Athena SWG (Secure Web Gateway)

Athena SWG (formerly Internet Access Gateway) ensures visibility and control across the network, detecting risks like unauthorized access, non-compliant activities, and data leaks to manage endpoints.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
13.0.120
{{sendMatomoQuery("Athena SWG (Secure Web Gateway)","Configuration Guide")}}

Configuration Guide

{{ $t('productDocDetail.updateTime') }}: 2025-12-29
  1. Configure the correct location, local, and international line from the virtual line, under the bandwidth management category.

  1. After configured, the admin can view which user has utilized most of the International Bandwidth from the internal data center.

  1. Able to check which application has utilized most of the International Bandwidth.

  1. Limit the user/application bandwidth that has utilized most of the International Bandwidth to solve the bandwidth problem is not well distributed.

Generate International Report from the internal data center.



[LCH1]Should rename to HA?@gfy

[2]这里表述是部署2台设备做高可用,可以是主备部署、主主部署,但都属于冗余部署,叫 Redundant也可以,或者交付侧看其他产品,比如AF是怎么翻译的吧

[LCH3]System > General > Date/Time page?

[4]是的  批注里的为正确路径,已修改

[A5]G   Status > User --->Status > Endpoint Visibility > Endpoints

[6]已修改

[LCH7]Which chapter.

[8]3.6.1.1.1 Access Control

[LCH9]Cant see in UI

[10]System->network->DHCP->status

[A11]修改

Security Event->Security Events

[12]ok

[LCH13]?

[14]server

[LCH15]Not same with UI

[16]已修改

[LCH17]Not same with UI.

[18]这里包括了requestresponse服务器,在已定义的ICAP服务器列表中选择。

或者可以把“ICAP SERVER GROUP”换成“ICAP Request Server+ICAP Response Server

[A19]G 

Objects > Source IP --> Objects > Source >

[LCH20]Not same with UI and replace ss

[21]已修改,图片已替换

[LCH22]Not same with UI.

[23]已修改

[A24]G  Objects > Source >

[25]已修改

[A26]G  Deny--> Reject

[27]已修改

[LCH28]Not same, replace ss

[29]已修改 已替换

[A30]G User --> User Management

[31]已修改

[LCH32]Wrong path

[33]已修改

[A34]G Submit --> OK

[LCH35]Secret key binding missing

[A36]3.5.1.4.3 Secret Key Binding

[A37]G  Download USB Key Driver--->Download

[A38]m

[A39]G  Commit--->OK

[ZY40]3.5.2章节是,13.0.80是新增内容

[LCH41]Which chapter?

[A42]m

[A43]G Auth --->Authentication Server

[LCH44]Disable IP/MAC bidning based auto authentication?

[45]是的,是指这个选项

[A46]G

Commit ==> OK

[A47]G

 System > System Config > Advanced > Notification

====>System > General > Advanced > Notification

[A48]G   LDAP Sync Options --->  LDAP  Options

[A49]G

Synchronize All LDAPs Now ---> Sync with all LDAP servers

[zyl50]这个图我直接从界面上截了

[zyl51]中文图

[zyl52]界面已经过时,建议重新截图

[zyl53]中文图

[U54]口袋助理还卖吗

[55]口袋助理还在继续卖,这个认证方式要继续保留

[zyl56]界面已变,请替换

[A57]G Commit --->OK

[LCH58]Cant see on UI.

[59]Send user credentials to other Sangfor appliances的填写指引

[LCH60]Is this Redirection URL? And APMAC Field is missing.

[61]是的

[62]APMAC字段已添加

[A63]G

Bandwidth Mgt ===>Bandwidth Management

[A64]G     Commit --->OK

[A65]G Commit --->Yes

[A66]G

Access Management  ===> Access Mgt

[ZY67]13.0.80新增功能

[ZY68]13.0.80新增功能

[LCH69]I don’t see how to set the violation in UI.

[ZY70]

[ZY71]13.0.73应该添加,原始文档漏掉,13.0.80补上

[LCH72]Replace ss

[A73]已修改,图片已替换

[LCH74]Imagechanges?

