Mcafee Web Gateway: Method of Procedure

Download as pdf or txt
Download as pdf or txt
You are on page 1of 8

McAfee Web Gateway

Method of Procedure

Youtube API v3 Ruleset


Step 1: Backup exisiting policies (Estimated time: 5 minutes)

It is best practice to perform a backup before performing any upgrades or troubleshooting any issu es.
This is to be sure that there will be a backup that can be used to revert any action if there are any
issue/problem encountered during the activity.

a) Login to MWG. See in the top of the web page, it must shown there the current version of the
MWG 9.2.16.

a.

b) Go to Troubleshooting then under the name of the appliance, select Backup/Restore. Check
SSO Credientials check bar and click Back up to file.
a. Note: This backup will include current configurations, accounts, policies and SSO
Credientials of web gateway.

Estimated time: 5 mins

b.

c) In Save Backup, click Browse to choose the backup location of the backup file that will be
exported and enter a Password then click Ok. There will be a pop-up message that the backup is
successful.
a.

d) Look for the exported file in backup location. You should see this kind of backup file generated.
This is for us to make sure that the backup is successfully created.

Step 2: Getting an API key from Google

API v3 requires a user to obtain an API key which is used to identify who is querying the API. Every API
has a specific quota which defined how many requests against the API can be done.

More details can be found at https://developers.google.com/youtube/v3/getting-started.

Note: McAfee and/or the product McAfee Web Gateway don’t have any control about the API itself (in
regards to availability) and/or the quota. In case you exceed the quota for your API key it may be
required to talk to YouTube/Google to increase the available quota for your key.

a) Before you start, You need a Google Account to access the Google API console, request an API
key, and register your application.

b) Create a project in the Google Developers Console and obtain authorization credentials so your
application can submit API requests.
After creating your project, make sure the YouTube Data API is one of the services that your application
is registered to use:

i. Go to the API Console and select the project that you just registered.
ii. Visit the Enabled APIs page. In the list of APIs, make sure the status is ON for the YouTube Data
API v3.

iii. Select Create Credentials.

iv. You will see now your created API key.


Step 3: Import the YouTube Ruleset API v3.

a) In the Policy tab, Click Add > Top Level Ruleset > Import rule set from Rule Set Library \

b) Click the “Import from File” > button in the lower left corner of the new window.

c) Select the rule set from the file you have downloaded.

d) Solve all conflicts by “refer to existing objects”.

e) Done.

Step 4: Configuration of HTTPS Scanning

a) Create an IP list only for the restricted Users that are Allowed to browse YouTube.
i. Click on the Lists Tab, then click the “+” icon on the upper left of the window.
ii. Create a name and Select Type as “IP”, click Ok.
Example: Youtube Allow list.

b) Edit the HTTPS Scanning Ruleset.


i. Select HTTPS Scanning, then click Edit.
ii. Click Add, select User/Group Criteria.
iii. Select Client.IP > is in list > Select the list of allowed IP for YouTube.

iv. Move down the criteria and select AND operator. (a AND b AND c) AND d
NOTE: If we enable the HTTPS Scanning, all the other websites they are going to browse will be affected
by the SSL inspection. And even if we export the certificate and install it to the users, we will be having a
problem on the other websites.

Step 4: Creation of Separate Proxy for the Users Allowed Youtube

a) Add a sub rule to the URL policy rule set.


i. Click Add Rule > Add Name
ii. Add criteria Client.IP is in list (list of Youtube Allow Users) AND URL.Host is in list
YouTube URL.
iii. Action Stop Rule Set.
iv. Done

Step 5: Installing Certificates to Users

a) Export a certificate from MWG.


i. Go to Settings > Select SSL Client Context with CA > Default CA
ii. Export and Save
iii. Install the certificate and Select Trusted Root Certification Authorities.

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy