Bypass options

Bypass is the term used to describe several methods of specifically allowing a request to circumvent (bypass) all or select features of Content Gateway. Full proxy bypass is often called tunneling.

In this discussion take note of when bypass affects:

  • Only certificate verification
  • Certificate verification and SSL decryption
  • Complete bypass of Content Gateway

These are the primary bypass methods:

  • SSL decryption bypass (category, client IP addresses, and destination hostname/IP address); SSL decryption bypass is configured in the Web module of Forcepoint Security Manager
  • The Content Gateway SSL Incident List
  • Content Gateway ARM bypass (transparent proxy)
  • Explicit proxy PAC file bypass
  • Transparent proxy routing device ACL bypass
  • Allow users to continue after verification failure (Configure > SSL > Validation > Verification Bypass)