How to allow access to Gmail while blocking the URL chat category and also block the ability to use the chat functionality while logged in to Gmail.

book

Article ID: 178003

calendar_today

Updated On:

Products

Web Gateway

Issue/Introduction

You would like to allow users to access Gmail but block access to the URL chat category in SWG and also block the ability to use the chat functionality while logged in to Gmail.

Resolution

In order to increase security,  HTTPS is enabled by default to access Gmail (https://mail.google.com). The SSL-encrypted login also means that URLs accessed via this tunnel are hidden to SWG unless the HTTP/S proxy feature is used. The proxy feature is available on SWG 5.0.0.x or later.

To block Google Talk (Gtalk) but still enable Google Mail (Gmail) several steps need to be completed:

  1. Make sure SWG has the HTTP/S proxy feature enabled and that the browsers accessing the web through this proxy.
  2. Make sure SWG has been licensed for Content Filter.
  3. Check which policy will be used to implement this or create a new one and make sure the client machines will match this policy when accessing the target URLs.
  4. Make sure that Gmail under Application Control Categories is set to monitor or allow
  5. Create a blacklist entry for the IP address that results of the command: nslookup talk.google.com
  6. Configure the policy to block Chat under Content Filtering categories.
  7. Within the same policy create the following exceptions:
    1. chatenabled.mail.google.com set to block
    2. mail.google.com set to monitor
    3. ssl.gstatic.com set to block
    4. talk.google.com set to block
    5. www.gmail.com set to monitor
  8. Open the browser and access https://mail.google.com. The site should be accessible and the Chat window should display the following message: "Unable to reach Gmail. Please check your internet connection or company's network settings".