BlueCoat´úÀí·þÎñÆ÷ÅäÖÃ˵Ã÷ - template ÏÂÔØ±¾ÎÄ

»¥ÁªÍø´úÀí°²È«Íø¹Ø¹¦ÄÜÐèÇóÎĵµ

2011Äê1ÔÂ

Ŀ ¼

Ò»¡¢ °²×°É豸¼°°²×°»·¾³ ........................................................................................ 4 1.1 ʵʩÉ豸Çåµ¥.................................................................................................... 4 1.2 ÊµÊ©ÍØÆÓ½á¹¹Í¼................................................................................................ 4 ¶þ¡¢ ʵʩ²½Öè ............................................................................................................ 4 2.1 ÎïÀíÁ¬½Ó............................................................................................................ 4 2.2 ³õʼIPµØÖ·ÅäÖà .............................................................................................. 4 2.3 Ô¶³Ì¹ÜÀíÈí¼þÅäÖÃ............................................................................................ 5 2.4 ÍøÂçÅäÖÃ............................................................................................................ 5 2.4.1 Adapter 1µØÖ·ÅäÖà .................................................................................... 6 2.4.2 ¾²Ì¬Â·ÓÉÅäÖà ............................................................................................ 6 2.4.3 ÅäÖÃÍâÍøDNS·þÎñÆ÷ ............................................................................... 8 2.4.4 ÅäÖÃÐéÄâIPµØÖ· ....................................................................................... 8 2.4.5 ÅäÖÃFail Over ............................................................................................ 9 2.5 ÅäÖôúÀí·þÎñ¶Ë¿Ú.......................................................................................... 11 2.6 ÅäÖñ¾µØÊ±ÖÓ.................................................................................................. 12 2.7 ÅäÖÃRADIUSÈÏÖ¤·þÎñ .................................................................................... 12 2.8 ÄÚÈݹýÂËÁÐ±í¶¨Òå¼°ÏÂÔØ.............................................................................. 15 2.9 ¶¨Ò岡¶¾É¨Ãè·þÎñÆ÷...................................................................................... 17 2.10 ´ø¿í¹ÜÀí¶¨Òå................................................................................................ 21 2.11 ²ßÂÔÉèÖÃ........................................................................................................ 22 2.11.1 ÅäÖÃDDOS¹¥»÷·ÀÓù ............................................................................ 22 2.11.2 ÉèÖÃȱʡ²ßÂÔΪDENY ......................................................................... 22 2.11.3 ÅäÖÃBlue Coat Anti-Spyware²ßÂÔ ........................................................ 23 2.11.4 ·ÃÎÊ¿ØÖƲßÂÔÅäÖÃ-VPM ....................................................................... 24

2.11.5 ²¡¶¾É¨Ãè²ßÂÔÅäÖà ................................................................................ 24 2.11.6 Óû§ÈÏÖ¤²ßÂÔÉèÖà ................................................................................ 26 2.11.7 ´ø¿í¹ÜÀí²ßÂÔ¶¨Òå ................................................................................ 28 2.11.8 Work_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå .............................................. 33 2.11.9 Management_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå .................................. 35 2.11.10 High_Level_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå .................................. 35 2.11.11 Normal_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå ......................................... 36 2.11.12 Temp_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå ............................................ 36 2.11.13 IEä¯ÀÀÆ÷°æ±¾¼ì²é²ßÂÔ ...................................................................... 40 2.11.14 DNS½âÎö²ßÂÔÉèÖà .............................................................................. 41

Ò»¡¢ °²×°É豸¼°°²×°»·¾³

1.1 ʵʩÉ豸Çåµ¥

Bluecoat°²È«´úÀíרÓÃÉ豸SG600£­10һ̨£¬AV510-Aһ̨£¬BCWFÄÚÈݹýÂË£¬MCAFEE·À²¡¶¾,ÆóÒµ°æ±¨±íÄ£¿é¡£

1.2 ÊµÊ©ÍØÆÓ½á¹¹Í¼

BluecoatÉ豸SG600-10£­3ÅäÖÃÓÚÄÚÍø£¬AV510-AÓëSG600-10Ö®¼äͨ¹ýICAPЭÒ齨Á¢Í¨ÐÅ¡£Á¬½Ó·½·¨ÓÐÒÔϼ¸ÖÖ£¬ÍøÂçʾÒâ½á¹¹ÈçÏÂͼ£º

ÅÔ·ģʽ£º

¶þ¡¢ ʵʩ²½Öè

2.1 ÎïÀíÁ¬½Ó

Á½Ì¨Bluecoat SG800£­2µÄAdapter0_Interface 0ºÍAdapter1_Interface0ͨ¹ýÒÔÌ«ÍøË«½ÊÏßÁ¬½ÓÓÚÁ½Ì¨Radware CID½»»»»ú¡£

