Applies To:
Show VersionsBIG-IP APM
- 13.0.1, 13.0.0
About initial configuration steps for SWG
On a BIG-IP® system with an SWG subscription, the first thing you must do is download the URL database. After that, if you want to use transparent user identification, you should install one of the Secure Web Gateway user identification agents: F5 DC Agent or F5 Logon Agent.
Overview: Downloading and updating the URL database for SWG
On a system where URL database download is available, you must complete the download before you start to configure per-request policies to categorize and filter URLs. You can download the URL database to the BIG-IP system or to an upstream proxy.
For SWG to best protect your network from new threats, schedule regular database downloads to update the existing URL categories with new URLs. Without these updates, SWG uses obsolete security intelligence and as a result, protection of your networks is less effective.
Task summary
Configuring an upstream proxy for the BIG-IP system
- On the Main tab, select
- In the Name field, type a name for the proxy server.
- In the IP Address field, type the IP address for the proxy server.
- In the Port field, type the port number for the proxy server.
- In the User Name and Passwordfields, type credentials for an account on the proxy server if needed.
- Click Save.
Downloading the URL database
- DNS for the BIG-IP device in the System area of the product.
- A default route in the Network area of the product.
Looking up a URL category in the master database
Configuring logging for the URL database
Viewing a URL database report
Secure Web Gateway database download log messages
When you deploy Secure Web Gateway (SWG), the database downloads output messages to the log destinations specified in the default-log-setting. This table lists messages that are available only when you enable debug.
Debug message | Description |
---|---|
Transfer Status 247 | The file is transferred successfully to the BIG-IP® system. If you see a Transfer Status other than 247, it might indicate an error. |
RTU Type | The RTU Type is always 1. If you see an RTU Type other than 1, it might indicate an error. |
Expiration Date | The BIG-IP system does not use the expiration date in this message. Instead, the BIG-IP system enforces the SWG license and the database download works accordingly. |