<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>M86 Security Knowledge Base</title><description>M86 Security Knowledge Base RSS 2.0 Feed</description><link>http://www.m86security.com/kb/</link><webMaster>Website@marshal.com</webMaster><lastBuildDate>Sat, 13 Mar 2010 00:09:52 GMT</lastBuildDate><ttl>20</ttl><generator>M86 Security Knowledge Base</generator><item><title>How to customize the unpacking folder location</title><link>http://www.m86security.com/kb/article.aspx?id=12249</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How to customize the unpacking folder location&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;In WebMarshal 6.5 and above, you can change the location of the unpacking folder. By default the folder location is the following subfolder of the WebMarshal install location: &lt;FONT face="Courier New"&gt;\Temp\unpacking&lt;/FONT&gt; &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Warning: &lt;/STRONG&gt;The instructions below are for advanced users and detail how to change the WebMarshal unpacking folder which is used to unpack and scan Web content. It is important that the directory is excluded from on-access or resident virus and spyware scanning. If you do not exclude this folder from scanning, the WebMarshal Engine and or WebMarshal Controller services may be unable to start. If you change the folder location ensure you update your on-access or resident virus and spyware scanners.  &lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;P&gt;To change the unpacking folder, add the following entry to the &lt;FONT face="Courier New"&gt;WMEngine.config.xml&lt;/FONT&gt; file, within the WebMarshal install:&lt;/P&gt;&lt;PRE&gt;&lt;FONT color=#aaaaaa&gt;&amp;lt;WebMarshal&amp;gt;   &amp;lt;Engine&amp;gt;     &amp;lt;Config&amp;gt;&lt;/FONT&gt;        &amp;lt;Paths unpacking="&amp;lt;new location&amp;gt;" /&amp;gt;&lt;/SPAN&gt;&lt;FONT color=#aaaaaa&gt;     &amp;lt;/Config&amp;gt;  &amp;lt;/Engine&amp;gt;&amp;lt;/WebMarshal&amp;gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;To apply the change, restart the Engine service.&lt;BR&gt;&lt;BR&gt;Marshal advises you ensure the &lt;STRONG&gt;Content Analysis &lt;/STRONG&gt;rule &lt;STRONG&gt;Block - Unpacking Error&lt;/STRONG&gt; is enabled (it is enabled by default).&lt;/P&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;P&gt;For more information see the following Marshal Knowledge Base articles:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://www.m86security.com/kb/article.aspx?id=10850" target=_blank&gt;Q10850&lt;/A&gt; : What directories need to be excluded from resident virus scanning and regular </description><pubDate>Wed, 10 Mar 2010 08:52:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>What URLs are required for operation of WebMarshal features?</title><link>http://www.m86security.com/kb/article.aspx?id=12872</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What URLs are required for operation of WebMarshal features?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;WebMarshal 6.5 includes a number of features that are automatically updated using web-based services.&lt;/P&gt;&lt;P&gt;These services are accessed by the WebMarshal processing node servers.&lt;/P&gt;&lt;P&gt;You should ensure that access to these services is permitted by any firewall or external proxy (and by WebMarshal rules if required by network setup). &lt;/P&gt;&lt;P&gt;The required URLs include:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For TRACEnet service&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;https://tracenetlicensing.marshal8e6.com &lt;LI&gt;https://tnreclassify.marshal8e6.com (For user reclassification request, if enabled, in version 6.5 through 6.5.3)&lt;LI&gt;https://tnreclassify.m86security.com (For user reclassification request, if enabled, in version 6.5.5 and above)&lt;LI&gt;https://tnfeedback.marshal8e6.com &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR&gt;For Marshal8e6 Filtering List&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;https://filterlistlicensing.marshal8e6.com &lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;(Note that this URL must also be accessible from the Array Manager at the time of initial configuration of the list.)&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;https://secureupdate.8e6.com &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Note:&lt;/H2&gt;&lt;P&gt;Other optional features, such as virus scanner updaters and other URL list updaters, require additional URL access to HTTP and HTTPS sites. Because WebMarshal is a proxy server, it is expected to have full access to the web. &lt;/P&gt;</description><pubDate>Mon, 08 Mar 2010 10:45:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>What is the WELF log file format?</title><link>http://www.m86security.com/kb/article.aspx?id=10899</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.X &lt;LI&gt;Security Reporting Center 2.X &lt;LI&gt;WebTrends Firewall Suite 2.X &lt;LI&gt;WebTrends Firewall Suite 3.X &lt;LI&gt;WebTrends Firewall Suite 4.X&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;What is the WELF log file format? &lt;P&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;&lt;B&gt;WELF&lt;/B&gt; is the &lt;B&gt;&lt;U&gt;W&lt;/U&gt;&lt;/B&gt;ebTrends &lt;B&gt;&lt;U&gt;E&lt;/U&gt;&lt;/B&gt;nhanced &lt;B&gt;&lt;U&gt;L&lt;/U&gt;&lt;/B&gt;og file &lt;B&gt;&lt;U&gt;F&lt;/U&gt;&lt;/B&gt;ormat. &lt;P&gt;The WELF Reference defines the WebTrends industry standard log file exchange format. Any firewall or VPN system logging to this format will be compatible with Firewall Suite 2.0 and later, Firewall Reporting Center 1.0 and later, and Security Reporting Center 2.0 and later. &lt;P&gt;&lt;STRONG&gt;WebMarshal 6.X&lt;/STRONG&gt; "Traffic Logging" logs are created in the WELF format. &lt;P&gt;&lt;H3&gt;Log File Format&lt;/H3&gt;&lt;P&gt;A log file is made up of records. Each record makes up a single line of the file. Records must be in chronological order. The earliest record is the first record in the file; the most recent record is the last record in the file. The WebTrends Enhanced Log Format places no restrictions on log file names or log file rotation policies. &lt;/P&gt;&lt;H3&gt;Record Format&lt;/H3&gt;&lt;P&gt;A record is terminated by the character sequence carriage return-line feed (0x0D-0x0A). There may be no carriage-returns or line-feeds within a record; this format results in a single record per line. &lt;P&gt;Each record is made up of fields. The record identifier field (id=) must be the first field in a record. All other fields can appear in any order. &lt;P&gt;Aside from a few &lt;A class=solutionlink href="http://www.m86security.com/kb/admin/editarticle.aspx?id=10899#Required Fields" target=_self&gt;required fields&lt;/A&gt;, you can decide which &lt;A class=solutionlink href="http://www.m86security.com/kb/admin/editarticle.aspx?id=10899#Optional Fields" target=_self&gt;optional fields&lt;/A&gt; are included in the record. You may want some fields to appear in only certain records because they are only relevant to certain type</description><pubDate>Mon, 08 Mar 2010 10:38:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>How are WebMarshal 6.X browsing times calculated?</title><link>http://www.m86security.com/kb/article.aspx?id=11755</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.X&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How are WebMarshal session and domain browsing times calculated?&lt;/LI&gt;&lt;LI&gt;Why do WebMarshal time calculations not add up?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;Calculation of browsing time is complex.&lt;/P&gt;&lt;P&gt;For each web site visited the browser will issue many page requests to obtain the necessary style sheets, graphics and text. Some of these requests may not even be to the original domain. A good example is pages which contain advertising, or links to a third party web analytics tool such as Google Analytics.&lt;/P&gt;&lt;P&gt;WebMarshal only sees the requests for pages and cannot determine the actual time spent reviewing a page once it is downloaded. To calculate browsing time for the Active Sessions view and reports, WebMarshal uses a heuristic estimate.&lt;/P&gt;&lt;H3&gt;Definitions:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;An individual browsing request is called a &lt;STRONG&gt;page view&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;A set of browsing requests within a defined time is regarded as a continuous period of browsing, called a &lt;STRONG&gt;session&lt;/STRONG&gt;. &lt;/LI&gt;&lt;LI&gt;A set of requests for items from a single domain is called a &lt;STRONG&gt;visit&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;BLOCKQUOTE style="MARGIN-RIGHT: 0px" dir=ltr&gt;&lt;P&gt;&lt;STRONG&gt;Notes:&lt;/STRONG&gt; &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;WebMarshal records a separate domain visit for each protocol used&lt;/STRONG&gt;. For instance, if a user visits a domain by HTTP and HTTPS, WebMarshal records &lt;STRONG&gt;two &lt;/STRONG&gt;separate visits. &lt;/LI&gt;&lt;LI&gt;In &lt;STRONG&gt;WebMarshal 6.5.5 and above&lt;/STRONG&gt;, using an application protocol (such as YouTube Video) counts as an additional domain visit.&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;WebMarshal 6.x allows you to set two values:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The &lt;STRONG&gt;session timeout&lt;/STRONG&gt; defaults to 5 minutes (minimum 2 minutes)&lt;/LI&gt;&lt;LI&gt;The &lt;STRONG&gt;page view padding&lt;/STRONG&gt; defaults to 20 seconds (maximum 2 minutes). &lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;Page Vi</description><pubDate>Mon, 08 Mar 2010 10:29:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>WebMarshal Authentication in Multiple Active Directory Domains</title><link>http://www.m86security.com/kb/article.aspx?id=11870</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.X &lt;LI&gt;Microsoft Active Directory&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Can WebMarshal authenticate users in multiple Active Directory domains?&lt;/LI&gt;&lt;LI&gt;What are the trust requirements for WebMarshal to authenticate AD users?&lt;/LI&gt;&lt;LI&gt;What are the connectivity requirements for WebMarshal in Active Directory environments?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;WebMarshal 6.0 includes a native Active Directory connector. You can import groups from Active Directory to control browsing through WebMarshal.&lt;/P&gt;&lt;H3&gt;Connectivity&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;All WebMarshal components must be on computers joined to Active Directory. This includes the Array Manager and any separate Processing Servers.&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Domain browsing and group import&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;The WebMarshal user interface only allows you to browse one domain at a time. However, you can import groups from other domains by typing the fully qualified name information for each group.&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Domain Trust Scenarios&lt;/H3&gt;&lt;P&gt;WebMarshal &lt;STRONG&gt;can &lt;/STRONG&gt;import groups and authenticate users from AD domains in the following scenarios:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;U&gt;Single domain&lt;/U&gt;&lt;BR&gt;&lt;BR&gt;&lt;/STRONG&gt;&lt;TABLE style="FONT-SIZE: 11px" border=0 cellSpacing=1 cellPadding=5 width=360&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD vAlign=top&gt;&lt;STRONG&gt;Domains:&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD vAlign=top&gt;DOMAIN1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=top&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD vAlign=top&gt;Single Domain&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=top&gt;&lt;STRONG&gt;WebMarshal Domain:&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD vAlign=top&gt;DOMAIN1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=top&gt;&lt;STRONG&gt;Users:&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD vAlign=top&gt;DOMAIN1\User1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=top&gt;&lt;STRONG&gt;Result:&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD vAlign=top&gt;DOMAIN1\User1 can authenticate with WebMarshal. &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;BR&gt;&lt;LI&gt;&lt;U&gt;&lt;STRONG&gt;Subdomain &lt;/STRONG&gt;&lt;BR&gt;&lt;/U&gt;&lt;BR&gt;&lt;TABLE style="FONT-SIZE: 11px" border=0 cellSpacing=1 cellPadding=5 width=360&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD vAlign=top&gt;&lt;ST</description><pubDate>Mon, 08 Mar 2010 10:16:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Proxy Caching Recommendations</title><link>http://www.m86security.com/kb/article.aspx?id=12720</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What are the best practices for configuration of proxy caching hardware and settings?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;H3&gt;Virus Scanning Exclusion&lt;/H3&gt;&lt;P&gt;When setting up proxy caching, you &lt;STRONG&gt;must&lt;/STRONG&gt; exclude the cache directory from on-access or resident virus/malware scanning. If WebMarshal determines that the cache directory is being scanned, proxy caching will be disabled. To re-enable caching, correct the scanner exclusions and then restart the WebMarshal Proxy service.