Specify proxy server authentication credentials if you have set up a proxy server to handle HTTP communication in your organization and authentication is required before web access is allowed.
For more information, see Configuring External Agent Proxy Settings.
Configure agent location settings if you have not done so. Agents will use these settings to determine their location and apply the correct web reputation policy. For details, see Endpoint Location.
Trend Micro recommends disabling Web Reputation for internal agents if you already use a Trend Micro product with the web reputation capability, such as InterScan Web Security Virtual Appliance.
When a web reputation policy is enabled:
You can only configure internal on-premises Security Agents to send web reputation queries to local Smart Protection Servers.
Internal agents send web reputation queries to:
Smart Protection Servers if the Send queries to Smart Protection Servers option is enabled.
Smart Protection Network if the Send queries to Smart Protection Servers option is disabled.
When in assessment mode, Security Agents allow access to all websites. For any accessed website that violates the configured Security Level setting, the Security Agent logs the event. Assessment mode allows you to monitor website access and evaluate the safety of websites before actively blocking users access. Based on your evaluation of the access logs, you can add trusted websites to the Approved URL List before disabling assessment mode.
HTTPS URL scanning also supports the HTTP/2 protocol. Before Web Reputation can check HTTPS or HTTP/2 URLs, you must configure some prerequisite settings for different browsers.
For more information, see HTTPS URL Scan Support.
If you enable this option:
Agents refer to the smart protection source list to determine the Smart Protection Servers to which they send queries.
For details about the smart protection source list, see Smart Protection Source List.
Be sure that Smart Protection Servers are available. If all Smart Protection Servers are unavailable, agents do not send queries to Smart Protection Network. The only remaining sources of web reputation data for agents are the approved and blocked URL lists.
If you want agents to connect to Smart Protection Servers through a proxy server, specify proxy settings in the Internal Proxy section on the Administration > Settings > Proxy > Agent tab.
Be sure to update Smart Protection Servers regularly so that protection remains current.
Agents do not block untested websites. Smart Protection Servers do not store web reputation data for these websites.
If you disable this option:
Agents send web reputation queries to the Smart Protection Network. Endpoints must have an Internet connection to send queries successfully.
If connection to Smart Protection Network requires proxy server authentication, specify authentication credentials in Administration > Settings > Proxy > Agent (tab) > External Proxy.
Agents can block untested websites if you select the Block pages that have not been tested by Trend Micro option.
The security levels determine whether Web Reputation allows or blocks access to a URL. For example, if you set the security level to Low, Web Reputation only blocks URLs that are known to be web threats. As you set the security level higher, the web threat detection rate improves but the possibility of false positives also increases.
While Trend Micro actively tests web pages for safety, users may encounter untested pages when visiting new or less popular websites. Blocking access to untested pages can improve safety but can also prevent access to safe pages.
Web Reputation utilizes both the Browser Exploit Prevention pattern and the Script Analyzer pattern to identify and block web pages before exposing the system.
The Browser Exploit Prevention feature provides support for Internet Explorer, Microsoft Edge Legacy, and Chrome browsers.
The Browser Exploit Prevention feature requires that you enable the Advanced Protection Service.
The Browser Exploit Prevention feature requires that you enable the Advanced Protection Service.
To enable the Advanced Protection Service, go to Agents > Agent Management, click Settings > Additional Service Settings.
After enabling the Browser Exploit Prevention feature for the first time on Security Agents, users must enable the required add-on in the browser before Browser Exploit Prevention is operational. For Security Agents running Internet Explorer 9, 10, or 11, users must enable the Trend Micro IE Protection add-on in the browser pop-up window.
The approved list takes precedence over the blocked list. When a URL matches an entry in the approved list, agents always allow access to the URL, even if it is in the blocked list.
You can add a wildcard character (*) anywhere on the URL.
For example:
Typing www.trendmicro.com/* means that Web Reputation approves all pages in the Trend Micro website.
Typing *.trendmicro.com/* means that Web Reputation approves all pages on any sub-domain of trendmicro.com.
You can type URLs containing IP addresses. If a URL contains an IPv6 address, enclose the address in parentheses.
Web Reputation does not perform any scanning on addresses located in the Approved and Blocked lists.
Apply to All Agents: Applies settings to all existing agents and to any new agent added to an existing/future domain. Future domains are domains not yet created at the time you configured the settings.
Apply to Future Domains Only: Applies settings only to agents added to future domains. This option will not apply settings to new agents added to an existing domain.