Web Security - Overview

This article gives an overview of the functionality, benefits, and known incompatibilities of Mimecast Web Security, and is intended for use by Administrators.

Mimecast Web Security gives your users strong security protection from malicious activity that has been initiated by users or malware (at the server level or front line later of the web).
 It works by blocking access to inappropriate websites based on your configured policies and features.

When combined with our Secure Email Gateway and Targeted Threat Protection services, Mimecast Web Security offers a single, cloud-based utility that protects against the two dominant cyberattack vectors: email and the web.

For detailed information on how to configure, optimize, integrate, and troubleshoot, see the Web Security Knowledge Hub.

 Benefits of Mimecast Web Security

      • Features and tools can be easily configured and maintained via the Mimecast Administration Console:
        • Policies are applied consistently, with integration to other features such as Targeted Threat Protection - URL Protect, giving in-depth defense across email and the web. They can also be configured based on location (office/server/gateway IP), groups, or domains.
        • There's no need to deploy a Mimecast certificate to view our block and warning pages for sites using an SSL certificate (https://.)
        • You can view consolidated real-time reporting of web usage and security risks via activity logs and dashboard analytics.
      • Lightweight security at the domain layer stops threats before they reach your network, improving your organization's overall protection.
        • Services and users' devices are protected when on the corporate network
        • Users' devices are protected when roaming or using public Wi-Fi.
        • Mimecast Security Agent can be used by non-domain users.

Considerations

      • Mimecast Web Security supports IPv4 and Dual-stack (IPv4 + IPv6) network configurations. IPv6 single-stack network configurations are currently unsupported.
      • Mimecast Security Agent does not support Man In The Middle (MITM) interceptors. Any attempt to intercept HTTPS traffic from the agent will prevent communication with Mimecast Web Security services. We recommend adding exceptions for this traffic. Refer to the vendor's documentation or support.

Known Incompatibilities

The Mimecast Security Agent (MSA) can coexist with security and VPN products, but some require you to change a specific setting that the Mimecast Security Agent isn't currently compatible with.

Product Details

Malwarebytes Real-Time Web Protection

Mimecast Web Security offers web protection, so you do not need this feature; we recommend turning it off using the following steps:
  1. Open Malwarebytes Premium.
  2. Click on the Settings menu item.
  3. Click on the Protection tab.
  4. Deselect the Web Protection option in the Under Real-Time Protection section.
  5. Click on the Yes button in the User Account Control dialog to confirm your change.

Kaspersky Security Versions

Some older versions of Kaspersky Security may be incompatible with the Mimecast Security Agent. We recommended you use Kaspersky Security v11.3 or higher.

Microsoft Defender Endpoint – Web Filtering

Mimecast Web Security offers web protection, so you do not need this feature; we recommend turning off the following options: 

  1. Web Content Filtering
  2. Custom Network Indicators
  3. Network Protection

Setting for items 1 and 2 can be found in the Advance features section of the Defender console.
For item 3, see Microsoft's Network protection knowledge base page.

McAfee Agent – Firewall Rules

You must configure an exception in the firewall rules in order for the Mimecast Security Agent to work properly. This must include the following:

  1. Application: Container.Runtime.exe
  2. File name or Path: C:\Program Files\ Mimecast\Security Agent\ Container.Runtime.exe
  3. Protocol: UDP, Remote port: 1024-65535

For more information, visit McAfee’s guidance knowledge base page.

SentinelOne – Firewall Control

Due to both solutions inspecting the same data, the Mimecast Security Agent is incompatible with the SentinelOne endpoint Firewall control. For devices that have the Mimecast Security Agent installed, we recommend deactivating this setting, by using the following steps:

  1. In the Management Console, click Network.
  2. Select a Scope: A Site, a Group, or All Sites, for Global Admins.
  3. Click Firewall Control.
  4. Click the Settings icon. 
  5. Click Disable Firewall Control.
Was this article helpful?
1 out of 3 found this helpful

Comments

0 comments

Please sign in to leave a comment.