Key concepts

To get started with the service, you must forward your web traffic to the cloud, configure user identity and synchronization (if required), and create policies to control web access. A default policy is pre‑configured.

Traffic forwarding

In order for the service to perform filtering, you must redirect web traffic to the cloud service, and configure your firewall to allow access to the service on specific ports.

Traffic can be directed to the cloud service in a number of ways:
  • A Forcepoint Endpoint: a lightweight software client that runs on end user devices, providing policy enforcement for web browsing.
  • A browser PAC (proxy auto-config) file: a configuration script that can be configured in your users’ browsers (via GPO or similar) to redirect browser requests to the service.
  • Firewall redirection: a simple method implemented on your firewall to redirect all HTTP/HTTPS traffic to the service.
  • Tunneling: IPsec or GRE connectivity to forward traffic to the service from a supported edge device.

User Identity and Synchronization

The service can identify and authenticate users to enforce user‑ and group‑specific policies and provide detailed activity reporting. Users may be added manually or synchronized automatically via identity management integrations.

This step is optional; some organizations apply the same policies to all users based solely on IP address, without requiring users to authenticate.

Note: If your organization has roaming users (those who connect from locations outside of your network), those users must be registered and must identify themselves in order to use the service remotely. See User registration methods.
Table 1. Authentication methods
Method Use Case Complexity Roaming Support
Endpoint Client Full control needed Medium to High
SSO Provider Uses existing identity system Medium
NTLM LAN users only Low
Manual Authentication Exceptions only Very High

Policies

Policies allow or block access to web resources, control authentication, and define content filtering, file upload/download behavior, and data security (Data Loss Prevention) settings. Exceptions can override policy rules per user or group.

Filtering is based on a set of web categories drawn from the Forcepoint URL Database, constantly updated by Forcepoint Security Labs, with security threats identified in real time by Forcepoint ThreatSeeker Intelligence.

A default policy is available, providing a set of standard web filtering settings. Once you are up and running with the service, you can edit this policy and create new ones, providing differing levels of access for different users and departments. (See Tailoring your policies.)