Entering your subscription key

When Content Gateway is deployed with Forcepoint Web Security, there is no need to enter a subscription key in the Content Gateway manager. The Forcepoint Web Security key is automatically shared with Content Gateway.
Note:

A key is associated with a Policy Server instance. If you have multiple keys, make sure that Content Gateway is connected to the correct Policy Server instance on the More Details view of the Monitor > My Proxy > Summary page.

To change which Policy Server instance Content Gateway uses:

  • (Appliance) See your Forcepoint appliance documentation.
  • (Software) Edit the /opt/WCG/websense.ini file to set the value of PolicyServerIP. After making the change, stop and start Content Gateway processes:

    /opt/WCG/WCGAdmin stop

    /opt/WCG/WCGAdmin start

When the number of subscribed clients exceeds the licensed count, Forcepoint Web Security tracks usage per unique client IP address over a rolling interval. The default interval is 24 hours. Once the licensed seat count is reached for that interval, the product treats any additional client IP address as over-subscription.

The Block users when subscription is exceeded setting on the Web > Settings > General > Account page in the Forcepoint Security Manager controls whether the product blocks or allows that traffic:

  • If you disable the option (the default), the product allows over-subscription traffic through but does not apply category-based policy. Filtering Service logs each request as an unfiltered "exceeded" event. Client IP addresses already counted before the limit was reached continue to be filtered normally.
  • If you enable the option, the product blocks over-subscription traffic and displays the standard policy block page.

This same setting handles subscription expiration. An expired (non-perpetual) subscription causes the effective licensed count to drop to zero, so the product treats all client traffic as over-subscription from that point forward.

Note: This behavior is the same for Forcepoint Web Security and Forcepoint URL Filtering deployments.

When Content Gateway is deployed with only Forcepoint DLP, you will need to enter your subscription key manually.

Steps

  1. Go to the Configure > My Proxy > Subscription > Subscription Management page of the Content Gateway manager.
  2. Enter your key in the field provided.
  3. Click Apply.
  4. Click Restart on the Configure > My Proxy > Basic > General page.