&lt;/P&gt;&lt;H3&gt;Cache Location&lt;/H3&gt;&lt;P&gt;By default the cache directory location is within the WebMarshal install location (on each processing node server). This location is appropriate for trial installations and low volumes of traffic.&lt;/P&gt;&lt;P&gt;However, to ensure adequate performance on production servers, M86 Security recommends you place the cache in another location.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Configure the cache on a separate physical disk. &lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;Ideally this disk should be used only for the cache.&lt;/LI&gt;&lt;LI&gt;At minimum it should be a different disk to the WebMarshal temp (unpacking) and logging directories.&lt;/LI&gt;&lt;LI&gt;Use a single disk with fast read and seek time. Do not use RAID or mirrored disks (redundancy slows access time).&lt;/LI&gt;&lt;LI&gt;M86 strongly recommends you use a local disk. The disk must have 100% availability. &lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;In 6.5.5 and above you cannot enter a UNC path. (However these versions will use a UNC path if you entered it previously. If you use a UNC path, the Windows account used to run the WebMarshal Proxy service must have full access to the location.)&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;LI&gt;Ensure that the cache disk always has some free space (at least 30% free, and preferably more). Set the cache maximum size accordingly. This will help preserve performance.&lt;/LI&gt;&lt;LI&gt;In an array with more than one processing server, the cache maximum si</description><pubDate>Mon, 08 Mar 2010 10:05:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>What HTML tags are used on WebMarshal notification pages?</title><link>http://www.m86security.com/kb/article.aspx?id=10865</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 2.X and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;What HTML tags are used on WebMarshal notification pages? &lt;P&gt;&lt;H2&gt;Information:&lt;/H2&gt;This article lists the HTML tags that can be used on WebMarshal notification pages. &lt;P&gt;&lt;B&gt;Note:&lt;/B&gt; When editing WebMarshal notification pages, it is recommended that you make a copy of the existing page, rename it, and then edit the renamed page. Please refer to the WebMarshal &lt;EM&gt;User Guide&lt;/EM&gt; for more detailed instructions on editing notification pages. &lt;UL&gt;&lt;P&gt;&lt;LI&gt;&lt;B&gt;{AcceptDetails}&lt;/B&gt; and &lt;B&gt;{AcceptUrl}&lt;/B&gt;&lt;BR&gt;These tags are used on warning pages. They allow access to be permitted to the site, after the user has clicked the button to accept the warning message.&lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;STRONG&gt;{DomainName}&lt;/STRONG&gt; &lt;EM&gt;- available from 6.5.&lt;/EM&gt;&lt;BR&gt;The domain of the URL that was blocked (used for display purposes) &lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;STRONG&gt;{DisplayUrl}&lt;/STRONG&gt; &lt;EM&gt;- available from 6.5.&lt;/EM&gt;&lt;STRONG&gt; &lt;BR&gt;&lt;/STRONG&gt;The URL that was blocked (formatted for display purposes) &lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;STRONG&gt;{CategoryMatches} &lt;/STRONG&gt;and &lt;STRONG&gt;{CategoryMatchesBlank}&lt;/STRONG&gt;  &lt;EM&gt;- available from 6.5.5.&lt;/EM&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;BR&gt;A comma separated list of URL Categories that match the triggered rule. &lt;BR&gt;If no categories match, &lt;FONT face="Courier New"&gt;{CategoryMatches}&lt;/FONT&gt; returns "Uncategorized" while  &lt;FONT face="Courier New"&gt;{CategoryMatchesBlank}&lt;/FONT&gt; returns a completely empty (invisible) result. &lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;STRONG&gt;{Url}&lt;/STRONG&gt;&lt;BR&gt;The URL that was blocked.&lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;B&gt;{UserName}&lt;/B&gt;&lt;BR&gt;The domain and user name of the user who was blocked from the site (e.g. domain\username). &lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;B&gt;{ServerName}&lt;/B&gt;&lt;BR&gt;The name of the WebMarshal server. &lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;B&gt;{RedirectMsg}&lt;/B&gt;&lt;BR&gt;The reason why the URL (or file download/upload) was blocked (e.g. "Access to this site was blocked by the rule Block Offensive Language"). &lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;B&gt;{P</description><pubDate>Mon, 08 Mar 2010 09:57:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Can I use an FTP application through WebMarshal?</title><link>http://www.m86security.com/kb/article.aspx?id=11962</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Can I use an FTP application through WebMarshal?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Reply:&lt;/H2&gt;&lt;P&gt;Yes, in addition to web browser applications, some FTP client applications can work with WebMarshal 6.X. The requirements are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use passive FTP&lt;/LI&gt;&lt;LI&gt;Use HTTP/1.1 CONNECT method to access the proxy&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;For instance, the FileZilla client using "generic proxy" has been used successfully through WebMarshal.&lt;/P&gt;&lt;H2&gt;Note:&lt;/H2&gt;&lt;P&gt;In WebMarshal 6.1 through 6.5.3, when HTTPS content inspection is enabled, the CONNECT method fails. This issue is corrected in WebMarshal 6.5.5. For more information, see M86 Knowledge Base article &lt;A href="http://www.m86security.com/kb/article.aspx?ID=12950"&gt;Q12950&lt;/A&gt;.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;H2&gt; &lt;/H2&gt;&lt;P&gt; &lt;/P&gt;</description><pubDate>Mon, 08 Mar 2010 09:47:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Supported Operating Systems and Prerequisite Versions</title><link>http://www.m86security.com/kb/article.aspx?id=11358</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP 6.7&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal Web Components (SQM and Web Console)&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;MailMarshal Exchange 5.2 &lt;/LI&gt;&lt;LI&gt;MailMarshal Exchange 5.3 &lt;LI&gt;WebMarshal 6.5&lt;/LI&gt;&lt;LI&gt;MailMarshal Secure Email Server 5.6&lt;/LI&gt;&lt;LI&gt;MailMarshal Reporting Console 2.1 (for MailMarshal SMTP and WebMarshal)&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What are the supported operating systems for MailMarshal and WebMarshal?&lt;/LI&gt;&lt;LI&gt;What version of SQL Server can be used with MailMarshal and WebMarshal?&lt;/LI&gt;&lt;LI&gt;What versions of IIS and ASP.NET are supported by MailMarshal Web components?&lt;/LI&gt;&lt;LI&gt;What versions of SQL, IIS and ASP.NET are supported by Marshal Reporting Console?&lt;/LI&gt;&lt;LI&gt;What versions of ASP.NET are supported by WebMarshal?&lt;/LI&gt;&lt;LI&gt;What versions of Internet Explorer are supported for MailMarshal Web components?&lt;/LI&gt;&lt;LI&gt;What versions of ISA Server can be used with WebMarshal as a plugin?&lt;/LI&gt;&lt;LI&gt;What versions of Microsoft Exchange are supported by MailMarshal Exchange?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;The following table shows supported versions of operating systems and supporting software. &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The table reflects the latest versions of Marshal products. &lt;STRONG&gt;For details of previous versions,&lt;/STRONG&gt; see the documentation for each version.&lt;/LI&gt;&lt;LI&gt;The table reflects server requirements.&lt;STRONG&gt; For details of requirements for all user interfaces&lt;/STRONG&gt;, see the documentation for each product version. &lt;/LI&gt;&lt;LI&gt;All 64 bit operating system support is by 32 bit application deployment.&lt;/LI&gt;&lt;/UL&gt;&lt;BLOCKQUOTE style="MARGIN-RIGHT: 0px" dir=ltr&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; VMWare deployments of the supported operating systems are also supported. See M86 Knowledge Base article &lt;A href="http://www.m86security.com/kb/article.aspx?id=11828"&gt;Q11828&lt;/A&gt;.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;H3&gt;Key:&lt;/H3&gt;&lt;P&gt;&lt;TABLE border=0 cellSpacing=3 cellPadding=3 width="85%"&gt;&lt;THEAD bgColor=#dddddd&gt;&lt;TR&gt;&lt;</description><pubDate>Mon, 08 Mar 2010 09:43:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>What versions of Marshal Security products are currently supported by Marshal Technical Support?</title><link>http://www.m86security.com/kb/article.aspx?id=10920</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP &lt;LI&gt;MailMarshal Exchange &lt;/LI&gt;&lt;LI&gt;MailMarshal SPE  &lt;LI&gt;MailMarshal SES &lt;LI&gt;Marshal Reporting Console &lt;LI&gt;MailMarshal Appliance e10000 &lt;LI&gt;WebMarshal&lt;/LI&gt;&lt;LI&gt;Marshal EndPoint Security&lt;/LI&gt;&lt;LI&gt;McAfee for Marshal&lt;/LI&gt;&lt;LI&gt;Sophos for Marshal&lt;/LI&gt;&lt;LI&gt;Counterspy for Marshal&lt;/LI&gt;&lt;LI&gt;PestPatrol for Marshal&lt;/LI&gt;&lt;LI&gt;MailMarshal Management Pack for MOM&lt;/LI&gt;&lt;LI&gt;MailMarshal Management Pack for SCOM&lt;/LI&gt;&lt;LI&gt;Security Reporting Center&lt;/LI&gt;&lt;LI&gt;Firewall Suite&lt;/LI&gt;&lt;LI&gt;imMarshal for MSN &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;What versions of Marshal products are currently supported by Marshal Technical Support? &lt;/P&gt;&lt;P&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;The following tables show the currently supported versions, planned dates of termination of support, and support end dates for discontinued versions.&lt;/P&gt;&lt;H3&gt;MailMarshal SMTP (including MailMarshal Secure)&lt;/H3&gt;&lt;TABLE border=1 cellSpacing=0 cellPadding=0 width=400&gt;&lt;TBODY style="FONT-SIZE: 11px"&gt;&lt;TR style="BACKGROUND-COLOR: silver"&gt;&lt;TD&gt;&lt;P align=center&gt;&lt;STRONG&gt;Software Version&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align=center&gt;&lt;STRONG&gt;Release Date&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align=center&gt;&lt;STRONG&gt;Discontinued Date&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;6.7.2.8378&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;November 10, 2009&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;Active&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;6.5.4.7535&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;May 27, 2009&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;Active&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;6.5.3.7407&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;May 18, 2009&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;&lt;STRONG&gt;January 31, 2010&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;6.5.1.7247&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=center&gt;April 21, 2009&lt;/P&gt;&lt;/TD&gt;&lt;TD vAlign=bottom&gt;&lt;P align=cent</description><pubDate>Mon, 08 Mar 2010 09:26:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Changes to Trickle Transfer in WebMarshal 6.5.5 and above</title><link>http://www.m86security.com/kb/article.aspx?id=12925</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5.5 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How has Trickle Transfer changed in WebMarshal 6.5.5?&lt;/LI&gt;&lt;LI&gt;How do I use Trickle Transfer and Streaming Content Types in WebMarshal 6.5.5 or above?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;WebMarshal behavior and configuration for large files and streaming media is enhanced in version 6.5.5 and above.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For most installations, no action is required.&lt;/STRONG&gt; The change will be handled automatically during upgrade.&lt;/P&gt;&lt;H3&gt;Background:&lt;/H3&gt;&lt;P&gt;WebMarshal Content Analysis rules (such as TextCensor and virus scanning) require the entire file to be available. This fact can cause several issues for web browsing.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;For large files, if a download is held back until the entire file is available, the user's browsing experience is affected. &lt;/LI&gt;&lt;LI&gt;Software downloads and other very large files could be delayed long enough that the browser times out. &lt;/LI&gt;&lt;LI&gt;Streaming media present an additional issue because the file will effectively never be complete.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;To address these issues, WebMarshal can send part of the file to the browser before completing processing. WebMarshal waits for a configurable time and/or amount of data before beginning to send the file.&lt;/P&gt;&lt;H3&gt;Previous behavior:&lt;/H3&gt;&lt;P&gt;Versions of WebMarshal before 6.5.5 "trickle" a configurable percentage of large files to the browser. This behavior displays file progress to the user, and also keeps the browser session alive. To resolve the issue of streaming media, certain MIME types could be defined as exempt from content analysis using the Streaming Content Types setting. However, the user still experiences "slow" file download, and streaming media settings can be complex to configure.&lt;/P&gt;&lt;H3&gt;Changes in Version 6.5.5 and above:&lt;/H3&gt;&lt;P&gt;In version 6.5.5 and above, the percentage trickle setting no longer</description><pubDate>Mon, 08 Mar 2010 09:25:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Configuring advanced settings for FTP proxy</title><link>http://www.m86security.com/kb/article.aspx?id=12950</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.1 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What is the behavior of WebMarshal with proxied FTP connections?