[75]没有变化,这里是写了一下支持的类型

[LCH76]Chinese doc link.

[77]没有英文版的帖子,建议直接把 SaaS Options这一段删除

[A78]G Commit -->OK

[A79]G Commit ---> OK

[LCH80]Cant find this

[81]删除

[A82]DeleteP3290#yIS1

[A83]G  Commit --->OK

[A84]G  Commit --->OK

[A85]G Commit ---> OK

[LCH86]Chinese site?

[87]只是一个例子,邮件地址可以自行配置的,改成example@example.com

[A88]G  Email Alarm ----> Email Alert

[zyl89]这里的表格跟上一个表格是同一个表格,还是两个不同表格?如果是,请合并为一个

[U90]同一个

[LCH91]Replace ss

[A92]已修改,图片已替换

[A93]G

commit ==>ok

[A94]G

commit ==>save

[A95]G

commit ==>yes

[A96]G

commit ==>ok

[A97]G

commit ==>save

[LCH98]Cant see this

[A99]应该是这个?

Define Object > User-Defined Application==>System > Objects > Custom Application

[LCH100]Replace ss

[A101]800 MB/s ==> 800 Mbps

[A102]G   Recommended Settings --->Restore Defaults?

[LCH103]Cant see this on UI.

[A104]G

Bandwidth Mgt ==>Bandwidth  Management

[A105]G Commit ---> OK

[A106]G

Commit ==> OK

[LCH107]Do not have this

[A108]G

 Recommended Settings --->Restore Defaults

[A109]G Commit --->OK

[A110]G

Customized ==> Custom

[LCH111]Do  not see this

[112]这是个描述说明,当满足配置的这些内容时才会生效,并不是说Channel Availability是一个单独的配置,有歧义的话可以把这个加粗的部分去掉

[A113]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Quota Control   ---->

Online Activities>Bandwidth Management>Quota Control>Add > Quota Control

[LCH114]Wrong path?

[A115]G Recommended Settings--->Restore Defaults

[LCH116]Don’t have this

[117]

[LCH118]Don’t have this

[119]和上面的同理,满足条件才会生效,并不是说有一个专门的配置项叫“通道生效”有歧义可以删掉加粗部分

[A120]G

Commit  ==> OK

[A121]G   Commit---->OK

[A122]G

Bandwidth Management > Bandwidth Mgt > Virtual Lines > Virtual Line Rule ==>

Bandwidth Management > Line Bandwidth > Virtual Lines > Virtual Line Rule

[LCH123]Replace ss

[A124]Proxies ==> Proxy Action?

[LCH125]Replace ss

[A126]Proxies ==> Proxy Action?

[zyl127]英文中说选择的是Resolve to IP address,但是截图中选择的是Redirect to DNS server.请确认译文是对的,还是截图是对的?

[U128]图错了更新图

[LCH129]Replace ss

[A130]已修改,图片已替换

[LCH131]Confirm the location of these.

[A132]G Redirect to specified line --->Forward to specified line

[A133]W

[134]

[LCH135]Path change and replace ss

[A136]G  Bandwidth Mgt > Link Load Balancing > Preferred Link Load Balancing Policy > Add

--->

Bandwidth Management > Load Balancing Policy> Preferred Link Load Balancing Policy > Add

[LCH137]Replace the Chinese ss

[LCH138]Cant see this. Path change and function change?

[A139]需要在网桥模式下

[zyl140]中文图,请确认是否删除

[A141]W

[A142]G  Link Load Balancing --->Load Balancing Policy

[A143]G  Link Load Balancing --->Load Balancing Policy

[A144]W

[A145]G Bandwidth Management > Link Load   --->

Bandwidth Management > Load Balancing Policy > Preferred Link Load Balancing Policy > Add

[A146]W

[147]配置没有了?

[A148]W

[LCH149]Imagenot sure is this section follow this. Some method cannot see in UI, and Weighted Round Robin content is missing.

