Bypass Content Security Scanning by overriding Content Security Policy
search cancel

Bypass Content Security Scanning by overriding Content Security Policy

book

Article ID: 388836

calendar_today

Updated On:

Products

ISG Proxy ProxySG Software - SGOS

Issue/Introduction

Starting in SGOS 7.x, you can enable a built-in Content Security Policy layer. Refer to the "Using Policy Services" chapter in the SGOS Administration Guide and the ProxySG Security Best Practices document. Details are in the KB 174669

The KB describes steps to bypass predefined Content Security Policies on the Edge Security Web Gateway (ProxySG) for specific destination URL.

Below is the Content Policy layer with predefined policy options:

:  

Resolution

To override content security policy for specific destination use following steps:

1.  Under VPM, add a "Web Content Layer".

2. Right click under newly created rule Action section, and click on "Set".

3. Click Add a new object and search for "Set Content Security Scanning" action.

 

4. Select  "Exempt From Content Security" option and click "Apply".

5. Modify destination object according to your business needs and click Apply policy button.

 

Additional Information

Note:  Clear the object cache on the proxy using cli command "clear-cache object-cache" if the content is scanned/blocked after applying policy.