2.2 ³õʼIPµØÖ·ÅäÖÃ

ͨ¹ýÉ豸ǰ¿ØÖÆÃæ°å¿ÉÒÔÉèÖÃProxySG800-2µÄAdapter0_Interface0µÄµØÖ·Îª£º

µÚһ̨SG800£­2£º191.32.1.9(IP)

255.255.255.224(Mask) 191.32.1.1(Default Gateway)

µÚ¶þ̨SG800£­2£º191.32.1.11(IP)

255.255.255.224(Mask) 191.32.1.1(Default Gateway)

2.3 Ô¶³Ì¹ÜÀíÈí¼þÅäÖÃ

Bluecoat°²È«´úÀíרÓÃÉ豸ͨ¹ýIEä¯ÀÀÆ÷ºÍSSHÃüÁî½øÐйÜÀí£¬ä¯ÀÀÆ÷¹ÜÀí¶Ë¿ÚΪ8082£¬¹ÜÀíÓõÄPC»úÐè°²×°ÁËJavaÔËÐл·¾³¡£¹ÜÀí½çÃæµÄURLΪ£º

https://191.32.1.9:8082ºÍhttps://191.32.1.11:8082

2.4 ÍøÂçÅäÖÃ

ÔÚxxxxxÍøÂç»·¾³ÖУ¬(1)ProxySG800-2Á½¸ö¶Ë¿Ú¾ùÐèÅäÖÃIPµØÖ·£»(2)³ýȱʡ·ÓÉÖ¸Ïò·À»ðǽ£¬»¹ÐèÒ»Ìõ¾²Ì¬Â·ÓÉ£¬×÷ΪÄÚÍøÍ¨Ñ¶µÄ·ÓÉ£¬(3)ÅäÖÃÍâÍøDNS£¬ÒÔ±ãProxySGµ½»¥ÁªÍøµÄ·ÃÎÊ£¬(4) ÿ̨ÁíÍâÐèÒªÒ»¸öÐéÄâIPµØÖ·£¬×÷ΪÄÚ²¿Ô±¹¤

µÄDNS½âÎö·þÎñÆ÷IPµØÖ·£»(5)¶ÔÐéÄâIPµØÖ·ÅäÖÃFail Over£¬µ±Ò»Ì¨ProxySGÍ£Ö¹¹¤×÷£¬ÆäÐéÄâIP½«Çл»µ½ÁíÍâһ̨¡£

2.4.1 Adapter 1µØÖ·ÅäÖÃ

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Adapter½øÈ룬ÔÚAdaptersÏÂÀ­¿òÖÐÑ¡ÔñAdapter1£¬²¢ÔÚIP address for Interface 0ºÍ Subnet mask for Interface 0ÖÐÅäÖÃIPµØÖ·ºÍ×ÓÍøÑÚÂ룬ÈçÏÂͼʾ£º

µÚһ̨ProxySG800-2µÄIPµØÖ·Îª£º191.32.1.10£¬ÑÚÂ룺255.255.255.224 µÚ¶þ̨ProxySG800-2µÄIPµØÖ·Îª£º191.32.1.12£¬ÑÚÂ룺255.255.255.224 µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.4.2 ¾²Ì¬Â·ÓÉÅäÖÃ

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Routing½øÈ룬ÔÚ´°¿ÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñRouting£¬²¢ÔÚInstall Routing table fromÏÂÀ­¿òÖÐÑ¡ÔñText Editor£¬ÈçÏÂͼʾ£º

µã»÷Install£¬²¢ÔÚµ¯³ö´°¿ÚÖÐÊäÈ뾲̬·ÓÉ£º 191.0.0.0 255.0.0.0 191.32.1.5 ÈçÏÂͼʾ£º

µã»÷InstallʹÅäÖÃÉúЧ¡£

2.4.3 ÅäÖÃÍâÍøDNS·þÎñÆ÷

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/DNS½øÈ룬ÈçÏÂͼʾ£º

µã»÷NewÔö¼ÓÍâÍøDNS·þÎñÆ÷IPµØÖ·£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.4.4 ÅäÖÃÐéÄâIPµØÖ·

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Advanced½øÈ룬ÔÚ´°¿ÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñVIPs£¬ÈçÏÂͼʾ£º

µã»÷NewÅäÖÃÐéÄâIPµØÖ·£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£ µÚһ̨ProxySG800-2µÄÐéÄâIPµØÖ·Îª£º191.32.1.13 µÚ¶þ̨ProxySG800-2µÄÐéÄâIPµØÖ·Îª£º191.32.1.14

2.4.5 ÅäÖÃFail Over

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Network/Advanced½øÈ룬ÔÚ´°¿ÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñFailover£¬ÈçÏÂͼʾ£º

µã»÷NewÅäÖÃFailover×飬ÈçÏÂͼʾ£º

ÔÚµ¯³ö´°¿ÚÖУ¬Ñ¡ÔñExisting IP£¬²¢ÔÚÏÂÀ­¿òÖÐÑ¡ÔñÒѶ¨ÒåµÄÐéÄâIPµØÖ·£º191.32.1.13£¨µÚһ̨ProxySG800£©£¬191.32.1.14£¨µÚ¶þ̨ProxySG800£©£¬ÔÚGroup SettingÖУ¬Ñ¡ÔñEnable£¬²¢ÔÚRelative PriorityÖÐÑ¡ÖÐMaster£¬µã»÷OKÍê³ÉÅäÖᣲ¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

