<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
  <head runat="server">
    <!-- PageID 382 - published by RedDot 7.5 - 7.5.1.69 - 22111 -->
    <META name="PublicArticle" content="True" />
    <META http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <META name="keywords" />
    <META name="summary" />
    <META name="product" content="fp_web,fp_filter" />
    <META name="version" content="v85" />
    <META name="book" content="Administrator Help for Forcepoint Web Security" />
    <title>Configure user access to the hybrid service</title>
    <!--Loading the 2016 fonts.-->
    <script type="text/javascript" src="//fast.fonts.net/jsapi/c504d579-e135-4f75-8335-4906f6c6ce67.js"></script>
    <!--Library content styles.-->
    <link rel="StyleSheet" href="https://help.forcepoint.com/docs/ni/assets/css/help2016.css" type="text/css" media="all" />
    <!--2016 font support -->
    <link type="text/css" rel="stylesheet" href="//fast.fonts.net/cssapi/c504d579-e135-4f75-8335-4906f6c6ce67.css" />
  </head>
  <body>
    <!--googleoff: all-->
    <a href="https://www.forcepoint.com">
      <img class="logo" alt="Forcepoint logo" src="https://help.forcepoint.com/docs/ni/assets/logo1.png" />
    </a>
    <div class="extLinksContainer">
      <a class="extLinks" href="//support.forcepoint.com/documentation">Documentation</a> | <a class="extLinks" href="//support.forcepoint.com">Support</a></div>
    <!--
		<wsApp:UserAccess ID="useraccess1" runat="server" IsSecure="False" />
		-->
    <div class="spacer1"></div>
    <br />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="h_dest_add-edit_explain.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="h_add_domain.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="web_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="hybrid_filtering.aspx">Configure the Hybrid Service</a> &gt; Configure user access to the hybrid service</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <!--googleon: all-->
    <div>
      <div class="N1H-Heading1"><a name="603066">Configure user access to the hybrid service</a></div>
      <div class="IN-TopicInfo"><a name="667082">Administrator Help&nbsp;| Forcepoint Web Security &nbsp;| v8.5.x</a></div>
      <div class="B-Body"><a name="603067">To use the hybrid service for policy enforcement, you must configure how users connect to and are managed by the hybrid service. To do so, select </a><span class="B-Bold">Settings&nbsp;&gt; Hybrid Configuration&nbsp;&gt; User Access</span>.</div>
      <div class="B-Body"><a name="620108">The </a><span class="B-Bold">Proxy Auto-Configuration (PAC) File</span> section shows the URL from which users' browsers retrieve the PAC file (see <span class="LEM-LinkEmphasis"><a href="h_pac_file.aspx" title="What is the hybrid PAC file?">What is the hybrid PAC file?</a></span>). </div>
      <div class="B-Body"><a name="644343">The PAC file defines which requests the browsers send to the hybrid service, and which are sent directly to the target site (see </a><span class="LEM-LinkEmphasis"><a href="h_unfiltdest_explain.aspx" title="Specify sites not managed by the hybrid service">Specify sites not managed by the hybrid service</a></span>). The PAC file also contains information about filtered locations, and the proxy configuration for any locations that manage Internet access for their users through an explicit or transparent proxy when on-premises, so that traffic can be routed properly at all locations.</div>
      <div class="F-Frame"><a name="644679">&nbsp;</a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="NI-NoteIcon">
              <img src="note.gif" alt="*" border="0" width="33" height="33" /><a name="644694">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="N-Note">Note<a name="644696">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="644714">The exact mechanism for configuring a user's browser to use the PAC file depends on the browser and your network environment. For example, if you are using Microsoft Active Directory and Internet Explorer or Mozilla Firefox, you might want to automate the process by using group policies.</a></div>
          </td>
        </tr>
      </table>
      <div class="B-Body"><a name="689236">The default PAC file is retrieved over port 8082. If users request this PAC file from a location where port 8082 is locked down, they cannot access it. In this case, use the second PAC file address in this section, which enables the user to access the PAC file and hybrid service over port 80. Remote users should also use the PAC file address for port 80 if requesting access from a network that has port 8081 locked down. Even if they can access the PAC file on port 8082, port 8081 is the standard port required to be able to use the hybrid service.</a></div>
      <div class="F-Frame"><a name="689237">&nbsp;</a></div>
      <table class="ImpTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="II-ImpIcon">
              <img src="important.gif" alt="*" border="0" width="30" height="34" /><a name="694395">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="IMP-Important">
              <span class="Bold">Important</span><a name="694397">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="694408">If you are using an identity provider for single sign-on, the PAC file defined for port 8082 is the only PAC file that can be used.</a></div>
          </td>
        </tr>
      </table>
      <div class="B-Body"><a name="687952">Use the </a><span class="B-Bold">Availability</span> section to specify whether all Internet requests should be permitted or blocked when the hybrid service is unable to access policy information for your organization.</div>
      <div class="B-Body"><a name="605236">Under </a><span class="B-Bold">Time Zone</span>, use the drop-down list to select a default time zone to use when applying policies in the following situations:</div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="605242">For users connecting to the hybrid service from an IP address that is not part of an existing filtered location (see </a><span class="LEM-LinkEmphasis"><a href="h_proxycl_explain.aspx" title="Filtered locations">Filtered locations</a></span>)</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="605261">The default time zone is used, for example, by off-site users, or for other users that self-register with the hybrid service.</a></div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="605269">Whenever time zone information is not available for a filtered location</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B-Body"><a name="603083">Use the </a><span class="B-Bold">Custom End User Block Page</span> section to define a customized logo and text for block pages displayed by the hybrid service (see <span class="LEM-LinkEmphasis"><a href="h_custom_block_page.aspx" title="Customizing hybrid block pages">Customizing hybrid block pages</a></span>).</div>