[150]

[A151]G

Access Mgt > Advanced > Logging ==>

Activity Audit > Advanced > Logging

[A152]G

Removable Storage Audit

  ==>USB and Portable Hard

[zyl153]这是国内的阅读器软件,待确认是否删除

[U154]保留

[zyl155]同上,是国内的。

[zyl156]同上,国产app,请确认是否删除或者替换掉

[U157]保留,规则库不区分中英文

[LCH158]Replace ss

[A159]已修改,图片已替换

[LCH160]Detection trigger, lock endpoints triggering the detection contents missing.

[161]

[A162]补充内容

[A163]G

Commit ==> OK

[A164]G Commit ---> OK

[LCH165]Link?

[166]没有链接,可以参考中文文档的做法,将这一段删除

[A167]G Mgt ---> Management

[A168]G

 System Mana ement > System Configuration > Alarm Option ==> System > General > Alert Option

[A169]G

Commit ==> OK

[A170]G

System Management > System Configuration > Alarm Option ====> System  > General > Alert Option

[A171]G

Commit ==> Save

[LCH172]Sangfor Engine Zero?

[A173]G

Alarm Option ==>Alert Option

[ZY174]英文版本13.0.80版本新增

[A175]G OK ===> Save

[A176]G Commit ---> OK

[zyl177]同上,看不到界面,这两个界面词待确认

[A178]G

Management Platform Port ==>Ports

[A179]W

不支持联动

[zyl180]看不到界面,待确认英文界面词

[A181]Internet Access Authentication ==>

 Authentication

[zyl182]看不到英文界面,界面词待确认

[A183]Log out. ==>Exit

[A184]G

 Alarm ==>  Alert

[LCH185]Replace ss

[A186]W

[A187]W

[A188]W

[A189]W

[LCH190]Cant find this.

[LCH191]Which chapter?

[192]

[A193]G

System Management > System Configuration > Alarm Option ==>

System > General > Alert Option

[A194]G

System Management > System Configuration > Alarm Option ===>

System > General > Alert Options

[A195]G OK ===>Save

[A196]G

System > System General > Alarm Option===>

System > General > Alert Options

[A197]G

 Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control ===> Online Activities > Access Control

[LCH198]Wrong path

[A199]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Ingress Policy===>

Online Activities > Access Control

[LCH200]Wrong path

[A201]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control ===> Online Activities > Access Control

[LCH202]Wrong path

[A203]G

Online Activities > Access Control

Bandwidth Mgt ===>

Bandwidth Management

[LCH204]Wrong path

[A205]G

Online Activities > Access Control

Search Keyword ===>Search

[LCH206]Wrong path

[A207]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control > File Type===>

Online Activities > Access Control > File Type

Bandwidth Mgt ===>

Bandwidth Management ? 在流量管理应该不用选文件类型吧?

[208]删除,加上外发管控的

[LCH209]Wrong path?

[A210]G

 Online Activities > Access Control,or Bandwidth Management > Bandwidth Channel. 

[LCH211]Cant see this

[212]和这个章节的内容没关系,删了吧

[A213]G  这个吗?

Web Access > Web Access Permission > SSL Mgt > SSL Security Protection ===>

Online Activities > SSL Decryption?

[A214]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control ===>

Online Activities>Access Control

[LCH215]Wrong path

[A216]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control ===>

Online Activities>Access Control

[LCH217]Wrong path

[A218]G Commit ==>OK

[A219]G

Bandwidth Mgt > Bandwidth Channel==>

Bandwidth Management > Bandwidth Channel

[A220]G

[LCH221]Wrong path

[LCH222]Whole section move to the new path or delete? Pls re-look.

