Athena SWG (Secure Web Gateway)

Athena SWG (formerly Internet Access Gateway) ensures visibility and control across the network, detecting risks like unauthorized access, non-compliant activities, and data leaks to manage endpoints.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
13.0.120
{{sendMatomoQuery("Athena SWG (Secure Web Gateway)","Self Service")}}

Self Service

{{ $t('productDocDetail.updateTime') }}: 2025-12-29

New Requests

After the administrator receives self-registered user information, Choose Status > Approval Center approve it on this page:

Self Registration

Support two registration methods, including User Registration and Endpoint Registration.

Prerequisites

User Registration: Local user and external password authentication support.

Endpoint Registration: Authentication support is not needed.

Other authentication servers do not support registration. When the authentication servers not supporting the registration are selected, the registration option will become grey.

Configuration Path

User authentication and management:

Authentication Policy > Open Authentication > Obtain during self registration

Authentication Policy > Password based, and Enable Self registration.

Access Mgt > User Management > Self Registration

Configuration idea: You can configure the self-registration-related information one by one or define the self-registration-related information in advance, which can be directly quoted in the authentication policy.

User Registration

Scenarios:

Password authentication: You need to type in the user profile to assist management.

Previously, the administrator created the accounts one by one. At present, the user can register by himself as per demands.

Local password authentication and password authentication of an external authentication server (including WeChat ID/SMS quick login).

Configuration Method

3.5.1.6.6.1 Configure self-registration

Step 1.Go to Access Mgt > User Management > Self Registration and click User Registration.

Step 2.Set user registration settings.

Form Fields: Commonly include mobile number, email address, gender, birthday, etc. (the best analogical pattern and the information required to be filled in when the user registers for specific forums)

Add New Field: Define contents, the default value (can be left blank), and whether the new field is required.

Binding Required: Support mobile number binding and email address binding. This method also can be used to retrieve the password.

Added To Group: The local user can specify the specific groups.

Approval Options: The administrator can determine whether the contents entered in self-registration need to be approved.

The administrator shall have permission to edit and view the New Request.

Advanced: You can set the account expiration. In addition, the account supports creating user binding.

If the administrator approval scenario is needed, whether the approval result is notified to the user is optional (the approval result shall be available for ensuring the SMS notification server).

3.5.1.6.6.2 Configure authentication policy

Go to Access Mgt > Authentication > Web Authentication > Authentication Policy > Auth Method, and select a local user database for Authentication Server. Then, select Self registration, select a user group, and click Commit.

3.5.1.6.6.3 Effect

Access the webpage and redirect to the authentication page. Since there is no account, click Register at the lower right corner.

Type in information following requirements.

Approval not required: Directly authenticate using the account password after registration.

Approval required: Your information is submitted. Please wait for the administrator to approve your request.

After receiving the notifications, the administrator logs in to the device console to see the account registration and audit information in the approval list:

Click Approved to complete user registration.

Click Reject to refuse a user registration.

If Notify approval result to users is configured, the registered user will receive an approval result notification.

After the registration is approved, the user uses the registered account password to authenticate (The quick login is configured, and the authentication can be completed using the quick login method).

If the registration is rejected, the user uses the registered account password to authenticate, prompting that the username and password are incorrect.

User Information Self-management

Scenarios:

User Profile Change, etc.

Path:

  1. Navigate to Access Mgt > Authentication > Web Authentication > Authentication Policy > Auth Method, click the hyperlink beside Login Redirection, and select User Profile.

User Profile

Click Edit to edit the information.

For binding the endpoint, only the following page is allowed to be viewed:

Access Mgt > Authentication > Advanced > Authentication Options > User Profile Change, and select the Allow user to edit endpoint information.

After selecting the box, the following page pops up:

Self Registration Approval

There are two approval methods to submit registration information by the user, whether the registration is account registration or endpoint registration.

One is approval not required, which indicates that the account takes effect after a successful registration. The other is approval required, which indicates that the account can take effect only if the administrator approves it with the corresponding group permission.

Approval Options:

Set endpoint registration approval:

After logging in to the device, the administrator can view the registration request submitted by the user in the approval list and select Approve or Reject. When Approve is selected, the registration request takes effect immediately; when Reject is selected, the registration request does not take effect. The user needs to submit the registration request again.

When the self-registration approval is rejected, the Approval Opinions box pops up, indicating the reason for rejection. Meanwhile, the reason is recorded in the approval history. When the user selects to reject account login, the approval rejection and reason will be prompted, and this approval opinion is allowed to be empty. Filling in the opinion once in batch approval is supported.

Select Notify user of approval result.