µã»÷NewÅäÖÃÁíÒ»¸öFailover×飬ÈçÏÂͼʾ£º

ÔÚµ¯³ö´°¿ÚÖУ¬Ñ¡ÔñNew IP£¬Ö¸¶¨ÐéÄâIPµØÖ·£º191.32.1.14£¨µÚһ̨ProxySG800£©£¬191.32.1.13£¨µÚ¶þ̨ProxySG800£©£¬ÔÚGroup SettingÖУ¬Ñ¡ÔñEnable£¬µã»÷OKÍê³ÉÅäÖᣲ¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.5 ÅäÖôúÀí·þÎñ¶Ë¿Ú

ÔÚxxxxxÍøÂçÖÐProxySG½«ÌṩHTTP£¨80¶Ë¿Ú£©¡¢SOCKS£¨1080¶Ë¿Ú£©¡¢DNS(53¶Ë¿Ú)µÄ´úÀí·þÎñ£¬ÆäËüͨѶÈ磺MSN¡¢Á÷ýÌåµÈ¾ùͨ¹ýHTTP»òSOCKS´úÀíʵÏÖ¡£

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Services/Service Ports½øÈ룬ÈçÏÂͼʾ£º

ÆäÖУ¬SSH-Console£¨22£©¡¢Telnet-Console£¨23£©¡¢HTTP-Console£¨8081£©ÊÇΪϵͳ¹ÜÀíÌṩ·þÎñµÄ¶Ë¿Ú£¬¿ÉÒÔ¸ù¾ÝÍøÂç¹ÜÀíÒªÇóÑ¡ÔñÊÇ·ñ¿ª·Å£»DNS-Proxy£¨53£©¡¢HTTP£¨80£©ºÍSOCKS£¨1080£©±ØÐëEnable£¨Yes£©£¬²¢ÇÒ°üÀ¨ExplicitÊôÐÔ£¬HTTP£¨80£©ÐèÒª°üÀ¨TransparentÊôÐÔ¡£²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.6 ÅäÖñ¾µØÊ±ÖÓ

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/General/Clock½øÈ룬ÈçÏÂͼʾ£º

Ñ¡Ôñ±¾µØÊ±ÖÓ¶¨ÒåΪ£«8Çø£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.7 ÅäÖÃRadiusÈÏÖ¤·þÎñ

»¥ÁªÍø·ÃÎÊÓû§½«²ÉÓÃRadius½øÐÐÓû§ÈÏÖ¤£¬Óû§·Ö×éͨ¹ýRadiusµÄÊôÐÔ½øÐж¨Ò壬·Ö×éÓëÊôÐÔ¶ÔÓ¦¹ØÏµÈçÏ£º

¹¤×÷×é ¹ÜÀí×é ¸ß¼¶×é ÆÕͨ×é ÁÙʱ×é

Login(1) Framed(2) Call Back login(3) Call Back Framed(4) Outbound(5)

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Authentication/RADIUS½øÈ룬ÈçÏÂͼʾ£º

µã»÷NewÉú³ÉRADIUSÅäÖã¬ÔÚµ¯³ö´°¿ÚÖж¨ÒåRadius·þÎñÆ÷µØÖ·£¬ÈçÏÂͼʾ£º

ÆäÖУ¬Real Name¶¨ÒåΪRADIUS£¬Primary server hostÖж¨ÒåRADIUS·þÎñÆ÷IPµØÖ·£º191.32.1.22£¨Ôݶ¨£©£¬PortΪ1812£¬SecretΪRADIUSÖж¨ÒåµÄͨѶÃÜÂ룻µã»÷OKÍê³É¶¨Òå¡£²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

×¢£ºPortºÍSecretµÄ¶¨Ò屨ÐëÓëRADIUS·þÎñÆ÷Öж¨Òå±£³ÖÒ»Ö¡£

ÈçÐ趨Ò屸·ÝµÄRADIUS·þÎñÆ÷£¬ÔÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñRADIUS Servers£¬ÈçÏÂͼʾ£º

ÔÚAlternate Server¶¨ÒåÖУ¬¶¨Ò屸ÓõÄRADIUS·þÎñÆ÷IPµØÖ·£¬¼°Í¨Ñ¶ÃÜÂë¡£

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Authentication/Transparent Proxy½øÈ룬ÈçÏÂͼʾ£º

ÆäÖУ¬MethodÑ¡¶¨IP£¬ÔÚIP TTLÖж¨Òå240·ÖÖÓ£¨4¸öСʱ£©£¬Óû§ÈÏÖ¤Ò»´Î½«±£³Ö4Сʱ£»²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.8 ÄÚÈݹýÂËÁÐ±í¶¨Òå¼°ÏÂÔØ

