How to configure secure web gateway policies
6:31 · Published April 12, 2023
Watch the dope.security policy walkthrough covering web categories, group exceptions, custom categories, bypass settings, and cloud application controls.
This recording shows the product as demonstrated at the time. The current interface and available features may differ.
In this demo
- 00:00 Policy walkthrough
- 00:28 The base policy
- 01:26 Block web categories
- 02:02 Add group exceptions
- 03:06 Create custom categories
- 03:38 Configure bypass settings
- 04:38 Cloud application controls
- 05:57 Policy recap
Read the full transcript
00:00Hi everyone, welcome back to our pre-check series. My name is Ashley and I'm a brand and product manager here at job security.
00:09To recap the last video with Amar together, you've walked through signing up instantly from our website. You've downloaded the endpoint
00:15onto your device and you've imported your users. If you haven't watched the first video in this series be sure
00:21to pause this one and watch that video first. But now we are ready for the exciting part of the series configuring basic
00:28policies that we can apply across your organization. Let's start by clicking the policies tab in the navigation where we can dive into our base policy.
00:40We have over 80 predefined URL categories that we've already determined that the vast majority of you might want to block.
00:50Let's scroll down to illegal and take a look at the subcategories already being blocked. As you can see piracy and
00:57plagiarism is blocked from the get-go. Which you can test out by looking up the pirate bay.org. in finding our default block page
01:12The base policy is applied to your entire organization. So any changes you make here will be applied everywhere. You can go in and customize this to your own needs.
01:26For example for productivity reasons, you might want to go ahead and block social media which we have set to as allowed.
01:36It's an easy. Click to just go from a loud block. and then hit save your policy will automatically update and we can
01:46test this out by visiting Instagram. And seeing that social media is blocked. But what if your marketing team needs access to social media for research?
02:02Here's what we want to add an exception. Let's create one specifically for this group on this right hand panel. You're going to find the plus button
02:11insert typing your group name. For my example today. I'm going to type in marketing. I'm going to hit allow.
02:25And then I'm going to hit save. and now if you were to go back to Instagram. You'll see that anyone applied to the Marketing Group now has
02:40access to social media. And let's scroll up to see how this impacts our policy. You'll find that in social media. We see that we have an
02:54exceptionist tag here. And under society and lifestyle you'll find it to say mixed because we have both allow and block.
03:06And while we have over 80 comprehensive categories as an admin, you can still create your own custom category. start typing in a custom category name such
03:16as Global block list you're going to set your restriction level. I'm going to put this at blocked. And you can see that you'll have the ability to add exceptions and
03:29add URL filtering. If you already have these URLs created you can also import them into the SWG by creating by dropping in a CSV
03:38file. The next feature we're going to look at is the bypass list where we'll be able to tackle both domain and application
03:51bypass. For domains, there are some websites that may break when proxied that you still want your employees to be able to use.
04:01And for applications likewise, there are some common apps that break when proxies such as zoo or Spotify. The dope SWG has predefined lists and
04:11app domain bypasses that you can continue to add to just as easily. To start typing in a domain or application name here and hit
04:19enter. The OS is going to be automatically set based off of the extension you use. As Windows uses the dot XCX extension and
04:38Mac does not it will automatically filter through. And I think we've saved the best for last Cloud up control.
04:53This is your initial layer of protection which reduces the viscup data exfiltration. Out of the box. We support Microsoft. O365 Salesforce
05:01Dropbox slack Google box and Cisco WebEx Since I have a Google account, let's walk through enabling Google control. Under email domain. I'm going to type in my current
05:18domain. sandroidab.com and hit enter now all of my employees will only be able to access Google accounts by signing into this domain.
05:33We can also specify consumer login. Which either allows or blocks personal email? By toggling this off you restrict any login from
05:43basic Gmail accounts, which reduces this data exfiltration piece and keeps all access work only. And with that that's a wrap for the second video of the
05:57series. To do a quick recap. We explored the base policy and learn how to customize it. We learned how to create exceptions for different users
06:06and groups. We explored the URL and application bypass list. And we dove into Cloud app controls to reduce the risk
06:16of data exfiltration. In the next video we'll dive into custom web content policies and how to manage your organizations different needs so
06:24that you're not stuck with a one size fits all solution. See you there.
Keep exploring
We made it dope.