      <div class="B-Body"><a name="703787">Use the </a><span class="B-Bold">Certificate Verification Bypass for HTTPS Sites</span> section to chose whether or not to use certificate verification and, when enabled, whether and how end users can bypass certificate verification failures (see <span class="LEM-LinkEmphasis"><a href="h_cert_veri_bypass.aspx" title="Configuring certificate verification bypass">Configuring certificate verification bypass</a></span>).</div>
      <div class="B-Body"><a name="628611">Use the </a><span class="B-Bold">HTTPS Notification Pages</span> section to enable users making HTTPS requests to view the appropriate notification pages (see <span class="LEM-LinkEmphasis"><a href="h_hybrid_ssl.aspx" title="Enabling hybrid HTTPS notification pages">Enabling hybrid HTTPS notification pages</a></span>).</div>
      <div class="B-Body"><a name="619472">If the hybrid service uses directory data collected by Directory Agent to identify users, you can configure hybrid passwords for user accounts on the </a><span class="B-Bold">Hybrid Configuration&nbsp;&gt; Shared User Data</span> page (see <span class="LEM-LinkEmphasis"><a href="h_diragent.aspx" title="Send user and group data to the hybrid service">Send user and group data to the hybrid service</a></span>). If your organization does not use directory data collected by Directory Agent to identify users connecting to the hybrid service from outside filtered locations, you can let users <span class="B-Bold">self-register</span> for the service. This allows users with email accounts associated with domains that you specify under <span class="B-Bold">Registered Domains</span> to identify themselves to the hybrid service.</div>
      <div class="B-Body"><a name="619473">Users requesting Internet access from an unrecognized IP address are prompted to self-register. The domain portion of the user's email address is used to associate the user with your organization so that the proper Default policy is applied.</a></div>
      <div class="B-Body"><a name="619474">Users who cannot be associated with an organization receive the hybrid service Default policy.</a></div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="619478">Click </a><span class="B-Bold">Add</span> to add a domain (see <span class="LEM-LinkEmphasis"><a href="h_add_domain.aspx" title="Adding domains for hybrid self-registration">Adding domains for hybrid self-registration</a></span>).</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="619481">Click a domain entry to edit the domain or its attributes (see </a><span class="LEM-LinkEmphasis"><a href="h_edit_domain.aspx" title="Editing domains for hybrid self-registration">Editing domains for hybrid self-registration</a></span>).</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B-Body"><a name="619444">You can also apply hybrid policy enforcement to off-site users connecting from unknown IP addresses, regardless of how those users are filtered when they are in-network or connecting from a filtered location. Under Off-site Users, mark </a><span class="B-Bold">Enable the hybrid service for off-site users</span>.</div>
      <div class="B-Body"><a name="619601">If you clear this check box, any user connecting from an unknown IP address will not be filtered.</a></div>
      <div class="B-Body"><a name="619597">See </a><span class="LEM-LinkEmphasis"><a href="h_off-site_intro.aspx" title="Hybrid service management of off-site users">Hybrid service management of off-site users</a></span> for more information.</div>
      <div class="B-Body"><a name="705041">By default, end user web traffic is routed to the nearest cloud data center based on the egress IP address of your Domain Name Server (DNS). This may mean that traffic for users in a geographic location different from the DNS is not optimally routed, causing some latency issues. Select</a><span class="B-Bold"> Route traffic based on end users' egress IP</span> on the <span class="B-Bold">Settings&nbsp;&gt; Hybrid Configuration&nbsp;&gt; User Access </span>to re-route your web traffic to data centers based on the location of the end user, rather than your DNS.</div>
    </div>
    <!--googleoff: all-->
    <div class="library_search">
      <form class="support_search" action="/content/kb-search.aspx" method="get">
        <label></label>
        <label></label>
        <input type="text" name="q" value=" Search eSupport" onfocus="if (this.value == ' Search eSupport') {this.value = '';}" onblur="if (this.value == '') {this.value = ' Search eSupport';}"></input>
        <input type="submit" value=" "></input>
      </form>
    </div>
    <br class="clear" />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="h_dest_add-edit_explain.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="h_add_domain.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="web_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="hybrid_filtering.aspx">Configure the Hybrid Service</a> &gt; Configure user access to the hybrid service</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <div class="extFooterContainer">
      <div class="extFooter">
        <div align="center">Copyright 2023 Forcepoint. All rights reserved.</div>
      </div>
    </div>
    <SCRIPT>
   function getFileName() {
      //this gets the full url
      var url = document.location.href;
      //this removes the anchor at the end, if there is one
      url = url.substring(0, (url.indexOf("#") == -1) ? url.length : url.indexOf("#"));
      //this removes the query after the file name, if there is one
      url = url.substring(0, (url.indexOf("?") == -1) ? url.length : url.indexOf("?"));
      //this removes everything before the last slash in the path
      url = url.substring(url.lastIndexOf("/") + 1, url.length);
      //return
      return url;
   }

   var url = document.URL;
   var Docname = getFileName()
   s.pageName = "enu:support:technical library:webhelp_v85x:" + Docname;
   s.prop1 = "enu:support";
   s.prop2 = "enu:support:technical library";
   s.channel = "support";
   // <!--
   s.server = "<%= System.Environment.MachineName %>";
   //--></SCRIPT>
    <script language="javascript1.1" type="text/javascript">
   /********Do Not alter below this line ***********/
   var s_code = s.t(); if (s_code) document.write(s_code)
   //--&gt;</script>
  </body>
  <!--"GENERALQUARTERSALLHANDSMANYOURSTATIONS"-->
</html>