&lt;/LI&gt;&lt;LI&gt;Using non-browser FTP clients &lt;EM&gt;(such as FileZilla or WinSCP)&lt;/EM&gt; through WebMarshal when HTTPS inspection is enabled&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;Non-browser FTP clients use a HTTP proxy such as WebMarshal by issuing a HTTP 1.1 CONNECT request to the proxy (requesting a connection to the remote FTP control port, usually port 21). The server replies with a passive FTP connection on a high port.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In &lt;STRONG&gt;WebMarshal 6.1 through 6.5.3&lt;/STRONG&gt;, when HTTPS inspection is enabled, these connections fail. The initial CONNECT request is treated as a request to create a SSL tunnel. The FTP data connection is not allowed.&lt;/LI&gt;&lt;LI&gt;In &lt;STRONG&gt;WebMarshal 6.5.5 and above&lt;/STRONG&gt;, WebMarshal examines the content of the CONNECT request to determine if it is a FTP connection. FTP connections that are established in this way are allowed and the content is inspected as with any other FTP connection.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Configuration:&lt;/H2&gt;&lt;P&gt;You can choose to disable the checking of the CONNECT requests, or the inspection of the FTP content sent through these connections (in WebMarshal 6.5.5 and above).&lt;/P&gt;&lt;P&gt;Configure these settings by adding an entry in the WebMarshal Proxy Configuration file (&lt;FONT face="Courier New"&gt;WMProxy.config.xml&lt;/FONT&gt;) as follows:&lt;/P&gt;&lt;PRE&gt;&lt;FONT color=#aaaaaa&gt;&amp;lt;WebMarshal&amp;gt;   &amp;lt;Proxy&amp;gt;     &amp;lt;Config&amp;gt;&lt;/FONT&gt;        &amp;lt;FTP detectFTPTunnels="&lt;EM&gt;{value}&lt;/EM&gt;" processTunnelFiles="&lt;EM&gt;{value}&lt;/EM&gt;" /&amp;gt;&lt;FONT color=#aaaaaa&gt;     &amp;lt;/Config&amp;gt;  &amp;lt;/Proxy&amp;gt;&amp;lt;/WebMarshal&amp;gt;&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;Where each value can be &lt;FONT face="Courier New"&gt;true&lt;/FONT&gt; or &lt;FONT face="Courier New"&gt;false. &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Enter the values in lower case, not including the {} braces, but including the quote marks&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;</description><pubDate>Mon, 08 Mar 2010 09:24:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Blocking Search Engines that are not Safe Search enforced</title><link>http://www.m86security.com/kb/article.aspx?id=12932</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How do I block user access to search engines that do not have Safe Search enforced by WebMarshal? &lt;/LI&gt;&lt;LI&gt;How do I require users to use Safe Search?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;WebMarshal 6.5 and above can enforce Safe Search functionality. As of the date of this article Safe Search enforcement is provided for Google, Yahoo!, and Bing.&lt;/P&gt;&lt;P&gt;To ensure that users only use the "safe" engines, you can create WebMarshal rules to allow these engines and block others.&lt;/P&gt;&lt;P&gt;Within the default WebMarshal configuration, you can implement this function as follows:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a URL Category named &lt;STRONG&gt;Safe Search Sites&lt;/STRONG&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;See the &lt;FONT face="Courier New"&gt;Safe Search Sites.txt&lt;/FONT&gt; file attached to this article for the list of URLs to this add to this category.&lt;/LI&gt;&lt;LI&gt;Import the file to the category using the &lt;STRONG&gt;Import &lt;/STRONG&gt;option on the category window.&lt;BR&gt;&lt;BR&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Create Standard rules similar to the following:&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Permit Safe Search Sites&lt;/STRONG&gt;&lt;BR&gt;&lt;FONT face="Courier New"&gt;When a web request is received&lt;BR&gt;For any users&lt;BR&gt;And where the URL is a member of &lt;FONT color=#5555dd&gt;&lt;U&gt;Safe Search Sites&lt;/U&gt;&lt;/FONT&gt;&lt;/FONT&gt; &lt;P&gt;&lt;FONT face="Courier New"&gt;Permit access&lt;BR&gt;And do not process any further standard rules&lt;BR&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Block Other Search Engines&lt;BR&gt;&lt;/STRONG&gt;&lt;FONT face="Courier New"&gt;When a web request is received&lt;BR&gt;For any users&lt;BR&gt;And where the URL is a member of &lt;FONT color=#5555dd&gt;&lt;U&gt;Search Engines&lt;BR&gt;&lt;BR&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;Block Access to this site and display &lt;U&gt;&lt;FONT color=#5555dd&gt;Blocked&lt;/FONT&gt;&lt;/U&gt; page&lt;BR&gt;And do not process any further standard rules&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;To apply this policy to a group of users&lt;/STRONG&gt; (such as Standard Users or Restricted Users), create these two rules as the &lt;STRONG&gt;last&lt;/S</description><pubDate>Mon, 08 Mar 2010 09:24:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Default Rule changes in WebMarshal 6.5.5</title><link>http://www.m86security.com/kb/article.aspx?id=12986</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5.5&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What are the changes in default policy in WebMarshal 6.5.5?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;As part of development for WebMarshal 6.5.5, the default rules and policy elements have been reviewed.&lt;/P&gt;&lt;P&gt;When you upgrade, your existing rules are retained. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;M86 Security recommends&lt;/STRONG&gt; you review the changes outlined below, and consider updating your existing rules.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The TRACEnet function and Proxy Caching are enabled by default. &lt;LI&gt;Policy evaluation (rule processing) is enabled by default.&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;Note that &lt;STRONG&gt;all requests will be denied&lt;/STRONG&gt; until users have been imported or IP range groups configured.&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Default rules have been reorganized. See the Default Rules document for details.&lt;/LI&gt;&lt;/UL&gt;</description><pubDate>Mon, 08 Mar 2010 09:23:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Using a UNC path for Configuration Backup</title><link>http://www.m86security.com/kb/article.aspx?id=12959</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5.5 and above &lt;LI&gt;Automatic Configuration Backup&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How do I configure WebMarshal and Windows accounts to allow configuration backup to a UNC path?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;WebMarshal Automatic Configuration Backup (6.5.5 and above) can save the backups to a network location specified by a UNC path. &lt;/P&gt;&lt;P&gt;For this function to work, you must run the WebMarshal Array Manager service under an account that has permission to read configuration and write to the remote location. &lt;/P&gt;&lt;P&gt;To set up the account:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a Windows account. &lt;/LI&gt;&lt;LI&gt;Change permission on the WebMarshal install folder to give the account write (modify) access.&lt;/LI&gt;&lt;LI&gt;Change permission on the remote share (UNC path) to give the account write (modify) access.&lt;/LI&gt;&lt;LI&gt;Change WebMarshal security (using the WebMarshal Security Tool) to give the account full access to WebMarshal policy. &lt;/LI&gt;&lt;LI&gt;Open the Windows Services manager and change the logon account for the WebMarshal Array Manager service. &lt;/LI&gt;&lt;LI&gt;Restart the WebMarshal Array Manager service. &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;After completing the above steps you can use WebMarshal Server and Array Properties to set the backup directory to the UNC path.&lt;/P&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;P&gt;If the configuration backup to the network location fails, WebMarshal takes the following actions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Logs the failure and notifies the administrator.&lt;/LI&gt;&lt;LI&gt;Attempts to back up configuration to the default location within the WebMarshal install location. If this action fails, again WebMarshal logs the failure and notifies the administrator.&lt;/LI&gt;&lt;/OL&gt;</description><pubDate>Mon, 08 Mar 2010 09:23:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Firefox cannot detect updates</title><link>http://www.m86security.com/kb/article.aspx?id=12958</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.1 and above &lt;LI&gt;Firefox &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal HTTPS Content Inspection enabled.&lt;/LI&gt;&lt;LI&gt;Firefox does not detect version updates. &lt;/LI&gt;&lt;LI&gt;Attempts to manually check for updates (Help &amp;gt; Check for Updates) will fail with one of the following errors: &lt;BR&gt;&lt;FONT face="Courier New"&gt;Update XML file malformed (200) &lt;BR&gt;AUS: Update XML File Not Found (404)&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;&lt;P&gt;Firefox checks if updates are available by contacting &lt;FONT face="Courier New"&gt;https://aus2.mozilla.org/. &lt;/FONT&gt;As part of this process, Firefox examines the HTTPS certificate to see who it was issued by. If the issuer is unknown, or is not one of the issuers built into Firefox, the update process fails. WebMarshal's content inspection root certificate is not built in and is therefore causing Firefox to fail to update.&lt;BR&gt;&lt;/P&gt;&lt;H2&gt;Resolution:&lt;/H2&gt;&lt;P&gt;Firefox will update correctly if WebMarshal is configured so that it will not inspect connections to &lt;FONT face="Courier New"&gt;https://aus2.mozilla.org/&lt;/FONT&gt;.  &lt;/P&gt;&lt;P&gt;To avoid inspecting these connections while using HTTPS Content Inspection for otehr sites, add an HTTPS rule for this site using the action &lt;STRONG&gt;Permit access and do not inspect content.&lt;/STRONG&gt;&lt;/P&gt;</description><pubDate>Mon, 08 Mar 2010 09:23:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Issues after uninstalling WebMarshal from one ISA node</title><link>http://www.m86security.com/kb/article.aspx?id=13684</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.X &lt;LI&gt;Microsoft ISA Server &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal installed as plug-in to ISA in a multi-node environment&lt;/LI&gt;&lt;LI&gt;Uninstalled WebMarshal from one node while in plug-in mode&lt;/LI&gt;&lt;LI&gt;Remaining nodes do not correctly use the WebMarshal plug-in&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal was uninstalled from a node while in plug-in mode. Due to ISA architecture, this action unregisters the plug-in on all nodes.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Resolution:&lt;/H2&gt;&lt;P&gt;&lt;STRONG&gt;To recover from this problem,&lt;/STRONG&gt; perform the following steps on each ISA processing node (including the node where you uninstalled WebMarshal):&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Open the Windows Services control panel. If any WebMarshal services are present and running, stop these services. This action will also stop the ISA firewall service.&lt;/LI&gt;&lt;LI&gt;Open a command prompt.&lt;/LI&gt;&lt;LI&gt;Navigate to the WebMarshal install location.&lt;/LI&gt;&lt;LI&gt;Enter the following command to manually de-register the WebMarshal filter:&lt;BR&gt;&lt;FONT face="Courier New"&gt;regsvr32 -u WMFilter.dll&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;On the nodes where you want to continue using WebMarshal as a plug-in, enter the following command to re-register the WebMarshal filter:&lt;BR&gt;&lt;FONT face="Courier New"&gt;regsvr32 WMFilter.dll&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Start WebMarshal services and any ISA services that were stopped.&lt;/LI&gt;&lt;/OL&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;P&gt;This problem does not occur if you first re-configure the node to use to WebMarshal Proxy (not ISA plug-in) before uninstallation.&lt;/P&gt;</description><pubDate>Mon, 08 Mar 2010 09:22:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Services do not start after upgrade</title><link>http://www.m86security.com/kb/article.aspx?id=13683</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal &lt;LI&gt;Upgrade from 6.5.3 or below to 6.5.5 or above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Array Manager does not start after upgrade.&lt;/LI&gt;&lt;LI&gt;Other services could also fail to start&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;This problem is due to a known issue with .NET Framework 2.0 RTM. The .NET Framework times out while attempting to validate the certificate used to sign the installation. &lt;/LI&gt;&lt;LI&gt;This problem will not occur if .NET Framework SP1 or above is installed.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Resolution:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Start the services manually.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;The problem only occurs once at the time of WebMarshal upgrade.&lt;/LI&gt;&lt;LI&gt;You should consider applying the latest service pack to the .NET framework on affected servers.&lt;/LI&gt;&lt;/UL&gt;</description><pubDate>Mon, 08 Mar 2010 09:22:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Upgrading WebMarshal Array installations</title><link>http://www.m86security.com/kb/article.aspx?id=13031</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.x &lt;LI&gt;Array installations &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What is the correct order for upgrading a WebMarshal array installation with separate Array Manager and Processing Node servers?