[A223]Whole section move to the new path

[A224]G

 Objects > Ingress Rule Database > Ingress Rules===>

Access Mgt >  Endpoint Check > Check  Policy

[A225]G

 Objects > Ingress Rule Database > Ingress Rules===>

Acess Mgt > Endpoint Check > Ingress Client Based

[A226]G

Required Operating System===>

Check Items

[A227]G

Registry Based Rule ===> Registry

[A228]G

Patch-based rule ===>Service Pack

[A229]Objects > Ingress Rule Database > Combined Ingress Rule ===>

Access Mgt > Endpoint Check >  Check Rules > Ingress Client Based > Combined Ingress Rule

[LCH230]Wrong path

[A231]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control > Service====>

System > Objects > Service

[A232]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control > Service====>

System > Objects > Service

[LCH233]Wrong path

[LCH234]Wrong path

[A235]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control > Service====>

System > Objects > Service

[A236]G

Bandwidth Mgt > Bandwidth Channel.===>

Bandwidth Management > Bandwidth Channel.

[A237]G

Online Mgt > Policies ===>

Online Activities> Access Control

Bandwidth Mgt > Bandwidth Channel===>

Bandwidth Management > Bandwidth Channel.

[LCH238]Wrong path

[A239]Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control > Search Keyword===>

Online Activities> Access Control> Add > Access Control > Search Keyword

[LCH240]Wrong path

[A241]G

Access Mgt > Authentication > Web Authentication > Custom Webpage> Add > Access Control > File Type===>

Online Activities> Access Control>Add > Access Control > File Type

[A242]G

Bandwidth Mgt > Bandwidth Channel===>

Bandwidth Management > Bandwidth Channel

[A243]G Commit ---> OK

[A244]G Commit ---> OK

[A245]G Commit ---> OK

[A246]G Commit ==> OK

[A247]G commit ==> OK

[A248]G Submit ===> OK

[A249]G  Encryption ===> Encryption Method

[A250]G  Commit ===>OK

[A251]G  Advanced Settings ===> Advanced

[A252]G Commit ==> OK

[A253]G Commit ==>OK

[A254]G Commit ==>OK

[LCH255]Not sure this is refer to which one.

[ZY256]图没有换

[A257]G   224-2000 ===>576-1500

[LCH258]Is this MSS

[259]

[LCH260]Cant see this

[261]找不到,中文文档也没有,建议删除

[LCH262]Replace ss

[A263]已修改,图片已替换

[ZY264]图没有更换

[A265]G   Local User ===> User Management

[A266]G

proxy subnet segment  ==>  Mapped IP

subnet mask ===> Netmask

[LCH267]Proxy Subnet Segment is Mapped IP?

[A268]G

proxy subnet segment  ==>  Mapped IP

subnet mask ===> Netmask

[LCH269]Statusment?

[270]这里的[本地子网列表]仅相当于一种“声明”作用,在此定义的网段,都会被我们的VPN设备和软件客户端视为VPN网段,所有访问这些网段的数据包经过VPN设备或软件后,都会被封装到VPN隧道中传输。一般情况下,在本地子网列表里添加了子网网段,都需要配合静态路由来完成对多子网的访问。

[LCH271]Imagepath change?

[272]13.0.120中的路径:System > Firewall

[LCH273]Replace ss

[274]VPN的页面没有替换为新UI

[LCH275]Path change?

[A276]G VPN Configuration > Settings > Time and Schedule Settings ===>

VPN  > Objects > Schedule

[LCH277]Path change?

[A278]G VPN Configuration > Settings > Time and Schedule Settings ===>

VPN  > Objects > Schedule

[A279]G Save ===>OK

[A280]G

 Permission Settings. ==> Allow

[LCH281]Ss missing

[A282]

[A283]G

 Permission Settings. ==> Allow

[A284]G Save ==> OK

[A285]W

[286]

[LCH287]Change name?

[A288]没有这个了

[A289]G

Administrative Role ==>Role Name?

[A290]G Commit ==> OK

[A291]G Administrative Roles ===>

Administrative Role

[A292]W 

[293]

[A294]G Alarm Options ===>Alert Options

[LCH295]Key business disconnectivy?

[A296]Key Service Inspection Alarm ==>Key business disconnectivy

[LCH297]Chinese path?

[ZY298]准确来说就是有中文字符的路径,已修改。

[ZY299]13.0.80新增内容

[A300]W  Delete?

