Another restrict action, Passphrase can be used to restrict the web access instead of just blocking it. Once the Passphrase action has been selected, the user will be redirected to a passphrase page when attempting to access the specified website. From this page, the user will need to enter the preset password to continue to the intended site.
If the password is correct, web access will be allowed. Otherwise it will be blocked and a blocked page will be sent to the client.
If the user didn't enter the correct password the first time, the passphrase page will be sent to the client again to prompt for thepassword a second time. Currently, client users have three opportunities to enter their passwords, meaning that if a user makes three failed attempts to enter the correct password, the site will be blocked.
If client users don't know the password, they can click 'Cancel'Â and the site will be blocked immediately.
The Passphrase action can be applied to the Web category, URI Lists, or both. For HTTPS websites, Client DPI-SSL must be enabled to apply Passphrase. We would need to perform the following steps for this setup.
EXAMPLE:Â We would like to allow access to Web categories: News and Media, Search Engines and Portals, and allow access to the websites: monster.com and indeed.com only if the right passphrase is entered.
Steps:
Creating a Decryption Policy:
Decryption policy matches the traffic, and the only two actions we can take are Decrypt and Bypass. With decryption, we get more visibility to the data helping us in performing better matches and applying the right security policy.



Creating a Security Policy
Security Policy ties together the URI list object, Web category and Security Rule Action so that we know what action needs to be taken for a specific match. Before an HTTP/HTTPS connection can be made, the end machine would need to perform DNS resolution of the URL. Since we have an implicit deny rule, DNS traffic needs to be allowed as well.
To create the DNS-related Security Policy:


Â
NOTE:This policy can also be created using the DNS protocol application signature, but this example is configured using the services.
To create the passphrase action to allow websites and web categories related Security Policy








While visiting websites like indeed.com or monster.com, You can enter the password to continue or hit cancel, which will automatically block the page.

Users will have three chances to enter the right password. If all three enteries are incorrect, the user is blocked automatically.