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;To upgrade an array with multiple processing nodes, &lt;STRONG&gt;upgrade the Array Manager first.&lt;/STRONG&gt; After upgrading the Array Manager, upgrade any additional processing nodes.&lt;/P&gt;&lt;P&gt;This order minimizes disruption when the version of XML configuration files is changed by the upgrade.&lt;/P&gt;&lt;P&gt;When the Array Manager has been updated you will note the following symptoms until you upgrade the nodes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A message will be logged in the Node Controller service logs: &lt;FONT face="Courier New"&gt;Warning - General : Contact with the WebMarshal Array Manager has been lost.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;WebMarshal Console will show the status of the node's configuration as "out of date" with the previous version.&lt;/LI&gt;&lt;LI&gt;The nodes will continue to process requests using the last valid configuration.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;P&gt;If you upgrade the nodes first, you will experience the following symptoms until the Array Manager is updated:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Proxy and Engine services will not start.&lt;/LI&gt;&lt;LI&gt;The following error message will be logged by each service: &lt;FONT face="Courier New"&gt;Error - Unexpected Error : An unexpected error has occurred: Fetch policy - Policy file is incorrect version ( should be 5 ).&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Once you upgrade the Array Manager, you may need to join the nodes to the array using the Server Tool.&lt;/LI&gt;&lt;/UL&gt;</description><pubDate>Mon, 08 Mar 2010 09:22:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Additions to Release Notes for WebMarshal 6.5</title><link>http://www.m86security.com/kb/article.aspx?id=12719</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What are the Release Notes for WebMarshal 6.5? &lt;LI&gt;What are the Release Notes for WebMarshal Reports 6.5?&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;The &lt;A href="http://www.m86security.com/software/webmarshal/WMReleaseNotes6.5.5.6975.htm" target=_blank&gt;Release Notes&lt;/A&gt; and &lt;A href="http://www.m86security.com/software/webmarshal/WMReportsReleaseNotes6.5.5.8951.htm" target=_blank&gt;Reports Release Notes&lt;/A&gt; included with WebMarshal 6.5 are accurate as of the date of publication.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The latest release is 6.5.5 (6.5.5.6975, March 9, 2010).&lt;/STRONG&gt;  &lt;/P&gt;&lt;P&gt;This article will provide any additional information generated after that date.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For specific information about an item fixed in the 6.5.3 release, see M86 Knowledge Base article &lt;A href="http://www.m86security.com/kb/article.aspx?id=12944"&gt;Q12944&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt; &lt;/P&gt;</description><pubDate>Mon, 08 Mar 2010 08:57:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>How do I customize the initial 220 response greeting string that MailMarshal returns to a sender?</title><link>http://www.m86security.com/kb/article.aspx?id=10324</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP 5.X &lt;LI&gt;MailMarshal SMTP 6.X&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;How do I customize the initial 220 response greeting string that MailMarshal returns to a sender? &lt;P&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;You can change both the &lt;STRONG&gt;Greeting String&lt;/STRONG&gt; and &lt;STRONG&gt;Received&lt;/STRONG&gt; field information from the advanced Receiver properties in the MailMarshal Configurator.&lt;/P&gt;&lt;P&gt;&lt;U&gt;MailMarshal SMTP 6.5 and above&lt;/U&gt;:&lt;/P&gt;&lt;P&gt;Go to &lt;STRONG&gt;Tools | MailMarshal Properties | Receiver Properties | Advanced&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;U&gt;MailMarshal SMTP 6.0 through 6.4:&lt;/U&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Go to &lt;STRONG&gt;Tools &lt;/STRONG&gt;| &lt;STRONG&gt;Server and Array Properties &lt;/STRONG&gt;| &lt;STRONG&gt;Advanced&lt;/STRONG&gt; tab. &lt;LI&gt;Click the &lt;STRONG&gt;Additional Options&lt;/STRONG&gt; button. &lt;LI&gt;Click the &lt;STRONG&gt;Receiver&lt;/STRONG&gt; tab.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;U&gt;MailMarshal SMTP 5.X&lt;/U&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Go to &lt;STRONG&gt;Tools &lt;/STRONG&gt;| &lt;STRONG&gt;Server Properties &lt;/STRONG&gt;| &lt;STRONG&gt;Advanced&lt;/STRONG&gt; tab. &lt;LI&gt;Click the &lt;STRONG&gt;Additional Options&lt;/STRONG&gt; button. &lt;LI&gt;Click the &lt;STRONG&gt;Receiver&lt;/STRONG&gt; tab.&lt;/LI&gt;&lt;/OL&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;P&gt;Example Greeting string: 220 ExchangeServer.Company.com ESMTP MailMarshal (v5.5.5.9) Ready&lt;/P&gt;&lt;P&gt;&lt;I&gt;&lt;DL&gt;&lt;DT&gt;This article was previously published as: &lt;DD&gt;NETIQKB37854&lt;/DD&gt;&lt;/DL&gt;&lt;/I&gt;</description><pubDate>Sun, 07 Mar 2010 09:55:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>MailMarshal for Exchange Engine takes a long time to start.</title><link>http://www.m86security.com/kb/article.aspx?id=10617</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal Exchange 5.X&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal Exchange Engine takes a long time to start. &lt;LI&gt;MailMarshal Exchange Engine is slow to start. &lt;LI&gt;MailMarshal Exchange Engine is taking too long to start. &lt;LI&gt;&lt;P&gt;MailMarshal Exchange is not starting or restarting in an acceptable amount of time. &lt;/P&gt;&lt;LI&gt;MailMarshal Exchange takes in excess of 5 to 10 minutes to start. &lt;LI&gt;&lt;P&gt;Error: 'Unable to get groups from domain &amp;lt;cn=users,cn=builtin,dc=server,dc=domain,dc=com&amp;gt; - &amp;lt;Not enough storage is available to complete this operation.&amp;gt;'&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;&lt;P&gt;On startup, MailMarshal Exchange attempts to download the entire tree from the Global Catalog.  If the entire tree for the organization is substantially large, or if there are Global Catalog server issues, MailMarshal may not be able to complete the download in an acceptable amount of time.&lt;/P&gt;&lt;P&gt;&lt;H2&gt;Reply:&lt;/H2&gt;&lt;P&gt;In MailMarshal Exchange 5.0.3.30, a change was made to the Engine service to allow domains to be excluded from the Global Catalog lookup.&lt;/P&gt;&lt;P&gt;This change requires the following registry modifications:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Warning&lt;/STRONG&gt;: Using the Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system.  Marshal cannot guarantee that problems resulting from the incorrect use of Registry Editor can be resolved. Make sure that you backup your Registry prior to making any changes.&lt;/P&gt;&lt;OL style="MARGIN-RIGHT: 0px" dir=ltr&gt;&lt;LI&gt;Launch the Microsoft Registry Editor. &lt;LI&gt;Go to the following key:  &lt;STRONG&gt;HKEY_LOCAL_MACHINE&lt;/STRONG&gt; | &lt;STRONG&gt;SOFTWARE&lt;/STRONG&gt; | &lt;STRONG&gt;Marshal Software&lt;/STRONG&gt; | &lt;STRONG&gt;MailMarshal Exchange&lt;/STRONG&gt; | &lt;STRONG&gt;Default&lt;/STRONG&gt; | &lt;STRONG&gt;Engine&lt;/STRONG&gt;. &lt;LI&gt;Add the key &lt;STRONG&gt;ADDomainExclusions&lt;/STRONG&gt; as a multi-string value. The k</description><pubDate>Sun, 07 Mar 2010 09:29:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Configuring the Authentication Bypass Cache</title><link>http://www.m86security.com/kb/article.aspx?id=12734</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.5 and above &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Authentication problems when using Apple clients through WebMarshal&lt;/LI&gt;&lt;LI&gt;Authentication problems when using Microsoft Silverlight Player through WebMarshal &lt;/LI&gt;&lt;LI&gt;Authentication problems with browser helper applications&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Background:&lt;/H2&gt;&lt;P&gt;In certain circumstances, browsers and browser plug-ins on the Apple Macintosh operating systems fail to authenticate with the Proxy. These pieces of software see the authentication request as a general failure and fail the request.&lt;/P&gt;&lt;P&gt;Other browser plug-ins can also have this problem. Silverlight Player is a known example.&lt;/P&gt;&lt;P&gt;The Authentication Bypass mechanism described here is an advanced feature designed to overcome this limitation in the client software. It is not limited to the named clients and could be used anywhere that a similar problem occurs.&lt;/P&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;The authentication bypass mechanism makes a short-term association between an IP address and a user. &lt;/P&gt;&lt;P&gt;When a user is authenticated with WebMarshal from a particular workstation, any new connections made to the Proxy from that workstation will be automatically authenticated with the user's credentials, based on the IP address. &lt;/P&gt;&lt;P&gt;A number of configuration options are available to ensure that the feature applies only to an intended set of client workstations, and only to certain software clients.&lt;/P&gt;&lt;P&gt;This feature is configured by making changed to the &lt;FONT face="Courier New"&gt;WMProxy.config.xml&lt;/FONT&gt; file on the WebMarshal server, or on each processing node in a WebMarshal array. &lt;STRONG&gt;To apply the changes&lt;/STRONG&gt;, restart the WebMarshal Proxy service.&lt;/P&gt;&lt;P&gt;Two &lt;STRONG&gt;sample&lt;/STRONG&gt; configuration sections are shown below. &lt;/P&gt;&lt;BLOCKQUOTE style="MARGIN-RIGHT: 0px" dir=ltr&gt;&lt;P&gt;&lt;STRONG&gt;Note: You must modify the examples to suit the local e</description><pubDate>Thu, 04 Mar 2010 09:50:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>How do I verify the score a missed message received in SpamCensor?</title><link>http://www.m86security.com/kb/article.aspx?id=10534</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How do I verify the score a missed message received in SpamCensor? &lt;LI&gt;How do I log all spam (SpamCensor) results?&lt;/LI&gt;&lt;LI&gt;How do I verify the score a missed message received from SpamProfiler (MailMarshal 6.7 and above)? &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;You may want to view the spam scoring of messages that were not blocked by MailMarshal.  By default, MailMarshal will only log results to the engine log file if the SpamCensor or SpamProfiler triggers. If you want to log all results, regardless of whether or not the features trigger, you will need to modify the registry of the MailMarshal Server.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Warning:&lt;/STRONG&gt; Using the Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Marshal cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Make sure that you backup your Registry prior to making any changes.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Open the Registry Editor. &lt;LI&gt;Go to &lt;STRONG&gt;HKEY_LOCAL_MACHINE\SOFTWARE\NetIQ\MailMarshal\Default\Engine&lt;/STRONG&gt;. &lt;LI&gt;Add a new &lt;STRONG&gt;DWORD&lt;/STRONG&gt; value named &lt;STRONG&gt;LogSpamAlways&lt;/STRONG&gt;. &lt;LI&gt;Set the value to &lt;STRONG&gt;0 &lt;/STRONG&gt;for false, or &lt;STRONG&gt;1 &lt;/STRONG&gt;for true (i.e. log all results). &lt;LI&gt;Save your registry settings. &lt;LI&gt;On MailMarshal 5.x, reload the rules, and restart the MMEngine service&lt;/LI&gt;&lt;LI&gt;On MailMarshal 6.x, restart the MMArrayManager service, commit configuration changes, then restart the MMController service on each node. &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;This feature was added for SpamCensor in MailMarshal SMTP version 5.5.3.2.&lt;/LI&gt;&lt;LI&gt;This feature was added for SpamProfiler in MailMarshal SMTP version 6.7. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;I&gt;&lt;DL&gt;&lt;DT&gt;This article was previously published as: &lt;DD&gt;NETIQKB39846&lt;/DD&gt;&lt;/DL&gt;&lt;/I&gt;</description><pubDate>Thu, 04 Mar 2010 09:30:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Blended Threats Module updates fail</title><link>http://www.m86security.com/kb/article.aspx?id=12931</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;&lt;SPAN id=_ctl0_ArticleRepeater__ctl1_ArticleText&gt; This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal 6.7 and above &lt;LI&gt;Windows 2003 SP2 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Why do Blended Threats Module updates fail?&lt;/LI&gt;&lt;LI&gt;Error message: &lt;FONT face="Courier New"&gt;HttpPost: 12057&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;If your Blended Threats Module (BTM) updates fail it can be because the MailMarshal Engine (processing node server) has been denied access to the Internet (HTTP and HTTPS). You must allow this access to use the BTM. You can configure MailMarshal to use a proxy server if required for node access. For details, see the documentation for "Internet Access" for your version of MailMarshal.