tmgreporter

Make The World A Better Place with Fastvue and Microsoft Reputation Services (MRS)

by

Etienne Liebetrau

Etienne Liebetrau

Uncle Ben told Peter Parker “With great power comes great responsibility”. With TMG Reporter and Webspy Vantage you gain total visibility of what your users are up to. This allows you to make informed decisions that can be backed up with hard data.

One great feature of Forefront TMG is URL filtering. Simply put, it knows which sites belong to which category and based on your rules, allows or denies access. Forefront TMG and other products use Microsoft Reputation Services to lookup the site category.

This is a great system as it relies on centralized / partnered and crowd sourced data to populate and keep the lists up to date. Having said that, it is not perfect and some sites do slip through the cracks especially new or small sites.

Fortunately, TMG Reporter can help you find any site that has not been categorized by Forefront TMG's URL Filtering service. You can then use this information to manually override the site and assign it to the correct category, but you can also submit the site to Microsoft Reputation Services (MRS), so everyone can benefit from your discovery!

Real-world Example

I was going through a daily report and saw that the bulk for the top user came from a single site. By simply doing a mouse-over I could see what site it was. Looking up the site it became clear that this was a remote proxy site. This kind of site should normally be categorized as Anonimizers.  Looking up the site in Forefront TMG did not identify the site at all.

Finding Uncategorized Sites

You can easily find all sites that have not been categorized by Forefront TMG. Simply run an Overview Report, click the Filters button, and enter the filter "Category Equal to Unknown". You may also like to add the filter "Action Equal to Allowed", to find any allowed uncategorized sites.

Click Run Report, and then go to the Top Sites by Size section of the report. Here you'll see all the sites that Forefront TMG has not been able to categorize.

Categorizing Sites Correctly

Once you have identified an uncategorized site, the first thing to do is manually override the site category. This is done in Forefront TMG as Fastvue TMG Reporter simply uses the logged URL category to determine a site's productivity.

Secondly (and this is the part where you can make the world a better place), do the right thing and submit the site to Microsoft Reputation Services. This way, your discovery can also benefit other users of the service!

Manually Overriding the site in Forefront TMG

  1. Open the TMG Management console
  2. Select Web Access Policy
  3. Check that the Tasks tab is selected in the right hand pane
  4. Click Query for URL Category
  5. Enter in the URL and click the Query button
  6. This should confirm the site has not been categorised by MRS (you can see this in the description)
  7. Click the URL Category Override tab
  8. Click the Add button
  9. Enter the URL
  10. Select the correct category
  11. Click OK
  12. Apply the setting and wait for the configuration to sync

To confirm everything is correct you can re-run the URL query. You should now notice the correct category is displayed in the description, and it points out that this is a User Defined Override.

Submitting the site to Microsoft Reputation Services (MRS)

Click this link https://www.microsoft.com/security/portal/mrs/default.aspx or click the link at the bottom of the URL query screen to go the the Microsoft Reputation Services page.

  1. Enter the URL you have discovered and click the Get Categories button
  2. You will notice the current categories section says: “The URL you provided was not found. You may still provide feedback by suggesting up to five (5) categories”
  3. Now it is simple a case of selecting the correct Category from the list (in this case Anonimizers)
  4. Solve the CAPTCHA
  5. Click Submit Report

That’s it! As you can see it take no more than a few seconds to submit a site for categorizing. This is where the great power and responsibility lines comes in. Fastvue TMG Reporter and WebSpy Vantage give you the information, it’s up to you to decide what to do with it!

Take Fastvue Reporter for a test drive

Download our FREE 14-day trial, or schedule a demo and we'll show you how it works.

  • Share this story
    facebook
    twitter
    linkedIn

How to Report on YouTube Activity with Fastvue TMG Reporter

This video shows you how to report on youtube.com including how to create a report that provides a simple list of all the videos that people have watched.
TMG Reporter

Forefront TMG Tips and Tricks

Richard Hicks has some great tips and tricks that you can apply to help make your Forefront TMG firewall easier to manage and even more performant.
TMG Reporter