Views:

Configure the settings that apply to all Internet Access gateways.

Setting
Description
Safe Search Settings
Enforce the use of Restricted Mode when users use YouTube and a strict SafeSearch setting when users use Google, Yahoo!, or Microsoft Bing.
Set up NTLM v2 or Kerberos authentication to transparently identify your on-premises Active Directory users using their Windows logon credentials. If both services are enabled, NTLM v2 handles authentication if the Kerberos service fails.
After users sign in to their Windows operating system, Internet Access automatically authenticates the users with your on-premises Active Directory server. Users do not need to sign in again on the Secure Access Module deployed to their endpoints or on a browser-based authentication page if they do not use the Secure Access Module.
Note
Note
This feature is not available in all regions.
Forward selected outbound web traffic through provisioned static IP addresses originating from a chosen location.
Disable Access Protection
Generate a temporary access key that allows a user to bypass Internet Access protection and access the internet directly, without going through the Internet Access Gateway. Use this option, for example, when troubleshooting a connectivity issue that may be caused by an Internet Access policy.
  1. Click the calendar icon to select an expiration time or date, provide a description, and click Generate Access Key.
  2. Provide the access key to the user who needs to bypass Internet Access protection.
Note
Note
You do not need to generate a separate key for each user. Access keys created with the same expiration time and date are identical, so you can share one key with multiple users who need to bypass protection during the same window.
To revoke and delete an access key, click the icon (delete_connector=3fc07446-32b8-4304-a62e-6c9ecc08d84f.jpg). Revoking and deleting an access key removes it from Trend Vision One. Any active endpoints using the token automatically re-enable the Internet Access service within a few minutes.
Configuration Backup and Restoration
Create backups of your Internet Access service configurations and restore created backups as necessary. Data backed up includes:
  • Internet Access rules
  • Secure access resources in use by Internet Access rules
  • PAC files
  • HTTPS inspection rules and exceptions
  • Allow and deny list configurations
  • Safe search settings
  • Internet Access-related custom notification settings
You may save up to 10 configuration backups. During the backup creation and restoration process, you may not make any changes to configurations, settings, or resources.
The X-Forwarded-For header allows you to insert your own public IP address to the header for inspected HTTP/HTTPS traffic.
Allow Internet Access or AI Secure Access to record the part of the content (up to 100 bytes) that matches either the DLP profile or the AI content inspection profile, or that is detected as a prompt injection.
Note
Note
You can have the matching content either masked or unmasked.
On-premises gateways support integration with third-party Internet Content Adaptation Protocol (ICAP) servers. The ZTSA on-premises gateway acts as an ICAP client, forwarding outbound traffic to ICAP servers via REQMOD for DLP scanning and taking action based on your Internet Access Rules.