&lt;/P&gt;&lt;P&gt;If you can confirm the MailMarshal node &lt;STRONG&gt;does&lt;/STRONG&gt; have access to the Internet, you may need to change the account used to run the Engine service. &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This step is typically required on Windows Server 2008, or Server 2003 with current updates, where access is via a proxy server. (For details of the issue, see the Notes section of this article.)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The account you select must:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Have permission to log on to the server&lt;/LI&gt;&lt;LI&gt;Be a member of the local Administrators group on the server&lt;/LI&gt;&lt;LI&gt;Have a valid user profile on the server&lt;/LI&gt;&lt;LI&gt;Have ability to browse the web, including configuration of any proxy settings within Internet Explorer if required.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you have an array of MailMarshal servers, follow the steps below on &lt;STRONG&gt;each processing node server&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;To change the account and confirm access:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Log on to the MailMarshal node server using the account you plan to use for the Engine service. &lt;LI&gt;Using Internet Explorer, if necessary add proxy details.&lt;LI&gt;&lt;STRONG&gt;Browse to&lt;/STRONG&gt; the following sites &lt;EM&gt;(browsing to the sites verif</description><pubDate>Wed, 03 Mar 2010 07:08:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>FTP over HTTP: Unauthorized - Error 401</title><link>http://www.m86security.com/kb/article.aspx?id=13414</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;When trying to access an FTP site, error 401 with error reason: “FTP over HTTP: Unauthorized” is returned.&lt;/div&gt;&lt;br&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;When browsing to a password protected FTP site through the Vital Security Web Appliance, the browser returns the following error:&lt;BR&gt;&lt;BR&gt;&lt;IMG alt="" src="http://www.m86security.com/kb/attachments/images/755~kb FTP 401 Error.jpg" border=0&gt;&lt;BR&gt; &lt;BR&gt;When browsing straight to the web-site, a dialog box which requires the user credentials appears:&lt;BR&gt;&lt;BR&gt;&lt;IMG alt="" src="http://www.m86security.com/kb/attachments/images/756~kb FTP Dialog.jpg" border=0&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;The problem is caused because the Vital Security Web Appliance is trying to access the FTP server with an anonymous account, which results in a failed login attempt.&lt;BR&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;In order to resolve this issue, the login credentials should be included in the URL in the following format: &lt;A href="ftp://username:password@ftp.adress.com"&gt;&lt;FONT color=#0000ff&gt;ftp://&lt;STRONG&gt;username&lt;/STRONG&gt;:&lt;STRONG&gt;password&lt;/STRONG&gt;@ftp.adress.com&lt;/FONT&gt;&lt;/A&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.3.x&lt;BR&gt;8.4.x&lt;BR&gt;8.5.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1576&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 01 Mar 2010 11:34:00 GMT</pubDate><dc:creator>Eric Hanson</dc:creator></item><item><title>How do I take my Enterprise Reporter out of evaluation mode?</title><link>http://www.m86security.com/kb/article.aspx?id=12494</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Enterprise Reporter &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;How do I take my Enterprise Reporter out of evaluation mode? &lt;H2&gt;Reply&lt;/H2&gt;&lt;P style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt;&lt;SPAN style="FONT-FAMILY: Arial; FONT-SIZE: 11pt"&gt;&lt;FONT size=2 face=Verdana&gt;After the designated evaluation period has expired, you may extend your evaluation period, or activate the unit and use it in the activated mode. To change the evaluation mode from the Administrator console&lt;/FONT&gt; &lt;FONT size=2 face=Verdana&gt;by &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: Arial; FONT-SIZE: 11pt; mso-bidi-font-size: 10.0pt"&gt;&lt;FONT size=2 face=Verdana&gt;logging in to the Reporter port 808, 88 for reports&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: Arial; FONT-SIZE: 11pt"&gt;:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Arial; FONT-SIZE: 11pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;•&lt;FONT face=Verdana&gt;&lt;FONT size=2&gt; In the ER Status pop-up box (see Fig. A-1), click &lt;B&gt;Change Evaluation Mode&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;&lt;/P&gt;&lt;P align=center&gt;&lt;IMG border=0 hspace=0 src="http://www.m86security.com/kb/Attachments/9def2cbf-40e1-4997-a2f6-3d80.JPG"&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal align=center&gt;&lt;FONT size=2&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN style="FONT-FAMILY: Arial; FONT-SIZE: 11pt"&gt;(&lt;FONT size=2 face=Verdana&gt;Fig. A-1&lt;/FONT&gt;)&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: Arial; FONT-SIZE: 11pt; mso-bidi-font-size: 10.0pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;SPAN style="FONT-FAMILY: Arial; FONT-SIZE: 11pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;P style="MARGIN: 0in </description><pubDate>Mon, 22 Feb 2010 02:43:00 GMT</pubDate><dc:creator>Imran Chaudhry</dc:creator></item><item><title>Is there any risk in Using IP Lookup when uploading a Master List to a custom category?</title><link>http://www.m86security.com/kb/article.aspx?id=12293</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;R3000 &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;Is there any risk in Using IP Lookup when uploading a Master List to a custom category? &lt;H2&gt;Reply:&lt;/H2&gt;&lt;P&gt;Remember, with IP Lookup enabled, filtering will take place by IP address as well. So if the custom category is set to a Block List, then IP addresses that correspond to URLs in the uploaded file will be blocked along with the URLs. &lt;P&gt;Conversely, if the custom category is set to an Allow List, then IP addresses that correspond to URLs in the uploaded file will be allowed along with the URLs. Depending on how your DNS handles certain web requests, you may run into the risk of different URLs resolving to the same web host IP address, which is common among smaller websites. &lt;P&gt;This can pose a problem if you have the following scenario: * Custom category CustomAllow sits in the Allow List of a profile. * Custom category CustomBlock sits in the Block List. * CustomAllow contains www.goodurl.com * CustomBlock contains www.badurl.com * www.goodurl.com and www.badurl.com are both hosted by the same site and both resolve to IP address 209.254.254.254 * IP Lookup was used when uploading the Master List for both of these custom categories In this situation, the IP address 209.254.254.254 will reside in both CustomAllow and CustomBlock. &lt;P&gt;Remember, the Allow List takes precedence over Block in the filtering hierarchy. So if a user with this profile goes to www.badurl.com, in some situations depending on your DNS, R3000 will see this request as 209.254.254.254. Thus, since this IP address exists in a category contained within the Allow List, the request will not be blocked. &lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;8e6 KB 276467&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;</description><pubDate>Fri, 19 Feb 2010 05:11:00 GMT</pubDate><dc:creator>Alfred Alva</dc:creator></item><item><title>Resetting security permissons</title><link>http://www.m86security.com/kb/article.aspx?id=13708</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 6.X &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Locked out of WebMarshal Console&lt;/LI&gt;&lt;LI&gt;Deleted all users and groups from WebMarshal Security Tool&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;If you have mistakenly removed all groups and users from WebMarshal Security using the Security Tool, you will not be able to use any WebMarshal user interfaces including the Security Tool.&lt;/P&gt;&lt;P&gt;You can reset security to the default level by editing a file on the server.&lt;/P&gt;&lt;P&gt;The default setting is for administrators of the Array Manager server to have access.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;To reset security:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Log on to the Array Manager server (or standalone WebMarshal server) using an account with administrator permission.&lt;/LI&gt;&lt;LI&gt;Locate the following file within the WebMarshal installation:&lt;BR&gt;&lt;FONT face="Courier New"&gt;...\Array Manager\Policy\ArrayPolicy.Working.xml&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Make a backup copy of the file.&lt;/LI&gt;&lt;LI&gt;Edit the file with a text or XML editor&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Note: take care when editing the file&lt;/STRONG&gt;. For help with editing XML documents, see M86 Knowledge Base article &lt;A href="http://www.m86security.com/kb/article.aspx?id=12705"&gt;Q12705&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Locate an attribute that begins:&lt;BR&gt;&lt;FONT face="Courier New"&gt;security="O:BAG:BAD:..."&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Remove the entire &lt;FONT face="Courier New"&gt;security &lt;/FONT&gt;attribute.&lt;/LI&gt;&lt;LI&gt;Save the XML file, and then restart the WebMarshal Array Manager service.&lt;/LI&gt;&lt;/OL&gt;</description><pubDate>Wed, 17 Feb 2010 09:05:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>My http requests are being categorized/filtered, but I don't get the "Access Denied" block page.</title><link>http://www.m86security.com/kb/article.aspx?id=12398</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;R3000 &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;My http requests are being categorized/filtered, but I don't get the "Access Denied" block page. &lt;H2&gt;Reply&lt;/H2&gt;Go through the following checklist.  If you need assistance with any of these items, please reference our FAQs or contact our technical support staff for additional help: &lt;UL&gt;&lt;LI&gt;If you are using a custom block page, ensure that your web server is up and running.  Are you able to browse directly to your web server from your workstation?&lt;/LI&gt;&lt;LI&gt;Check your firewall to verify that the R3000 can send the “URL redirect” to users on TCP port 81, and that users can connect to the R3000 on port 80 to download the block page. &lt;/LI&gt;&lt;LI&gt;Verify that your workstation can communicate with the R3000 to download the block page by typing this in your web browser:  &lt;A href="http://X.X.X.X:81/cgi/block.cgi"&gt;http://X.X.X.X:81/cgi/block.cgi&lt;/A&gt; (note: replace the “X’s” with the IP address of your R3000’s block page interface. Failure to download the block page from the R3000 might indicate a routing or firewall issue between the R3000 and the users.&lt;/LI&gt;&lt;LI&gt;If you are using an http proxy server, be sure that the URL redirect and block page is not going through the proxy server.  To accomplish this, set up an exception in your web browser’s proxy settings.  For example, if you’re using Internet Explorer, go to Internet Options -&amp;gt; Connections -&amp;gt; LAN Settings -&amp;gt; Advanced -&amp;gt; Exceptions.  In the “Exceptions” list, enter the IP address of your R3000’s block page interface, &lt;U&gt;and the R3000’s hostname&lt;/U&gt;.  If you are using a custom block page, you should enter the IP address and hostname of your web server, &lt;U&gt;in addition&lt;/U&gt; to the IP address and hostname of the R3000.  You will have to make this simple modification on every workstation that’s being filtered.  Normally, you can push this out as a Policy from your Active Directory</description><pubDate>Tue, 16 Feb 2010 08:32:00 GMT</pubDate><dc:creator>Imran Chaudhry</dc:creator></item><item><title>Configuring Windows Firewall on MailMarshal Servers</title><link>http://www.m86security.com/kb/article.aspx?id=12209</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP &lt;LI&gt;MailMarshal Exchange &lt;LI&gt;MailMarshal SES &lt;LI&gt;Windows Firewall &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;What settings are required to allow MailMarshal to work with Windows Firewall? &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;When you install MailMarshal server components on a computer with Windows Firewall enabled, you must add exceptions to the Windows firewall configuration to allow MailMarshal to function correctly. These exceptions allow inbound connections to the MailMarshal components.&lt;/P&gt;&lt;P&gt;The required exceptions depend on the MailMarshal version and the server role.&lt;/P&gt;&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;&lt;P&gt;&lt;STRONG&gt;Notes:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;MailMarshal SMTP 6.5&lt;/STRONG&gt; &lt;STRONG&gt;and above&lt;/STRONG&gt; automatically adds most required exceptions for the MailMarshal services. &lt;/LI&gt;&lt;LI&gt;In the details below, all executables mentioned are found in the MailMarshal installation folder.&lt;/LI&gt;&lt;LI&gt;The TCP ports listed are the default values. It is possible to change the ports MailMarshal uses. &lt;/LI&gt;&lt;LI&gt;M86 Security &lt;STRONG&gt;does not recommend&lt;/STRONG&gt; opening TCP ports 137,138,139 for a computer open to the Internet. If you require remote Configurator access to a computer in this situation, you could use Remote Desktop.