ÔÚProxySGÖмÓÔØBlue Coat·ÖÀàÁбí×÷Ϊ»¥ÁªÍø·ÃÎÊ¿ØÖƼ°Anti-Spyware²ßÂԵĻù´¡¡£

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Content Filtering/Bluecoat½øÈ룬ÈçÏÂͼʾ£º

ÊäÈëÓû§Ãû/ÃÜÂ룬ѡÔñForce Full Update£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ£¬È»ºóµã»÷Download Now¿ªÊ¼ÏÂÔØ·ÖÀàÁбí¿â¡£

·ÖÀàÁбíÏÂÔØ½áÊøºó£¨µÚÒ»´ÎÏÂÔØ³¬¹ý80MbypesÊý¾Ý£¬ËùÐèʱ¼äÓëÍøÂçºÍ´ø¿íÓйأ©£¬¶¨Òå×Ô¶¯ÏÂÔØ¸üУ¬ÔÚÉϲ¿Ñ¡ÏîÖÐÑ¡ÔñAutomatic Download£¬ÈçÏÂͼʾ£º

ÆäÖУºÑ¡ÔñÿÌìUTCʱ¼äÏÂÎç4:00£¨±¾µØÊ±¼äÍíÉÏ12:00£©×Ô¶¯ÏÂÔØ¸üУ¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

Æô¶¯¶¯Ì¬·ÖÀàģʽ£¬ÔÚÉϲ¿²Ëµ¥Ñ¡ÔñDynamic Categorization£¬ÈçÏÂͼʾ£º

Ñ¡ÔñEnable Dynamic CategorizationºÍCategorize dynamically in the background£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

Ñ¡¶¨Ê¹Blue Coat·ÖÀàÁбíÉúЧ£¬´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Content Filtering/General½øÈ룬ÈçÏÂͼʾ£º

Ñ¡¶¨Use Blue Coat Web Filter£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.9 ¶¨Ò岡¶¾É¨Ãè·þÎñÆ÷

¶ÔËùÓÐͨ¹ýProxySGµÄHTTP¡¢FTPͨѶ½øÐв¡¶¾É¨Ã裬²¡¶¾É¨Ãè·þÎñÆ÷²ÉÓÃMcAfee£¬ProxySGͨ¹ýICAPЭÒéʵÏÖÓëMcAfee²¡¶¾É¨Ãè·þÎñÆ÷ͨѶ¡£

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/External Services/ICAP½øÈ룬µã»÷NewÉú³ÉICAP·þÎñÅäÖã¬ÈçÏÂͼʾ£º

ServiceÃûΪMcAfee_1ºÍMcAfee_2£¬Ñ¡Ôñ·þÎñÃûMcAfee_1£¬²¢µã»÷Edit£¬½øÈë·þÎñÅäÖô°¿Ú£¬ÈçÏÂͼʾ£º

ÔÚService URLÖУ¬¶¨Òåicap://10.32.0.15£¬²¢µã»÷Sense settings´ÓMcAfee»ñÈ¡²¡¶¾É¨Ãè²ÎÊýÅäÖ㬵ã»÷Register¶¨Òå½øÐн¡¿µ¼ì²é£¬µã»÷OKÍê³É¶¨Ò壬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

Ñ¡Ôñ·þÎñÃûMcAfee_2£¬²¢µã»÷Edit£¬Öظ´ÒÔÉϹý³Ì£¬²¢ÔÚService URLÖж¨Òåicap://10.32.0.16¡£

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/External Services/Serice-Group½øÈ룬½«Á½Ì¨McAfee·þÎñÆ÷¶¨ÒåΪһ¸öGroup£¬µã»÷NewÉú³ÉService GroupÅäÖÃÈçÏÂͼʾ£º

Service GroupÃû¶¨ÒåΪMcAfee_Group£¬µã»÷Edit½øÐзþÎñÆ÷×鶨Ò壬ÈçÏÂͼʾ£º

ͨ¹ýµã»÷New½«McAfee_1ºÍMcAfee_2¼ÓÈëMcAfee_GroupÖУ¬µã»÷Edit¿ÉÒԸıäGroup³ÉÔ±µÄÈ¨ÖØ£¬Ñ¡ÔñOKÍê³ÉÅäÖ㬲¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.10 ´ø¿í¹ÜÀí¶¨Òå

¸ù¾Ý´ø¿í¹ÜÀí²ßÂÔÒªÇ󣬶¨ÒåÆß¸ö´ø¿íÀ࣬ÆäÖÐWork_Group_Bandwidth¡¢Management_Group_Bandwidth¡¢High_Level_Group_Bandwidth¡¢

