18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Implementation options for Web access<br />

Figure 12-4. Option 1:<br />

The HTTP proxy passes<br />

all Web traffic<br />

12-4 Setting Up Web Services<br />

Option 1: HTTP proxy passes all Web traffic<br />

Option 1 depicts a scenario in which the HTTP (or HTTPS) proxy<br />

regulates Web traffic moving between all burbs on the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

Using the appropriate Web Application Defenses within your HTTP/<br />

HTTPS proxy rules, you can configure URL properties, perform<br />

request and reply header filtering, perform MIME/anti-virus filtering,<br />

and deny certain types <strong>of</strong> Web content. You can also configure<br />

whether allowed connections can be transparent, non-transparent, or<br />

both. If you configure transparent HTTP, it will appear to a user that<br />

they are connecting directly to Web server rather than connecting to<br />

the <strong>Sidewinder</strong> <strong>G2</strong> first. The HTTPS proxy also allows you perform<br />

SSL decryption. Figure 12-4 illustrates the HTTP proxy regulating all<br />

Web traffic.<br />

internal user<br />

internal<br />

Web site<br />

Web server<br />

DMZ burb<br />

HTTP proxy<br />

Internet<br />

internal network external network<br />

Option 2: Web proxy server regulates all Web traffic<br />

external user<br />

Web server<br />

Web site<br />

In Option 2, the Web proxy server regulates Web traffic between all<br />

burbs. This option is generally used in larger companies that have<br />

security policies about how employees can use the Web. The Web<br />

proxy server is the best option if you want to provide caching and<br />

SmartFilter services on the <strong>Sidewinder</strong> <strong>G2</strong>. In general, caching does<br />

not apply to Internet users that access a Web site on your internal<br />

network. (Option 3 illustrates a more likely scenarios for using the<br />

caching feature.)<br />

Note: For more information on using the Web proxy server, refer to “Using the Web proxy<br />

server” on page 12-10.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!