[U301]删除,去掉了

[A302]G commit ==>OK

[A303]G  Clone ===> Copy

[A304]W  Update===> Edit

[A305]G         ===>Test Connection

===> Sync Now

[A306]G   Commit ===> OK

[A307]G  OK ===> Save

[ZY308]13.0.80英文版新增,图片已经替换

[ZY309]13.0.80版本新增,自定义导入SSL证书。

[A310]G OK ==> Save

[A311]G  Commit ==> Save

[LCH312]Imagecontent and screenshot not same with current UI.

[313]在你这个截图的下面

[A314]G   Enable Access Backstage ===> Enable Firmware Updater

[A315]W

 Delete?

[U316]

[A317]W

Delete?

[A318]G Commit ==>OK

[LCH319]Doesn’t has this.

[A320]G

Open Interface ==> Public API Service

[A321]G

Open Interface ==> Public API Service

[A322]G

System > General > Advanced > Public API

======>

Access Mgt > User Management > Public API Service > Public API

[LCH323]Doesn’t has this

[LCH324]Path change

[A325]G

Authentication Server > SMS Based Authentication ====>

Access Mgt > Authentication > Web Authentication > Authentication Server > add > SMS Based Authentication

[LCH326]Path change

[A327]G 

SMS Notification > Verification Code in Notification  ===>

SMS Notification > Settings

[A328]W

[LCH329]Didn’t see auto nego in UI.

[330]可以隐藏了,默认支持自协商

[331]这个考虑删掉吧,IAG没有做XDR联动适配

[A332]W

[A333]W

IAG13.0.120XDR不支持设备联动

[U334]XDR不支持,用SIP举例吧

[A335]W

[A336]W

[A337]W

[LCH338]ImageHealth Check content is missing

[339]在下面

[A340]G

Restart ===>Equipment Operation

[A341]G

关机 ===> Device Shutdown

[A342]补充内容

[A343]G Commit ===> OK

[A344]G

Access Mgt > Authentication > Web Authentication > Single Sign-On (SSO) Microsoft AD Domain ====>

Access Mgt > Authentication > Web Authentication > Single Sign-On (SSO) > MS AD Domain

[345]截图是 AC,要换成IAG

[346]截图是中文的,要做替换

[347]截图是中文的,要做替换

[348]截图是中文的,要做替换

[349]截图是中文的,要做替换

[350]截图是中文的,要做替换

[351]截图是中文的,要做替换

[zyl352]这个图片含有中文字符,请替换图。

[LCH353]Wrong  path

[A354]G

Users > Authentication Policy ====>

Access Mgt > Authentication > Web Authentication >Authentication Policy

[355]下面截图是中文的,要做替换

[356]截图是中文的,要做替换

[A357]W

[358]截图是中文的,要做替换

[LCH359]Wrong path

[A360]G 

Users > Authentication Policy ====>

Access Mgt > Authentication > Web Authentication >Authentication Policy

[A361]G

 Users > Advanced > Authentication Options===>

Access Mgt  >  Authentication > Advanced > Authentication Options

[A362]G

 Auth Server ====>

Authentication Server

[A363]w

[A364]G Commit ==> OK

[A365]G

Access Mgt > Access Control ====>

Activity Audit > Audit Policy

[A366]G Commit ==> OK

[A367]G  Whole Day ===> All Day

[A368]G

Commit ==> OK

[A369]G

Access Mgt > Access Control ====>

Activity Audit > Audit Policy

[A370]G Commit ===> OK

[A371]G

Endpoint Device > Antiproxy====>

Endpoint Mgt > Antiproxy

[A372]G Commit ===> OK

[A373]G

Commit ===> OK

[A374]G

Commit ===> OK

[A375]G

Commit ==> OK

[LCH376]Figure missing

[A377]G

Commit ==> OK

[A378]G

Commit ==> OK

[A379]G

Commit ==> OK

[A380]G

Commit ==> OK

[A381]G

Commit ==> OK

[A382]G

Alarm ===>Alert