&lt;/LI&gt;&lt;LI&gt;For additional details of port usage, see M86 Security Knowledge Base article &lt;A href="http://www.m86security.com/kb/article.aspx?id=10905"&gt;Q10905&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;H3 dir=ltr&gt;MailMarshal SMTP&lt;/H3&gt;&lt;P&gt;&lt;STRONG&gt;Version 6.x:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;MailMarshal SMTP 6.5&lt;/STRONG&gt; &lt;STRONG&gt;and above&lt;/STRONG&gt; automatically adds required exceptions for the MailMarshal services that are actually installed on a server (but not the File and Printer Sharing service). If you do not need remote access to the Configurator, no further action is required. Un-installing MailMarshal removes the ex</description><pubDate>Thu, 11 Feb 2010 14:05:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>How do I add custom file type definitions to MailMarshal SMTP?</title><link>http://www.m86security.com/kb/article.aspx?id=10199</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP 5.5 &lt;LI&gt;MailMarshal SMTP 6.X&lt;/LI&gt;&lt;LI&gt;MailMarshal SMTP 2006&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How do I add custom file type definitions to MailMarshal? &lt;LI&gt;How do I configure MailMarshal to correctly recognize my file types? &lt;LI&gt;How do I prevent my "Block Unknown Attachments" rule from triggering on legitimate attachments? &lt;LI&gt;Why is MailMarshal blocking legitimate file types? &lt;LI&gt;How do I stop MailMarshal from blocking legitimate file types?&lt;BR&gt;&lt;BR&gt;&lt;/LI&gt;&lt;LI&gt;See also &lt;A href="http://www.m86security.com/kb/Article.aspx?id=12988"&gt;Q12988&lt;/A&gt;, &lt;EM&gt;How do I remove or disable custom filetypes?&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;&lt;P&gt;MailMarshal recognizes many, but not all, executable, image, document, movie, sound, archive, encrypted, and other file types. If MailMarshal does not recognize an attachment as a legitimate file type during mail processing, it tags the unrecognized file as Binary Unknown (BIN). By default, MailMarshal blocks the file with the Block Unknown Attachments rule. The workaround is to add a custom file type definition locally. Once MailMarshal recognizes the file as a custom file type, and not as BIN, the attachment will no longer trigger the Block Unknown Attachments rule. &lt;/P&gt;&lt;P&gt;This article explains how MailMarshal administrators can create custom file type definitions, enabling MailMarshal to recognize and pass files you do not want it to block. &lt;/P&gt;&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;&lt;P&gt;&lt;STRONG&gt;Warning:&lt;/STRONG&gt; Custom types &lt;STRONG&gt;override MailMarshal's built-in types&lt;/STRONG&gt;. MailMarshal assigns only one file type to each file. If a file is recognized as a custom type, it may not be unpacked or scanned for malware as expected. This behavior can result in security breaches. Test any custom file types carefully.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; This solution is intended for advanced users. Most sites will not nee</description><pubDate>Thu, 11 Feb 2010 07:31:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>WebMarshal console takes a long time to respond</title><link>http://www.m86security.com/kb/article.aspx?id=12220</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;WebMarshal 3.7&lt;/LI&gt;&lt;LI&gt;WebMarshal 6.X&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;The WebMarshal console takes a long time to respond when you commit the configuration&lt;/LI&gt;&lt;LI&gt;Configuration backups fail&lt;/LI&gt;&lt;LI&gt;Error message: &lt;FONT face="Courier New"&gt;Failed to create backup: Exception of type 'System.OutOfMemoryException' was thrown.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;One or more URL categories with over 5000 entries&lt;/LI&gt;&lt;LI&gt;A common reason for very large URL categories is URL harvesting with the "Add URL to category" rule action.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Resolution:&lt;/H2&gt;&lt;P&gt;In WebMarshal 3.7 and above, you can use FileFilter (text based URL filtering lists) to maintain large URL categories outside the WebMarshal user interface. FileFilter categories are reloaded on a daily schedule.&lt;/P&gt;&lt;P&gt;Follow the steps below to convert a URL category to a FileFilter category:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Log on to the WebMarshal Array Manager computer.&lt;/LI&gt;&lt;LI&gt;Open the WebMarshal Console, and navigate to the URL category you want to convert.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Export to File&lt;/STRONG&gt; at the top of the category window.&lt;/LI&gt;&lt;LI&gt;Save the file as a plain text (.txt) file in the Array Manager FileFilter folder. By default this folder is located at: &lt;FONT face="Courier New"&gt;C:\Program Files\Marshal\WebMarshal\ArrayManager\Policy\FilteringLists\FileFilter&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Using Notepad or another text editor, open the file you have just saved. At the top of the file, add text within brackets. The text must include an integer and a name for the category, as seen in the example image below.&lt;BR&gt;&lt;BR&gt;&lt;DIV align=center&gt;&lt;IMG hspace=0 src="http://www.m86security.com/kb/Attachments/ea554e99-7066-42ce-b5bf-90d7.JPG" border=0&gt;&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;To make the file easy to find, the file name and category name should match.&lt;/LI&gt;&lt;LI&gt;Each FileFilter category &lt;STRONG&gt;mus</description><pubDate>Wed, 10 Feb 2010 14:12:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Microsoft Windows Update causes database connection problem for SPE Web Console </title><link>http://www.m86security.com/kb/article.aspx?id=11754</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SPE 2.1.0+&lt;LI&gt;Internet Explorer 7 &lt;LI&gt;Internet Explorer 8 &lt;LI&gt;Microsoft Windows Update KB937143&lt;/LI&gt;&lt;LI&gt;Microsoft Windows Update KB939653&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Applied Windows Update KB937143 or KB939653 on MailMarshal SPE Web Console server.&lt;/LI&gt;&lt;LI&gt;Upgraded server to Internet Explorer 7&lt;/LI&gt;&lt;LI&gt;Upgraded server to Internet Explorer 8&lt;/LI&gt;&lt;LI&gt;MailMarshal SPE Web Console v2.1.0 - v2.2.0 displays error: &lt;EM&gt;System Error: Database could not be contacted - Login failed for user 'sa'.&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;MailMarshal SPE Web Console v2.3.0 and above displays error: &lt;EM&gt;System Error: Database Version not supported - Expected minimum 9 but got -1.&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;The Web Console cannot be used. Other MailMarshal SPE and MailMarshal SMTP components continue to function.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt; &lt;/P&gt;&lt;H2&gt;Causes&lt;/H2&gt;&lt;P&gt;Windows Update KB937143 (&lt;EM&gt;MS07-045: Cumulative Security Update for Internet Explorer&lt;/EM&gt;) causes unexpected changes in some Windows system functionality that is used by the MailMarshal SPE Web Console website.&lt;/P&gt;&lt;P&gt;It appears that the account used as the identity by the SPE Application Pool has insufficient/incorrect privileges to complete a request. By default the SPE App Pool uses an identity of "Network Service".&lt;/P&gt;&lt;P&gt;This update only affects servers with IE7 or IE8 installed. Servers that have IE6 installed are not affected.&lt;/P&gt;&lt;H2&gt;Resolution:&lt;/H2&gt;&lt;P&gt;Microsoft has issued a hotfix that resolves this issue. For more information, please see the following Microsoft Knowledge Base article:&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/945701"&gt;http://support.microsoft.com/kb/945701&lt;/A&gt;&lt;/P&gt;&lt;H2&gt;Workaround:&lt;/H2&gt;&lt;P&gt;If you are unable to apply the Microsoft hotfix, choose one of the following three possible workarounds: &lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Safest workaround:&lt;/LI&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Correct Security Permissions in the R</description><pubDate>Tue, 09 Feb 2010 13:51:00 GMT</pubDate><dc:creator>SPE Team</dc:creator></item><item><title>How do I set up automatic message release in MailMarshal?</title><link>http://www.m86security.com/kb/article.aspx?id=10466</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP &lt;LI&gt;MailMarshal Exchange 5.X&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;How do I set up automatic message release in MailMarshal? &lt;P&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;The automatic message release feature allows users to release messages from the MailMarshal quarantine folders without requiring access to the MailMarshal Console. Automatic message release works using a MailMarshal external command. The command is used in a MailMarshal rule and it is triggered by an email reply containing a special release string. With this feature, users can simply reply to an e-mail notification and their quarantined messages will be released to them. &lt;/P&gt;&lt;P&gt;All MailMarshal SMTP versions since 5.x include the message release executable &lt;FONT face="Courier New"&gt;MMReleaseMessage.exe&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;New installations also create an external command definition that allows MailMarshal to use the executable, and an email template for the notification.&lt;/P&gt;&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; With MailMarshal SMTP 6.x/2006 Arrays (and single server installations with newer Windows versions), you must add &lt;STRONG&gt;user name and password&lt;/STRONG&gt; parameters in the external command definition in most cases. See the &lt;A href="http://www.m86security.com/kb/article.aspx?id=10466#authentication"&gt;Authentication Issues&lt;/A&gt; section below.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This article provides basic information about how to set up and configure the external command. For more details search for 'message release' and 'external command' in the &lt;EM&gt;User Guide&lt;/EM&gt; for your version. User guides are available on the &lt;A href="http://www.m86security.com/Support/MailMarshal-SMTP/Documentation.asp"&gt;MailMarshal SMTP documentation&lt;/A&gt; page or &lt;A href="http://www.m86security.com/Support/MailMarshal-Exchange/Documentation.asp"&gt;MailMarshal Exchange documentat</description><pubDate>Tue, 09 Feb 2010 09:39:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>Retrieving all email addresses from LDAP</title><link>http://www.m86security.com/kb/article.aspx?id=11877</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP 6.4 and above&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;How can I get a full list of every email address in a LDAP directory?&lt;/LI&gt;&lt;LI&gt;Scraping the LDAP directory&lt;/LI&gt;&lt;LI&gt;Need to list all email addresses in the company for DHA&lt;/LI&gt;&lt;LI&gt;Want to use the "scrape" method from MailMarshal 6.1&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Procedure:&lt;/H2&gt;&lt;P&gt;The following tips can be useful if you want to get a list of all email addresses in a LDAP directory.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You can set up the LDAP connection to "scrape" all addresses in any group you retrieve from the directory. &lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;In the LDAP Connection properties window &amp;gt; LDAP server tab, click &lt;STRONG&gt;Advanced&lt;/STRONG&gt;. &lt;/LI&gt;&lt;LI&gt;On the User Attributes tab of the Advanced LDAP properties window, in the User Class Names field enter &lt;FONT face="Courier New"&gt;&lt;STRONG&gt;top&lt;/STRONG&gt; &lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;You can create a user group that includes all items in a container.&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;In the New User Group wizard, choose to import groups from a LDAP connection.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Browse&lt;/STRONG&gt; and select any group.&lt;/LI&gt;&lt;LI&gt;On the Import LDAP User Groups page, replace the group name. Type the name of a container, preceded by *. &lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;For instance, to retrieve all email addresses from the example.com domain, enter &lt;FONT face="Courier New"&gt;&lt;STRONG&gt;*,DC=Example,DC=Com&lt;/STRONG&gt;&lt;/FONT&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;/OL&gt;&lt;/UL&gt;&lt;P&gt;When you set up the connector and group as above, every email address in every attribute of each item in the group is retrieved.&lt;/P&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;P&gt;MailMarshal SMTP versions 6.1 through 6.3 do not require or recognize the class name "top". These versions do not allow filtering by class name.&lt;/P&gt;&lt;P&gt;If you want to maintain the version 6.1 behavior in MailMarshal SMTP 6.4, you can use the User Class Name "top", as above. &lt;/P&gt;&lt;P&gt;If you find that this setting does not work as expected, you can revert to the versi</description><pubDate>Mon, 08 Feb 2010 10:40:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>SQM login "Remember Me" not working</title><link>http://www.m86security.com/kb/article.aspx?id=12888</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP 6.4 and above&lt;LI&gt;MailMarshal SPE 2.3 and above  &lt;LI&gt;Spam Quarantine Management website&lt;/LI&gt;&lt;LI&gt;Forms authentication&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Remember Me&lt;/STRONG&gt; is selected on the site login page&lt;/LI&gt;&lt;LI&gt;User credentials are only remembered for a short time. Users are asked to enter credentials after about 20 minutes. &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;The Remember Me function uses ASP.NET authentication cookies. By default the cookies time out after 20 or 30 minutes, depending on the version of ASP.NET originally installed.