Normal_Group_Bandwidth¡¢Temp_Group_Bandwidth·Ö±ð¶ÔÓ¦¹¤×÷×é¡¢¹ÜÀí×é¡¢¸ß¼¶×é¡¢ÆÕͨ×é¡¢ÁÙʱ×éµÄ´ø¿í¹ÜÀíÒªÇó£¬Limit_App_Bandwidth¶ÔÓ¦¸ß´ø¿íÏûºÄÓ¦ÓõĴø¿í¹ÜÀí²ßÂÔ£¬Key_App_Bandwidth¶ÔÓ¦¹Ø¼üÓ¦ÓÃÍøÕ¾µÄ´ø¿í¹ÜÀí²ßÂÔ¡£

´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Bandwidth Mgmt./BWM Classes½øÈ룬µã»÷New¶¨Òå´ø¿íÀ࣬ÈçÏÂͼʾ£º

ÆäÖУ¬ÐèÑ¡ÖÐEnable Bandwidth Management£¬¶¨Òå´ø¿íÀ࣬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.11 ²ßÂÔÉèÖÃ

2.11.1 ÅäÖÃDDOS¹¥»÷·ÀÓù

ͨ¹ýTelnet¡¢SSH»òConsole½øÈëProxySGµÄÃüÁîÐйÜÀí½çÃæ£¬½øÈëenable״̬£¬Í¨¹ýÃüÁîconf t½øÈëÅäÖÃ״̬£¬Í¨¹ýÒÔÏÂÃüÁîÆô¶¯DDOS·ÀÓù£º

attack-detection client enable-limits

2.11.2 ÉèÖÃȱʡ²ßÂÔΪDENY

´ÓWeb¹ÜÀí½çÃæManagement Console/configuration/Policy/Policy Options½øÈëȱʡ²ßÂÔÉèÖã¬ÈçÏÂͼʾ£º

ÆäÖУ¬Ñ¡ÔñDENY£¬²¢µã»÷ApplyʹÅäÖÃÉúЧ¡£

2.11.3 ÅäÖÃBlue Coat Anti-Spyware²ßÂÔ

´ÓWeb¹ÜÀí½çÃæManagement Console/configuration/Policy/Policy Files½øÈëȱʡ²ßÂÔÉèÖã¬ÈçÏÂͼʾ£º

ÔÚInstall Local File FromµÄÏÂÀ­¿òÖÐÑ¡ÔñLocal File£¬µã»÷Install£¬ÈçÏÂͼʾ£º

ÔÚµ¯³öµÄ´°¿ÚÖУ¬µã»÷ä¯ÀÀ£¬²¢Ñ¡¶¨Blue Coat·¢²¼µÄAnti-Spyware²ßÂÔ£¬Ñ¡ÔñInstall½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.4 ·ÃÎÊ¿ØÖƲßÂÔÅäÖÃ-VPM

·ÃÎÊ¿ØÖƲßÂÔͨ¹ýBlue CoatͼÊÓ»¯½çÃæVPM½øÐÐÅäÖ㬴ÓWeb¹ÜÀí½çÃæManagement Console/configuration/Policy/ Visual Policy Manager½øÈ룬²¢µã»÷Launch£¬¼´¿ÉÆô¶¯VPM½çÃæ£¬ÈçÏÂͼʾ£º

2.11.5 ²¡¶¾É¨Ãè²ßÂÔÅäÖÃ

¶¨Òå¶ÔËùÓÐͨ¹ýProxySGµÄÁ÷Á¿½øÐв¡¶¾É¨Ã裬ʹÓò¡¶¾É¨Ãè·þÎñÆ÷×éMcAfee_Group¡£

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Content Layer£¬Éú³ÉWebÄÚÈÝ¿ØÖƲßÂԲ㣬Ãû×Ö¶¨ÒåΪWeb AV£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬ActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Set ICAP Response Service£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÔÚUse ICAP response serviceµÄÏÂÀ­¿òÖÐÑ¡ÔñMcAfee_Group£¬²¢Ñ¡¶¨Continure without further ICAP response£¬µã»÷OK£¬Í˵½ÉÏÒ»²ã£¬ÔÚ´°¿ÚÖÐÑ¡ÔñICAPResponseService1£¬²¢µã»÷OK£¬Íê³É¹æÔòÉèÖã»ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.6 Óû§ÈÏÖ¤²ßÂÔÉèÖÃ

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Authentication Layer£¬Éú³ÉWeb·ÃÎÊÓû§ÈÏÖ¤²ã£¬Ãû×Ö¶¨ÒåΪWeb_Radius_Auth£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬ActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Authenticate£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÔÚµ¯³öµÄ´°¿ÚÖУ¬RealmÀ¸Ñ¡¶¨radius(RADIUS)£¬ModeÖÐÑ¡¶¨Proxy IP£¬µã»÷OK£¬Í˵½ÉÏÒ»²ã£¬ÔÚ´°¿ÚÖÐÑ¡ÔñAuthenticate1£¬²¢µã»÷OK£¬Íê³É¹æÔòÉèÖã»ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd SOCKS Authentication Layer£¬Éú³ÉSOCKS·ÃÎÊÓû§ÈÏÖ¤²ã£¬Ãû×Ö¶¨ÒåΪSOCKS_Radius_Auth£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬ActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨SOCKS Authenticate£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÆäÖУ¬RealmÖÐÑ¡¶¨radius(RADIUS)£¬µã»÷OK£¬Í˵½ÉÏÒ»²ã£¬ÔÚ´°¿ÚÖÐÑ¡ÔñSOCKSAuthenticate1£¬²¢µã»÷OK£¬Íê³É¹æÔòÉèÖã»ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.7 ´ø¿í¹ÜÀí²ßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪBandwidth_Management£¬²¢ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Attribute£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÆäÖУ¬¶¨ÒåNameΪWork_Group£¬Authentication RealmÑ¡¶¨

