Enable ThreatSeeker

To start using ThreatSeeker categories for URL filtering, enable ThreatSeeker for the engine.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Select Engine.
  2. Right-click an engine, then select Edit <element type>.
  3. In the navigation pane on the left, browse to Add-Ons > ThreatSeeker.
  4. Do one of the following:
    • To use ThreatSeeker URL Categorization cloud database for URL filtering:
      1. Select the Enable checkbox.
      2. From the URL Categorization drop-down list, select the ThreatSeeker Cloud Service option.
        Note: By default, this option is selected.
    • To use the locally downloaded ThreatSeeker URL Categorization database for URL filtering:
      1. Select the Enable checkbox.
      2. From the URL Categorization drop-down list, select the Local (with Database Download) option.
  5. Select from the following:
    • To validate the changes, select More actions > Validate.
    • To validate and save the changes, click Save.
    • To validate and save the changes and refresh the security policy on the engine, click Save and Refresh.
    Note: Validation issues are displayed in the Issues pane. Double-click an issue to return to the section in which the issue can be fixed.

Engine Editor > Add-Ons > ThreatSeeker

Use this branch to select HTTP Proxy elements for the connection to the ThreatSeeker Intelligence Cloud.

Option Definition
Enable When selected, enables ThreatSeeker URL filtering for the engine.
HTTP Proxies

(Optional)

When specified, requests are sent through an HTTP proxy instead of the engine accessing the external network directly.

Add — Allows you to add an HTTP Proxy to the list.

Remove — Removes the selected HTTP Proxy from the list.

URL Categorization
Select one of the following options:
  • ThreatSeeker Cloud Service: When selected, the ThreatSeeker URL Categorization cloud database is used for the URL filtering.
    Note: By default, this option is selected.
  • Local (with Database Download): When selected, the locally downloaded ThreatSeeker URL Categorization database is used for the URL filtering.
Note:
  • The Security Engine must have a minimum of 16 GB of memory to use the locally downloaded ThreatSeeker URL Categorization database.
  • When the Local (with Database Download) option is selected the entire ThreatSeeker URL Categorization database is automatically downloaded and is made locally available to the engine.
  • The local database is automatically updated over the internet whenever updates are available.
  • If the ThreatSeeker Cloud Service option is selected after the Local (with Database Download) option was selected, the locally downloaded database will be automatically deleted.