Workplace Secure Internet Access allows your employees to securely connect to public websites and third-party software-as-a-service (SaaS) applications over the internet from anywhere and on any device.
With Workplace Secure Internet Access, employees at office locations can safely connect to SaaS apps, click on web links, and open email attachments without the fear of infecting their devices. Unlike traditional solutions that require integrating separate point products, Exium Workplace Secure Internet Access combines the best of web security, Firewall, intrusion detection and prevention services, and DNS security offerings into a single, easy-to-use, and cost-effective service.
Workplace Secure Internet Access requires deployment of Exium's Cyber Gateway at the office location as shown in the Figure below.
This document describes high level steps to configure and verify Workplace Secure Internet Access features on Multi Interface Cyber Gateway. Please refer to Secured Internet Access user guide for detailed instructions on configuring Secured Internet access service. Please Refer to CGW deployment guide for instructions to deploy Cyber Gateway.
You would need to deploy Cyber Gateways (CGW) on each site to provide Workplace Secure Internet Access. You can create as many CGWs as you wish in the centralized admin console and follow the instructions for Multiple interface CGW deployment on each site.
To configure the Workplace Secure Internet Access security policies, follow the steps below:
Create web category rules as shown below
By default, rules created at workspace level will be applicable to users who are connected via the Cyber Gateway. No additional configuration or changes are required at CGW level to support this.
Group level policies can be created and can be enforced to the users connecting via the Cyber gateway.
Select CGW to which group level policies should be applied and select group name from User groups as shown in screenshot and click on update. Whatever policies defined for the group ( In this example it is “developers”) will be enforced on gateway users.