RADIUS(RADIUS)£¬RADIUS AttributeÑ¡¶¨Login(1)£¬Ñ¡ÔñOK£¬Íê³ÉÊôÐÔ¶¨Òå¡£

ÖØ¸´ÒÔÉϹý³Ì·Ö±ð¶¨ÒåNameΪManagement_Group¡¢High_Level_Group¡¢Normal_Group¡¢Temp1_Group£¬Temp0_Group£¬Temp2_Group·Ö±ð¶ÔÓ¦RADIUS AttributeΪFramed(2)¡¢Call Back login(3)¡¢Call Back Framed(4)¡¢Outbound(5)¡¢NAS Prompt(7)¡¢Administrative(6)¡£

ÔÚµÚÒ»Ìõ¹æÔòµÄServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÆäÖУ¬Ñ¡¶¨P2PºÍAll P2P£¬²¢Ñ¡ÔñOK£¬Íê³É¶¨Òå¡£

ÔÚµÚÒ»Ìõ¹æÔòµÄDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨URL£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÔÚSimple MatchÖÐÖ¸¶¨¹Ø¼üÒµÎñµÄÓòÃû£¬Ñ¡ÔñAddÔö¼Ó¶¨Ò壬ѡÔñClose½áÊø¶¨Òå¡£

ÔÚµÚÒ»Ìõ¹æÔòµÄActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Manage Bandwidth£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÆäÖУ¬Name¶¨ÒåΪKey_App_Bandwidth£¬Limit Bandwidth onÖÐÑ¡¶¨Server SideºÍInbound£¬ÔÚBandwidth ClassÖÐÑ¡¶¨Key_App_Bandwidth£¬Ñ¡ÔñOKÍê³É¶¨Ò壻

ÖØ¸´ÒÔÉϹý³Ì£¬¶¨ÒåÃûNameΪLimit_App_Bandwidth_in£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪLimit_App_Bandwidth£»

¶¨ÒåÃûNameΪLimit_App_Bandwidth_out£¬ÊôÐÔΪServer Side Outbound£¬Bandwidth ClassΪLimit_App_Bandwidth£»

¶¨ÒåÃûNameΪWork_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪWork_Group_Bandwidth£»

¶¨ÒåÃûNameΪManagement_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪManagement_Group_Bandwidth£»

¶¨ÒåÃûNameΪHigh_Level_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪHigh_Level_Group_Bandwidth£»

¶¨ÒåÃûNameΪNormal_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪNormal_Group_Bandwidth£»

¶¨ÒåÃûNameΪTemp_Group_Bandwidth£¬ÊôÐÔΪServer Side Inbound£¬Bandwidth ClassΪTemp_Group_Bandwidth¡£

ÔÚVPM½çÃæµã»÷Add RuleÔö¼ÓÆßÌõ¹æÔò£¬×ܹ²°ËÌõ¹æÔò£¬

µÚÒ»Ìõ¹æÔò¶¨Ò壺ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñÒÔÉ϶¨ÒåµÄ¹Ø¼üÒµÎñURL£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñKey_App_Bandwidth£»

µÚ¶þÌõ¹æÔò¶¨Ò壺ÔÚServiceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñAll P2P£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñLimit_App_Bandwidth_in£»

µÚÈýÌõ¹æÔò¶¨Ò壺ÔÚServiceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñAll P2P£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñLimit_App_Bandwidth_out£»

µÚËÄÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñWork_Group_Bandwidth£»

µÚÎåÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñManagement_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñManagement_Group_Bandwidth£»

µÚÁùÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñHigh_Level_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñHigh_Level_Group_Bandwidth£»

µÚÆßÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñNormal_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñNormal_Group_Bandwidth£»

µÚ°ËÌõ¹æÔò¶¨Ò壺ÔÚSourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñTemp_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñTemp_Group_Bandwidth¡£

Íê³É¶¨ÒåÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.8 Work_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪWork_Group_Policy£¬Í¨¹ýAdd RuleÔö¼ÓÁ½Ìõ¹æÔò¡£

ÔÚµÚÒ»Ìõ¹æÔòµÄServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÆäÖУ¬Ñ¡¶¨SOCKSºÍAll SOCKS£¬²¢Ñ¡ÔñOK£¬Íê³É¶¨Òå¡£

ÔÙÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡¶¨StreamingºÍAll Streaming¡£

ÔÚVPM²Ëµ¥Ñ¡ÔñAdd RuleÔö¼ÓÁ½Ìõ¹æÔò£¬¹²ÈýÌõ¹æÔò¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All SOCKS£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All Streaming£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚÈýÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñWork_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.9 Management_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪManagement_Group_Policy¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñManagement_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.10 High_Level_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪHigh_Level_Group_Policy¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñHigh_Level_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.11 Normal_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪNormal_Group_Policy¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNormal_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All Streaming£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNormal_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.12 Temp1_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪTemp1_Group_Policy¡£

ÔÚµÚÒ»Ìõ¹æÔòµÄServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡¶¨Client Protocol£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÆäÖУ¬Ñ¡¶¨FTPºÍAll FTP£¬²¢Ñ¡ÔñOK£¬Íê³É¶¨Òå¡£

ÔÚVPM²Ëµ¥Ñ¡ÔñAdd RuleÔö¼ÓËÄÌõ¹æÔò£¬¹²ÎåÌõ¹æÔò¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All SOCKS£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All Streaming£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚÈýÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All FTP£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚËÄÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨New£¬Ñ¡ÔñURL£¬¶¨ÒåSimple MatchÖÐÓòÃûΪpassport.com£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚÎåÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp1_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.13 Temp0_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪTemp0_Group_Policy¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp0_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.14 Temp2_GroupÓû§×é·ÃÎÊ¿ØÖƲßÂÔ¶¨Òå

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪTemp2_Group_Policy¡£

ÔÚVPM²Ëµ¥Ñ¡ÔñAdd RuleÔö¼Ó¶þÌõ¹æÔò£¬¹²ÈýÌõ¹æÔò¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp2_Group£¬ÔÚServicesÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨All SOCKS£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp2_Group£¬ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡¶¨New£¬Ñ¡ÔñURL£¬¶¨ÒåSimple MatchÖÐÓòÃûΪpassport.com£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñDeny¡£

ÔÚµÚÈýÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñTemp2_Group£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

Íê³É¹æÔò¶¨Ò壬ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.15 IEä¯ÀÀÆ÷°æ±¾¼ì²é²ßÂÔ

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd Web Access Layer£¬Éú³ÉWeb·ÃÎÊ¿ØÖƲ㣬Ãû×Ö¶¨ÒåΪBrowser_Version_Check£¬Í¨¹ýAdd RuleÔö¼ÓÒ»Ìõ¹æÔò£¬¹²Á½Ìõ¹æÔò¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡ÔñRequest Header£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

ÆäÖУ¬Name¶¨ÒåΪRequestHeader_IE6£¬ÔÚHeader NameÏÂÀ­¿òÖÐÑ¡ÔñUser-Agent£¬ÔÚHeader RegexÖÐÊäÈë.*MSIE6.*£¬µã»÷OKÍê³É¶¨Òå¡£

ÔÚµÚÒ»Ìõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñRequestHeader_IE6£¬ÔÚDestinationÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖеã»÷New£¬Ñ¡ÔñURL£¬¶¨Òåmicrosoft.com£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñAllow¡£

ÔÚµÚ¶þÌõ¹æÔòÖУ¬SourceÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñRequestHeader_IE6£¬ÔÚActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÑ¡ÔñNew£¬²¢Ñ¡ÔñDeny£¬µ¯³ö´°¿ÚÈçÏÂͼʾ£º

Ñ¡¶¨Force Deny£¬DetailsÌáʾΪ£ºPlease upgrade your Browser to IE6.x£¬µã»÷OKÍê³É¶¨Ò壬²¢ÔÚ·µ»ØµÄ´°¿ÚÖÐÑ¡¶¨Deny1£¬µã»÷OK£¬Íê³É¶¨Òå¡£ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.11.16 DNS½âÎö²ßÂÔÉèÖÃ

ProxySG½«ÎªÓû§ÌṩDNS½âÎö·þÎñ£¬½«¶Ô½âÎöÇëÇóÓ¦´ðProxySGµÄIPµØÖ·£¬ÅäÖùý³ÌÈçÏ£º

´ÓVPMµÄPolicy²Ëµ¥Ñ¡ÔñAdd DNS Access Layer£¬Éú³ÉDNS·ÃÎÊ¿ØÖƲ㣬ÔÚµÚÒ»Ìõ¹æÔòµÄActionÀ¸ÓÃÊó±êÓÒ¼ü£¬Ñ¡ÔñSet£¬ÔÚµ¯³ö´°¿ÚÖÐÑ¡ÔñNew£¬Ñ¡ÔñSend DNS Response£¬ÈçÏÂͼʾ£º

ÆäÖУºNameΪSendDNSResponse_CCB£¬HostΪJiangSu_CCB£¬Ñ¡¶¨Responds with incoming proxy IP£¬Ñ¡ÔñOK£¬²¢Ôڲ˵¥ÖÐÑ¡¶¨SendDNSResponse_CCB£¬Ñ¡ÔñOKÍê³É¶¨Ò壬ÈçÏÂͼʾ£º