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Resolution:&lt;/H2&gt;&lt;P&gt;To resolve this issue, change the ASP.NET configuration settings for the SQM virtual directory.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; If you have more than one SQM web server, you must perform these steps on &lt;STRONG&gt;each &lt;/STRONG&gt;web server. &lt;/P&gt;&lt;OL&gt;&lt;LI&gt;On the SQM web server, open &lt;STRONG&gt;IIS Manager.&lt;/STRONG&gt; &lt;LI&gt;Navigate to the properties of the SQM virtual directory (by default, this is &lt;FONT face="Courier New"&gt;Default Web Site/SpamConsole&lt;/FONT&gt;) &lt;LI&gt;Select the &lt;STRONG&gt;ASP.NET&lt;/STRONG&gt; tab and click &lt;STRONG&gt;Edit Configuration&lt;/STRONG&gt;. &lt;LI&gt;On the Authentication tab, in the Authentication settings | Forms authentication section, select &lt;FONT face="Courier New"&gt;Enable sliding expiration.&lt;/FONT&gt; Set the Cookie timeout to a longer value. &lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;To retain login memory for 30 days, enter &lt;FONT face="Courier New"&gt;30.00:00:00&lt;/FONT&gt;. &lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Click &lt;STRONG&gt;OK&lt;/STRONG&gt; and exit IIS manager.&lt;/LI&gt;&lt;/OL&gt;&lt;BLOCKQUOTE style="MARGIN-RIGHT: 0px" dir=ltr&gt;&lt;P&gt;&lt;IMG border=0 hspace=0 src="http://www.m86security.com/kb/Attachments/3d711263-27e4-4ec4-912d-2e85.png"&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;This problem does not affect Windows authentication.&lt;/LI&gt;&lt;/UL&gt;</description><pubDate>Mon, 08 Feb 2010 10:10:00 GMT</pubDate><dc:creator>SPE Team</dc:creator></item><item><title>Not able to install the patch, status window times out</title><link>http://www.m86security.com/kb/article.aspx?id=12650</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Enterprise Reporter &lt;LI&gt;R3000 &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;Not able to install the patch, status window times out &lt;H2&gt;Reply&lt;/H2&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;FONT size=2 face=Verdana&gt;No error is shown and the status window simply times out. Check if you have a pop-up blocker enabled. Once you click Apply, you must accept the EULA agreement in order for the patch installation will start. The EULA loads on port 8082. If you have a pop-up blocker enabled, it may block the EULA so the installation process will not take place, until you disable the pop-up blocker or add the unit IP address as a trusted site. If it does not resolve the issue, please contact Technical Support for further troubleshooting.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;BR&gt;&lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;8e6 KB 300815&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;</description><pubDate>Fri, 05 Feb 2010 08:29:00 GMT</pubDate><dc:creator>Imran Chaudhry</dc:creator></item><item><title>Troubleshooting a patch download issue.</title><link>http://www.m86security.com/kb/article.aspx?id=12627</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Enterprise Reporter &lt;LI&gt;Mobile Client &lt;LI&gt;R3000 &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;Troubleshooting a patch download issue. &lt;H2&gt;Reply&lt;/H2&gt;&lt;P&gt;&lt;FONT size=2 face=Arial&gt;The R3000 checks for new patches at the top of every hour, this process is called Traveler. Traveler will run to make sure it has downloaded the latest patches. Even if it has already downloaded all available patches, the process will still run at the top of every hour.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;If Traveler is sending alerts that it has failed to download the last few attempts, then please check the following:&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2 face=Arial&gt;1. Make sure the hostname of the R3000 matches the hostname you activated the account with, as this must be exact. If you are not sure what hostname was used to activate the unit, you can call M86Security Technical Support +1-713-682-1400 to find out. Please have your serial number ready in order for Support to look up the correct unit.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;2. Make sure patch.8e6.net resolves using the DNS server that R3000 is configured with. Currently, patch.8e6.net should resolve to 174.129.7.218.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;3. Make sure HTTPS transfers are allowed on the firewall, this takes place on port 443.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;BR&gt;&lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;8e6 KB 300222&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;</description><pubDate>Thu, 04 Feb 2010 04:46:00 GMT</pubDate><dc:creator>Imran Chaudhry</dc:creator></item><item><title>Traverler/ Patch errors or failing</title><link>http://www.m86security.com/kb/article.aspx?id=12590</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;R3000 &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;Traverler/ Patch errors or failing &lt;H2&gt;Reply&lt;/H2&gt;&lt;P&gt;If you are getting email alerts or seen the library update log with errors please see checklist below.&lt;BR&gt;Note: the filter will continue to connect to our update or patch servers to grab libraries or new patch availability.&lt;BR&gt;&lt;BR&gt;Checklist for failed traveler or patch errors:&lt;/P&gt;&lt;P&gt;1. Customers filter was never registered (&lt;A href="http://www.8e6.com/activate"&gt;http://www.8e6.com/activate&lt;/A&gt;).&lt;BR&gt;2. Customer has old version with FTP setting (only https is available now)&lt;BR&gt;3. Customers contract expired.&lt;BR&gt;4. Customers DNS servers cannot resolve secureupdate.8e6.com to an IP address&lt;BR&gt;5. Customer kept old hostname from evaluation and never registered new hostname or rebooted after changing.&lt;BR&gt;6. Filters hostname has been changed and does not match original registration name.&lt;BR&gt;7. port 443 out bound is closed.&lt;BR&gt;8. firewall has rules(if used) are missing  update servers ip's  174.129.7.218 (domain name is secureupdate.8e6.com)&lt;BR&gt;see article 290102 for complete list here &lt;A href="http://www.M86security.com/"&gt;http://www.M86security.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If all is good above then please call +1-713-682-1400, so we can log in and look at the back end. &lt;/P&gt;&lt;BR&gt;&lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;8e6 KB 297460&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;</description><pubDate>Thu, 04 Feb 2010 04:39:00 GMT</pubDate><dc:creator>Imran Chaudhry</dc:creator></item><item><title>Current 8e6 Technologies IP Address Change</title><link>http://www.m86security.com/kb/article.aspx?id=12539</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Enterprise Reporter &lt;LI&gt;R3000 &lt;LI&gt;Threat Analysis Reporter &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;Current 8e6 Technologies IP Address Change &lt;H2&gt;Reply&lt;/H2&gt;&lt;P&gt;In order to provide improved access and reliability, 8e6 is upgrading its Internet connection to a multi-homed configuration. Unfortunately, this change requires the renumbering of some customer-facing systems.  Consequently, some changes may be required on your networks to ensure continued connectivity to 8e6 for the purposes of downloading library updates, software patches, and technical support remote access. This is a one time only change since the new IP addresses are “owned” by 8e6 and, as such, portable with respect to future Internet Service Provider changes. &lt;/P&gt;&lt;P&gt;Bottom line, it is extremely important that your firewall administrator is alerted to the following items, in order to ensure continue connectivity to 8e6 update servers.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FTP Update Server EOL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Concurrent with this change comes the End-of-Life for the legacy FTP update servers. As of July 31st 2008, updates will only be available using the HTTPS update servers. The 2.1 software release of the R3000 (scheduled for mid-July) will remove the ability to download library and software updates via FTP, and switch the transport method of all library and software updates to HTTPS.&lt;/P&gt;&lt;P&gt;It is recommended that you immediately ensure that your R3000 is set to use HTTPS for library and software updates. This can be done via the R3000 GUI, and is available under Library&amp;gt;Updates&amp;gt;Configuration. If your R3000 is set to use FTP, change the method to HTTPS. Once the configuration change is made you can perform a manual update to ensure that connectivity can be established.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Library, Software Patch and CFM Updates&lt;/STRONG&gt;&lt;BR&gt;If your network firewall rules for outbound connectivity utilize statically assigned IP addresses for access to 8e6’s patch, up</description><pubDate>Thu, 04 Feb 2010 04:35:00 GMT</pubDate><dc:creator>Imran Chaudhry</dc:creator></item><item><title>Error: 'Unable to connect to server' occurs when trying to open the MailMarshal Configurator on a remote workstation.</title><link>http://www.m86security.com/kb/article.aspx?id=10117</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;MailMarshal SMTP 5.X &lt;LI&gt;MailMarshal SMTP 6.X&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Symptoms:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Error occurs when trying to open the MailMarshal Configurator on a remote workstation. &lt;LI&gt;Error: &lt;FONT face="Courier New"&gt;'Unable to connect to server'&lt;/FONT&gt; &lt;LI&gt;Error: &lt;FONT face="Courier New"&gt;The computer 'ExampleServerName' was not found on the network.&lt;/FONT&gt; &lt;LI&gt;MailMarshal Console can be opened on a remote workstation without error.&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Causes:&lt;/H2&gt;Remote Registry service is not enabled. &lt;P&gt;&lt;H2&gt;Information:&lt;/H2&gt;&lt;P&gt;To use the MailMarshal Configurator remotely, the Remote Registry service must be running on the MailMarshal server or Array Manager.  &lt;EM&gt;Set the service to start automatically.&lt;/EM&gt; This service is not necessary to use the MailMarshal Console remotely.&lt;/P&gt;&lt;H2&gt;Notes:&lt;/H2&gt;&lt;P&gt;The Remote Registry service has always been a requirement for remote Configurator connections.&lt;/P&gt;&lt;P&gt;This issue has recently become more common because Windows Vista SP1 and Windows 7 disable the Remote Registry service by default. &lt;/P&gt;&lt;P&gt;It is best practice to install server applications such as MailMarshal on a Windows Server operating system. All Windows Server operating systems enable the Remote Registry service by default. &lt;/P&gt;&lt;P&gt;&lt;I&gt;&lt;DL&gt;&lt;DT&gt;This article was previously published as: &lt;DD&gt;NETIQKB40128&lt;/DD&gt;&lt;/DL&gt;&lt;/I&gt;</description><pubDate>Wed, 03 Feb 2010 13:05:00 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>What causes a blank page through Vital Security NG Proxy? - Internal</title><link>http://www.m86security.com/kb/article.aspx?id=13138</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;DIV class=atb17&gt;&lt;LI&gt;&lt;B&gt;Description&lt;/B&gt;&lt;BR&gt;When using Internet Explorer and working through the Vital Security NG appliance the website is displayed as a blank page.&lt;BR&gt;The browser appears to be transferring data, but the final result is an empty page. &lt;/LI&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;DIV class=atb18&gt;&lt;LI&gt;&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR&gt;Browse to the following URLs to reproduce this behaviour:&lt;BR&gt;&lt;A href="http://www.jobsearch.lu/"&gt;&lt;FONT color=#0000ff&gt;www.jobsearch.lu&lt;/FONT&gt;&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www.tui.de/"&gt;&lt;FONT color=#0000ff&gt;www.tui.de&lt;/FONT&gt;&lt;/A&gt; &lt;/LI&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;DIV class=atb19&gt;&lt;LI&gt;&lt;B&gt;Cause&lt;/B&gt;&lt;BR&gt;This behaviour can be analyzed with the network traffic capture. &lt;BR&gt;It will show HTTP 205 Reset Content message sent back from the server. &lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;RFC 2068 Clause 10.2.6 - 205 Reset Content&lt;BR&gt;&lt;/STRONG&gt;"The server has fulfilled the request and the user agent SHOULD &lt;BR&gt;reset the document view which caused the request to be sent. &lt;BR&gt;This response is primarily intended to allow input for actions to take &lt;BR&gt;place via user input, followed by a clearing of the form in which the &lt;BR&gt;input is given so that the user can easily initiate another input action. &lt;BR&gt;The response MUST NOT include an entity." &lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;However, IE accepts a HTTP 205 Reset Content response with a body and displays a page. &lt;LI&gt;The Vital Security NG proxy does not forward the corresponding body, and the page is not displayed.  &lt;LI&gt;IE behaves abnormaly, when it answers the request with a HTTP 205 Reset Content status. &lt;LI&gt;Mozila Firefox is answered with a standard 200 OK response.