SurfControl Web Filter for Cisco Content Engine 5.0.0.236                       April 2005

Welcome

New Features in Version 5.0

License Information

Upgrading
Customer Issues Fixed
Known Issues

Welcome


Welcome to version 5.0 of SurfControl Web Filter for Cisco Content Engine and SurfControl's Virtual Control Agent™ (VCA).
 

SurfControl Web Filter offers the most advanced filtering technology available for the corporate environment, easing the challenge of managing Internet usage in the workplace.  It can help you increase employee productivity, optimize network bandwidth, increase security and limit legal liability that occurs when corporations provide Internet access to their employees. Protect your employees and your company by promoting intelligent Internet use.

SurfControl Web Filter offers a complete set of tools for monitoring, filtering and reporting on Internet Access:

 

New Features in Version 5.0


SurfControl Report Central

A new web-based reporting engine, making it easier for users throughout the organization to run and schedule the reports they need. SurfControl Report Central also brings faster reporting and a new report showing how much time a specific user spent at each category.

New URL Database Categories

7 New categories have been added since version 4.5. These include Spyware, Downloads, Illegal Drugs, Phishing & Fraud and Business.

Active Directory Support

Browse your Active Directory tree from the SurfControl Rules Administrator. You can select users and groups from Active Directory for inclusion in your access rules. SurfControl Web Filter continues to support NT Domain and Novell NDS/eDirectory environments.

VLAN Support

Filtering, monitoring and reporting in VLAN environments.

Reduced Data Storage

The option to reduce the amount of information logged and stored, but still capture the relevant activity that you will want to include in reports.

 

Single Management Console

View, monitor and manage multiple SurfControl servers from a single location.

Faster and more resilient Data Handling

The way logged data is written to your MSDE or SQL database has been re-designed to vastly improve performance and increase resilience to database problems.

 

Track User access by Workstation

Identify if a user accesses the web from different workstations.

 

Continuous VCA processing

The VCA will now run as a service, continually checking for new, uncategorized sites. In previous releases the VCA was a scheduled task. This new design will improve the turnaround time for the VCA categorization of a site that has never been seen before.


Processing of suspected corrupt flat files:

 

During a flat file update, any invalid files found will be quarantined in the following created folder:

 

Program Files\SurfControl\Web Filter\tmp\quarantine

 

A new command line tool – treatquarantined.exe can then be run which checks these files line by line to see if they correspond to the correct format. Any corrupt lines are left in the original file with clean lines written to a new file in the tmp directory and the corrupt file then deleted from the quarantined folder.

 

SurfControl strongly recommends that  you use the Scheduler to run the treatquarantined.exe command on a daily basis. For more information see Knowledge Base Article 1611 at:

 

http://kb.surfcontrol.com/display/1/articleDirect/index.asp?aid=1611&r=0.7167627



License Information


The SurfControl Web Filter product will run as an evaluation version for 30 days. During the evaluation period, you can schedule and download updates to the URL Category List, so that you obtain the latest version for testing.

The VCA product will run as an evaluation version until serialized, but categorization work performed during the evaluation period is not saved.


Upgrading

For complete installation and configuration information, please see the SurfControl Web Filter Installation and Configuration Guide. This is available as an Adobe Acrobat™ (PDF) document from http://www.surfcontrol.com/.


Customer Reported Issues Fixed In This Release

Issue Number

Description

13905

ICAP service crash

14680

NetBIOS is selected in the Advance option following an upgrade from version 4.5 to version 5.0.

 

 

Known Issues

 

Issue Number

Description

4729

VCA results are not correctly updated in Monitor.

13010

VCA categorizations incorrect when "Block Until Categorized" option is switched on.
VCA categorizations are incorrect when "Block Until Categorized" option is switched on. To avoid both these situations you should set the VCA machine's subnet to be unmonitored.
For 4729 ISA and MS Proxy Server platforms, you should create a new admin user for the VCA machine and then set that user to unmonitored.
13010 is only an issue for SurfControl Web Filter for Windows.

11045

Installing EUM onto local 2003 domain controller
Customer is trying to install EUM using the Automatic Enterprise User Monitoring Installation utility and reports getting the error: "Failed to restart %s. Error %s".

This is an unlikely scenario but if the customer happens to install the SurfControl Web Filter product onto a Domain Controller (or Active Directory server) and then install EUM automatically onto itself - when it asks whether to reboot the machine now - if the customer selects "yes" - the error will be generated as it is in conflict with the currently running EUM install utility.
The error will not cause a problem. However, the user would need to manually reboot the machine. To prevent this error, simply advise the customer to select NO when asked whether to reboot the Domain Controller and have them do that manually.

11072

Choosing Windows authentication in a WORKGROUP fails to control the SWF service.
If SWF is installed in a workgroup as opposed to a domain and Windows authentication is chosen, setting the account for the service to run as 'This Account' does not get set in the Services applet. For instance, say the username is 'administrator' and the password 'abc123', these details do not get set. This culminates in a 997 error at the end of the installation because the SWF service can't be controlled with the account credentials supplied. The workaround to this is to manually change the logon details for the SWF Service in the Services applet.

11534

Need SQL Client Tools in order to create a database on a named instance of SQL Server.
Need SQL Client Tools in order to create a database on a named instance of SQL Server.

To create a database on a named instance of SQL Server using the SurfControl Create MSDE/SQL Server Database wizard you must have SQL Client Tools installed on your machine otherwise a series of errors are generated.

11839

When changing Spider Settings new folder is not used until application is closed and reopened.
When changing the Spider Settings file location in the Settings tab of the VCA application and applying the changes, this new location is not used until the application is closed and reopened.

12922

Network Groups Update fails under NetWare scenario.

The following situation causes a problem:

The user(s) no longer exist(s) on the domain controller at the time a scheduled Network Group Update event was run AND their last connection was later than that configured in the dialog for automatically removing users after a given period of inactivity.

 

Under NT username handling, the user(s) is/are removed. However, under Netware handling, the user(s) is/are not removed and neither are their groups updated. The workaround to this is to manually delete the user(s) once you know that they should no longer be present.

13482

Sample monitored data contains irrelevant information.
When creating a new database using the Create SQL Server dialog, if the user selects to populate the database with sample monitor data, the data will include irrelevant information to the Juniper product. The site and user detail will contain bandwidth and duration information, and the SMTP mail user is still specified with 26 hits, even though there is no information in the user activity detail.

N/A

Recording User Level share access.

If Windows 95/98 machines on the network are configured for User Level Share, when anyone goes to open a file from one of those machines, the domain controller records that the remote user logged onto the Windows 95/98 machine. This results in the browser activity from the Windows 95/98 machine being recorded under the incorrect user name. Windows NT domain controllers demonstrate the same behavior.

N/A

Remote Administrator with NDS.

When installing a Remote Administrator, users will be presented with the dialogs to set-up username support as in the Complete Product. The information from these dialogs is necessary to browse and display data at the user specified Context in the NDS Tree. The specified NDS Context should be the same as the one used in the Complete Product, but the username and password information can be different. If a different username is specified, this user should have the same rights to the NDS Context as the user specified in the Complete Product. In addition make sure you choose the same options for username monitoring in all installations.

N/A

NetWare EUM does not work with long filenames.

The NetWare NLM for Username support only supports 8.3 DOS directory formats; therefore, please copy the NLM into a 8.3 DOS directory.

 

*** END OF FILE ***