ÔÚVPM²Ëµ¥Öеã»÷Install Policy½«²ßÂÔ¼ÓÔØµ½ProxySGÖС£

2.12 Anti-Spyware²ßÂÔ

Blue Coat¶¨ÆÚ·¢²¼Anti-Spyware²ßÂÔ£¬¸Ã²ßÂÔ»ùÓÚBlue Coat URLÁÐ±í£¬Òò´Ë±ØÐëÔÚBlue Coat URL·ÖÀàÁбíÏÂÔØ½áÊø²¢ÉúЧºó£¬²ÅÄܰ²×°¸Ã²ßÂÔ¡£

ÔÚ»ñµÃAnti-Spyware²ßÂÔÎļþºó£¬´ÓWeb¹ÜÀí½çÃæManagement Console/Configuration/Policy/Policy Files½øÈ룬ÈçÏÂͼʾ£º

ÔÚInstall Local File FromÑ¡ÏîÖÐÑ¡ÔñLocal File£¬²¢µã»÷Install£¬ÔÚµ¯³ö´°¿ÚÖÐBrowseµ½Anti-Spyware²ßÂÔÎÊÌ⣬²¢½«Æä°²×°µ½ProxySGÖУ¬²ßÂÔ¼´ÉúЧ¡£

Èç¹ûÐèÒª¶¨ÒåÌØ¶¨ÍøÕ¾²»ÊÜAnti-Spyware²ßÂÔµÄÓ°Ï죬ÐèÆô¶¯VPM

£¨Management Console/Configuration/Policy/Visual Policy Manager£©£»ÔÚVPM²Ëµ¥ConfigurationÖÐÑ¡ÔñEdit Categories£¬ÈçÏÂͼʾ£º

½«PolicyÕ¹¿ª£¬²¢Ñ¡¶¨Additional_Spyware_Trusted_Sites£¬µã»÷Edit URLs£¬²¢ÔÚµ¯³ö´°¿ÚÖУ¬½«Ö¸¶¨ÓòÃû¼ÓÈ룬ÈçÏÂͼʾ£º

¿ÉÒÔ¼Ó¶àÐУ¬µã»÷OK£¬Íê³É¶¨Ò壬ÔÚµã»÷OK»Øµ½VPMÒ³Ãæ£¬²¢µã»÷Install PolicyʹÅäÖÃÉúЧ¡£

2.13 PACÎļþ¶¨Òå

PACÎļþ¶¨ÒåIEä¯ÀÀÆ÷ÉÏÍø´úÀíµÄ½Å±¾£¬¿ÉÒÔ¼ÓÔØµ½ProxySGÖУ¬PACΪÎı¾Îļþ£¬¶¨ÒåÈçÏ£º

function FindProxyForURL(url, host) {

if (isInNet(host, \ return \ else

return \ }

ÆäÖУº191.0.0.0/24ΪxxxxxÄÚ²¿Íø¶Î£¬Èç¹û»¹ÓÐÆäËüÍø¶Î£¬¿ÉÒÔÔö¼Óif¶¨Ò壻191.32.1.15ΪCIDÐéÄâ³öµÄIPµØÖ·£¬ÓÃÀ´¸øÉÏÍøÓû§×ö´úÀí¡£

ͨ¹ýTelnet»òSSH½øÈëProxySGÃüÁîÐнçÃæ£¬Í¨¹ýEnableÃüÁî½øÈë¹ÜÀí״̬£¬Ê¹ÓÃÒÔÏÂÃüÁî¼ÓÔØPACÎļþÅäÖãº

#inline accelerated-pac

function FindProxyForURL(url, host) {

if (isInNet(host, \ return \ else

return \ }

·ÃÎÊProxySGÖеÄPACÎļþµÄ·¾¶Îª£º

http:// 191.32.1.13/accelerated_pac_base.pac

ÅäÖÃIEä¯ÀÀÆ÷ʹÓøÃPACÎļþÉÏÍø£¬´Óä¯ÀÀÆ÷²Ëµ¥½øÈëÅäÖ㺹¤¾ß/InternetÑ¡Ïî/Á¬½Ó/¾ÖÓòÍøÉèÖ㬵¯³ö´°¿ÚÈçÏÂͼʾ£º

ÔÚÆäÖÐÑ¡¶¨¡°Ê¹ÓÃ×Ô¶¯ÅäÖýű¾¡±£¬µØÖ·À¸ÖÐÊäÈ룺

http:// 191.32.1.13/accelerated_pac_base.pac

ÕâÑù£¬ËùÓÐ¶ÔÆóÒµÍøÂçµÄ·þÎñÆ÷IP·ÃÎʽ«²»»áʹÓôúÀí£¬¶ø¶Ô»¥ÁªÍøµÄ·ÃÎʽ«Í¨¹ýProxySG´úÀí¡£