñ¡ÔñURL£¬¶¨ÒåSimple MatchÖÐÓòÃûΪpassport.com£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£
ÔÚµÚÈýÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp2_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.15 IEä¯ÀÀÆ÷°æ±¾¼ì²é²ßÂÔ
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪBrowser_Version_Check£¬Í¨¹ýAdd RuleÔö¼ÓÒ»Ìõ¹æÔò£¬¹²Á½Ìõ¹æÔò¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡ÔñRequest Header£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
ÆäÖУ¬Name¶¨ÒåΪRequestHeader_IE6£¬ÔÚHeader NameÏÂÀ¿òÖÐÑ¡ÔñUser-Agent£¬ÔÚHeader RegexÖÐÊäÈë.*MSIE6.*£¬µã»÷OKÍê³É¶¨Òå¡£
ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñRequestHeader_IE6£¬ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖеã»÷New£¬Ñ¡ÔñURL£¬¶¨Òåmicrosoft.com£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£
ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñRequestHeader_IE6£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬²¢Ñ¡ÔñDeny£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º
Ñ¡¶¨Force Deny£¬DetailsÌáʾΪ£ºPlease upgrade your Browser to IE6.x£¬µã»÷OKÍê³É¶¨Ò壬²¢ÔÚ·µ»ØµÄ´°¿ÚÖÐÑ¡¶¨Deny1£¬µã»÷OK£¬Íê³É¶¨Òå¡£ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.11.16 DNS½âÎö²ßÂÔÉèÖÃ
ProxySG½«ÎªÓû§ÌṩDNS½âÎö·þÎñ£¬½«¶Ô½âÎöÇëÇóÓ¦´ðProxySGµÄIPµØÖ·£¬ÅäÖùý³ÌÈçÏ£º
´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd DNS Access Layer£¬Éú³ÉDNS·ÃÎÊ¿ØÖƲ㣬ÔÚµÚÒ»Ìõ¹æÔòµÄActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡ÔñSend DNS Response£¬ÈçÏÂͼʾ£º
ÆäÖУºNameΪSendDNSResponse_CCB£¬HostΪJiangSu_CCB£¬Ñ¡¶¨Responds with incoming proxy IP£¬Ñ¡ÔñOK£¬²¢Ôڲ˵¥ÖÐÑ¡¶¨SendDNSResponse_CCB£¬Ñ¡ÔñOKÍê³É¶¨Ò壬ÈçÏÂͼʾ£º
ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£
2.12 Anti-Spyware²ßÂÔ
Blue Coat¶¨ÆÚ·¢²¼Anti-Spyware²ßÂÔ£¬¸Ã²ßÂÔ»ùÓÚBlue Coat URLÁÐ±í£¬Òò´Ë±ØÐëÔÚBlue Coat URL·ÖÀàÁбíÏÂÔØ½áÊø²¢ÉúЧºó£¬²ÅÄܰ²×°¸Ã²ßÂÔ¡£
ÔÚ»ñµÃAnti-Spyware²ßÂÔÎļþºó£¬´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Policy/Policy Files½øÈ룬ÈçÏÂͼʾ£º
ÔÚInstall Local File FromÑ¡ÏîÖÐÑ¡ÔñLocal File£¬²¢µã»÷Install£¬ÔÚµ¯³ö´°¿ÚÖÐBrowseµ½Anti-Spyware²ßÂÔÎÊÌ⣬²¢½«Æä°²×°µ½ProxySGÖУ¬²ßÂÔ¼´ÉúЧ¡£
Èç¹ûÐèÒª¶¨ÒåÌØ¶¨ÍøÕ¾²»ÊÜAnti-Spyware²ßÂÔµÄÓ°Ï죬ÐèÆô¶¯VPM
£¨Management Console/Configuration/Policy/Visual Policy Manager£©£»ÔÚVPM²Ëµ¥ConfigurationÖÐÑ¡ÔñEdit Categories£¬ÈçÏÂͼʾ£º
½«PolicyÕ¹¿ª£¬²¢Ñ¡¶¨Additional_Spyware_Trusted_Sites£¬µã»÷Edit URLs£¬²¢ÔÚµ¯³ö´°¿ÚÖУ¬½«Ö¸¶¨ÓòÃû¼ÓÈ룬ÈçÏÂͼʾ£º
¿ÉÒÔ¼Ó¶àÐУ¬µã»÷OK£¬Íê³É¶¨Ò壬ÔÚµã»÷OK»Øµ½VPMÒ³Ãæ£¬²¢µã»÷Install PolicyʹÅäÖÃÉúЧ¡£
2.13 PACÎļþ¶¨Òå
PACÎļþ¶¨ÒåIEä¯ÀÀÆ÷ÉÏÍø´úÀíµÄ½Å±¾£¬¿ÉÒÔ¼ÓÔØµ½ProxySGÖУ¬PACΪÎı¾Îļþ£¬¶¨ÒåÈçÏ£º
function FindProxyForURL(url, host) {
if (isInNet(host, \ return \ else
return \ }
ÆäÖУº191.0.0.0/24ΪxxxxxÄÚ²¿Íø¶Î£¬Èç¹û»¹ÓÐÆäËüÍø¶Î£¬¿ÉÒÔÔö¼Óif¶¨Ò壻191.32.1.15ΪCIDÐéÄâ³öµÄIPµØÖ·£¬ÓÃÀ´¸øÉÏÍøÓû§×ö´úÀí¡£
ͨ¹ýTelnet»òSSH½øÈëProxySGÃüÁîÐнçÃæ£¬Í¨¹ýEnableÃüÁî½øÈë¹ÜÀí״̬£¬Ê¹ÓÃÒÔÏÂÃüÁî¼ÓÔØPACÎļþÅäÖãº
#inline accelerated-pac
function FindProxyForURL(url, host) {
if (isInNet(host, \ return \ else
return \ }
·ÃÎÊProxySGÖеÄPACÎļþµÄ·¾¶Îª£º
http:// 191.32.1.13/accelerated_pac_base.pac
ÅäÖÃIEä¯ÀÀÆ÷ʹÓøÃPACÎļþÉÏÍø£¬´Óä¯ÀÀÆ÷²Ëµ¥½øÈëÅäÖ㺹¤¾ß/InternetÑ¡Ïî/Á¬½Ó/¾ÖÓòÍøÉèÖ㬵¯³ö´°¿ÚÈçÏÂͼʾ£º
ÔÚÆäÖÐÑ¡¶¨¡°Ê¹ÓÃ×Ô¶¯ÅäÖýű¾¡±£¬µØÖ·À¸ÖÐÊäÈ룺
http:// 191.32.1.13/accelerated_pac_base.pac
ÕâÑù£¬ËùÓÐ¶ÔÆóÒµÍøÂçµÄ·þÎñÆ÷IP·ÃÎʽ«²»»áʹÓôúÀí£¬¶ø¶Ô»¥ÁªÍøµÄ·ÃÎʽ«Í¨¹ýProxySG´úÀí¡£