cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

Safe Search Enforcer with MWG as ICAP Server

Jump to solution

Hi all.

I'm using MWG 7.2 as ICAP Server and SQUID as ICAP Client.

I enabled rule Safe Search Enforcer, but I can change Safe Search filter to "no filter" (Google Search) in my lab.

Explicit Mode Proxy it works.

Anybody can help me?

Thanks!

1 Solution

Accepted Solutions

Re: Safe Search Enforcer with MWG as ICAP Server

Jump to solution

MWGs ICAP server component did not detect that the SSE changed the URL and sent back the original one. So SafeSearch was effectively not enforced. This has been fixed in 7.3 and 7.2.0.2.

The Bugzilla discussion tells the following workaround: "As a workaround the customer can add an arbitrary header in the request cycle."

Workaround.png

Message was edited by: fschulte on 7/10/12 3:38:08 AM CDT

View solution in original post

4 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 5

Re: Safe Search Enforcer with MWG as ICAP Server

Jump to solution

Hi Lucas,

I would get connection traces from a working scenario (direct proxy), and from a non-working scenario (as ICAP server). Then submit this to support, connection traces can be gathered under Configuration > Troubleshooting, then you will need to specify the client IP, and check both of the boxes for connection tracing.

Turn connection tracing off immediatley after you reproduced the issue. They can be collected from the CLI or under Troubleshooting > Connection tracing.

Connection tracing will allow us to see what is different. SafeSearch enforcer should work if MWG is an ICAP server.

Hope this helps,

Jon

Highlighted

Re: Safe Search Enforcer with MWG as ICAP Server

Jump to solution

Keep in mind that SafeSearch is used in the REQMOD cycle only.

It modifies the request before it goes out to google.

If you are using Squid in RESPMOD, it will have no effect.

Highlighted

Re: Safe Search Enforcer with MWG as ICAP Server

Jump to solution

Hi all

I opened a case to support. I sent TCP Dump and connection traces to support.

We are using MWG as ICAP Server with REQMOD and RESPMOD.

I will post results here.

Thanks!

Lucas

Re: Safe Search Enforcer with MWG as ICAP Server

Jump to solution

MWGs ICAP server component did not detect that the SSE changed the URL and sent back the original one. So SafeSearch was effectively not enforced. This has been fixed in 7.3 and 7.2.0.2.

The Bugzilla discussion tells the following workaround: "As a workaround the customer can add an arbitrary header in the request cycle."

Workaround.png

Message was edited by: fschulte on 7/10/12 3:38:08 AM CDT

View solution in original post

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community