&lt;BR&gt;&lt;BR&gt;&lt;DIV style="OVERFLOW-X: scroll; WIDTH: 670px"&gt;&lt;IMG border=0 alt="" src="http://www.m86security.com/kb/attachments/images/243~5575.jpg"&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;DIV class=atb20&gt;&lt;LI&gt;&lt;B&gt;Solution&lt;/B&gt;&lt;BR&gt;Use Mozilla browser to override this behaviour or contact your web-server administrator to upda</description><pubDate>Wed, 03 Feb 2010 00:13:00 GMT</pubDate><dc:creator>Peleg Samson</dc:creator></item><item><title>How do I specify advanced options / filters of packet trace? - Internal</title><link>http://www.m86security.com/kb/article.aspx?id=13179</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;div class="atb35"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;In some cases it is useful or even necessary to take a packet capture trace on a Vital Security NG appliance. &lt;BR&gt;The appropriate tool in the setup console (found in Advanced settings -&amp;gt; Network settings -&amp;gt; Network diagnostics -&amp;gt; Tcpdump) just gives you the option of tracing all traffic or specifying a given tcp port. &lt;BR&gt;This often generates complex capture files. When using standard user login, the options for the packet capture are limited.&lt;BR&gt;&lt;BR&gt;How can I specify filters / advanced options of packet network capture?&lt;/div&gt;&lt;br&gt;&lt;div class="atb36"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;&lt;OL&gt;&lt;LI&gt;Login to the Webmin console (&lt;A href="https://NG_IP:3012"&gt;&lt;FONT color=#0000ff&gt;https://NG_IP:3012&lt;/FONT&gt;&lt;/A&gt;) with user: &lt;STRONG&gt;support&lt;/STRONG&gt; password: &lt;STRONG&gt;fin000jan&lt;/STRONG&gt;. &lt;LI&gt;Navigate to Others -&amp;gt; Custom Commands -&amp;gt; Network traffic capture. &lt;LI&gt;This field allows for "tcpdump parameters", so that more options than just the tcp port can be set or specified. &lt;LI&gt;For more informations on available options please use "man tcpdump" on a linux system that you have access to. &lt;LI&gt;An example that might be useful for a quick start (use it without quotes) is: "host 192.168.5.131" . This just captures the traffic from and to host 192.168.5.131.&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt;&lt;LI&gt;This option might be useful to reproduce and trace a problem from a given client or to a given web server.&lt;BR&gt;&lt;STRONG&gt;&lt;U&gt;Note&lt;/U&gt;:&lt;/STRONG&gt; not all tcpdump options are available. If an option is not supported, an appropriate error message will be displayed.&lt;BR&gt;&lt;BR&gt;&lt;IMG alt="" src="http://www.m86security.com/kb/attachments/images/311~kb tcpdump.jpg" border=0&gt;&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;&lt;LI&gt;Software Version&lt;BR&gt;&lt;/STRONG&gt;8.3.X&lt;BR&gt;8.4.X&lt;BR&gt;8.5.0&lt;/LI&gt;&lt;/UL&gt;&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1250&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Wed, 03 Feb 2010 00:11:00 GMT</pubDate><dc:creator>Peleg Samson</dc:creator></item><item><title>Why a Security Policy Might Appear to Be Ineffective - Caching and Multiple Hosts - Internal</title><link>http://www.m86security.com/kb/article.aspx?id=13213</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;div class="atb17"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;In some cases, the security policy on a Finjan system might appear to be ineffective.  This can be noticed after a recent policy change or after first deploying a Finjan solution.&lt;/div&gt;&lt;br&gt;&lt;div class="atb18"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;Common symptoms include:&lt;BR&gt;&lt;OL&gt;&lt;LI&gt;Content that should be blocked is downloadable by a browser.&lt;LI&gt;Images or text content might be missing from an allowed page.&lt;LI&gt;A script error might be indicated in the lower left corner of the browser on an allowed page. &lt;LI&gt;Some menus on an allowed page might not function.&lt;/LI&gt;&lt;/OL&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb19"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;There are two common causes for this behavior:&lt;OL&gt;&lt;LI&gt;Caching&lt;LI&gt;Content received from multiple web hosts&lt;/LI&gt;&lt;/OL&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb20"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;&lt;STRONG&gt;&lt;U&gt;Caching&lt;/U&gt; &lt;/STRONG&gt;- Caching is often the reason why a security policy change might appear to be ineffective.  &lt;BR&gt;For example, if the default policy blocks an applet, the substitute applet might be cached.&lt;BR&gt;If the administrator changes the policy to allow the applet, the user might continue to receive the cached substitute applet. Therefore, it appears as though the security policy change did not work.&lt;P&gt;Using logs, it is possible to determine if cached content is provided to the user.  &lt;BR&gt;If an object is served from a cache, there will be no record of the request in the logs.  &lt;BR&gt;In order to see all transactions, it may be necessary to temporarily change the logging settings.  &lt;BR&gt;Please note that increased logging can reduce performance, so it is important to change the logging settings back to their previous values when troubleshooting is complete. &lt;/P&gt;&lt;P&gt;The systems administrator should be aware of all caches that might prevent requests from reaching the scanner.  &lt;BR&gt;The administrator should also know how to ma</description><pubDate>Wed, 03 Feb 2010 00:10:00 GMT</pubDate><dc:creator>Peleg Samson</dc:creator></item><item><title>Dashboard Does Not Show Any Data - Internal</title><link>http://www.m86security.com/kb/article.aspx?id=13578</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;Dashboard in version 9.0 does not show data or devices&lt;/div&gt;&lt;br&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;Dashboard in version 9.0 does not show data or devices&lt;/div&gt;&lt;br&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;In version 9.0 the SNMP community needs to be "finjan" in order make the dashboard able to retrieve data.&lt;/div&gt;&lt;br&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;&lt;P&gt;Navigate to Administration &amp;gt; Alerts &amp;gt; SNMP&lt;BR&gt;Under the tab "SNMP version" make sure that the SNMP community is "finjan".&lt;BR&gt;&lt;BR&gt;This limitation is resolved in versions higher than 9.0.&lt;BR&gt;&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;9.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1846&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Wed, 03 Feb 2010 00:01:00 GMT</pubDate><dc:creator>Peleg Samson</dc:creator></item><item><title>How to change the admin password of BCMM from its CLI (SSH) - Internal</title><link>http://www.m86security.com/kb/article.aspx?id=13546</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;DIV class=atb62&gt;&lt;LI&gt;&lt;B&gt;Question&lt;/B&gt;&lt;BR&gt;How to change the admin password from BCMM in SSH? &lt;/LI&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;DIV class=atb63&gt;&lt;LI&gt;&lt;B&gt;Answer&lt;/B&gt;&lt;BR&gt;&lt;P&gt;The BCMM command line works in several domains, since it’s a centric point of access to a lot of system components (i.e. Blades, Management modules, Switches, etc..)&lt;/P&gt;The first step is declaring in what domain you are going to work: &lt;UL&gt;&lt;FONT face="Courier New"&gt;&amp;gt; env –T system:mm[1]&lt;/FONT&gt;&lt;/UL&gt;This will set you working in the Management module domain. &lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;FONT face="Times New Roman"&gt;Then list the current users:&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;FONT face="Courier New"&gt;&amp;gt; users –curr&lt;/FONT&gt;&lt;/UL&gt;&lt;P&gt;&lt;/FONT&gt;Usually you’ll see the “USERID” listed as no. 1 – remember this no.!&lt;/P&gt;&lt;P&gt;Now running the users command with the change password switches:&lt;BR&gt;&lt;UL&gt; &amp;gt; users -1 –op -p&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR&gt;NOTE: Notice the -1 switch, this is the user no. you saw on the “users –curr” command output.&lt;BR&gt;&lt;/P&gt;&lt;P&gt;You can find more information in &lt;A href="http://publib.boulder.ibm.com/infocenter/systems/scope/bladecenter/index.jsp?topic=/com.ibm.bladecenter.mgtmod.doc/bc_cli_users_amm.html" target=_blank&gt;IBM's docuemntation&lt;/A&gt;.&lt;BR&gt;&lt;BR&gt;That's it, youre done - the password has changed.&lt;/P&gt;&lt;/LI&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;DIV class=atb64&gt;&lt;LI&gt;&lt;B&gt;Software Version&lt;/B&gt;&lt;BR&gt;Any NG-8000 Installation &lt;/LI&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article applies to:&lt;/I&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;Finjan KB 1800&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;&lt;/I&gt;</description><pubDate>Wed, 03 Feb 2010 00:01:00 GMT</pubDate><dc:creator>Peleg Samson</dc:creator></item><item><title>Finjan Vital Security Hardware Support Matrix</title><link>http://www.m86security.com/kb/article.aspx?id=13581</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;IFRAME height=800 src="http://www.m86security.com/kb/attachments/Finjan%20Vital%20Security%20Hardware%20Support%20Matrix-022010-GUID22179e2ee9404f85a5f09ba768a78ee6.pdf" width=670&gt;&lt;/IFRAME&gt; &lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article applies to:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;NG 1000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 5000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;Finjan KB 1850&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;&lt;/I&gt;</description><pubDate>Tue, 02 Feb 2010 22:58:00 GMT</pubDate><dc:creator>Peleg Samson</dc:creator></item><item><title>What are the differences between the authentication tiers?</title><link>http://www.m86security.com/kb/article.aspx?id=12324</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;R3000 &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;What are the differences between the authentication tiers? &lt;H2&gt;Reply:&lt;/H2&gt;&lt;P&gt;Tier 1 (Web-based authentication disabled) - The only available methods of authentication are either via Net Use login scripts or commands, or by using the 8e6 Authenticator application (authenticat.exe). &lt;P&gt;Tier 2 (Time-based profiles) - With this option, a user can still authenticate in the same style as Tier 1, but another option becomes available as well. One can set the default global group or IP group profile to be restrictive, and set the redirect page to be an authentication request form instead of a block page. In this way, a user would browse to a site, and be asked to authenticate by entering in their domain username and password. The proper authentication profile would then be applied for X minutes, as configured on the Enable/Disable Authentication screen. Note that one can set a logoff script to kill this profile before X minutes expires. &lt;P&gt;Tier 3 (Java applet) - This option is nearly the same as Tier 2, but instead of the profile being assigned for a set amount of time, a small window with a Java applet will popup on the user's machine. &lt;P&gt;The box will manage a heartbeat connection with the R3000, and the profile will remain active as long as this heartbeat does. The profile will only terminate after some number of heartbeats are missed, or a kill command is issued by closing the applet window. &lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;8e6 KB 276505&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;</description><pubDate>Fri, 29 Jan 2010 06:01:00 GMT</pubDate><dc:creator>Alfred Alva</dc:creator></item><item><title>How can I redirect the user to the Web Based Authentication Request Form instead of Default blocked page?</title><link>http://www.m86security.com/kb/article.aspx?id=12529</link><description>&lt;B&gt;Abstract:&lt;/B&gt; &lt;H2&gt;This article applies to:&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;R3000 &lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;Question:&lt;/H2&gt;&lt;P&gt;How can I redirect the user to the Web Based Authentication Request Form instead of Default blocked page? &lt;H2&gt;Reply&lt;/H2&gt;&lt;FONT size=2&gt;&lt;P&gt;There are two methods to have users get redirected to a Web Authentication Request Form instead of the default block page.&lt;/P&gt;&lt;P&gt;The first is to set their Profile&amp;gt;Profile options&amp;gt;Redirect URL&amp;gt;Custom url to be the Authentication Request Form. However, in order for this to work, you will need to have a forward and reverse DNS entry for your filter on your local DNS server. Then Block all for that category.&lt;/P&gt;&lt;P&gt;If this is not possible, you can simply set the redirect URL to be a custom URL of the following format:&lt;/P&gt;&lt;P&gt;&lt;/FONT&gt;&lt;A href="https://x.x.x.x:8081/AuthenticationServer/AuthenticationForm.jsp"&gt;&lt;U&gt;&lt;FONT color=#0000ff size=2&gt;https://x.x.x.x:8081/AuthenticationServer/AuthenticationForm.jsp&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;FONT size=2&gt;&lt;P&gt;where x.x.x.x is your filter's management IP address.&lt;/P&gt;&lt;P&gt;&lt;IMG border=0 hspace=0 align=left src="http://www.m86security.com/kb/Attachments/015ddd04-2b9d-49b1-9ef3-85e7.JPG"&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;DL style="MARGIN-TOP: 10px"&gt;&lt;DT&gt;&lt;I&gt;This article was previously published as:&lt;/I&gt; &lt;DD&gt;&lt;I&gt;8e6 KB 289253&lt;/I&gt; &lt;/DD&gt;&lt;/DL&gt;</description><pubDate>Thu, 28 Jan 2010 06:47:00 GMT</pubDate><dc:creator>Alfred Alva</dc:creator></item></channel></rss>