05.08.2013 Views

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Trend</strong> <strong>Micro</strong> <strong>InterScan</strong> <strong>Gateway</strong> <strong>Security</strong> <strong>Appliance</strong> M-<strong>Series</strong> Administrator’s Guide<br />

2-10<br />

The appliance supports two transparent proxy modes (“operation modes”):<br />

• Transparent proxy mode<br />

• Fully transparent proxy mode<br />

The major difference between transparent and fully transparent proxy modes is the<br />

“actual transparency” of the appliance with the destination server. The appliance<br />

creates an independent connection to the destination server. In transparent proxy<br />

mode, the destination server is aware of the IP address of the appliance.<br />

In neither mode can the appliance keep the client’s MAC address when delivering the<br />

request to the server.<br />

Transparent Proxy Mode<br />

<strong>InterScan</strong> <strong>Gateway</strong> <strong>Security</strong> <strong>Appliance</strong> enforces transparency through the following<br />

behavior:<br />

• Clients do not see the presence of additional filters/scanners unless a violation is<br />

detected.<br />

• Administrators do not need any additional configuration on the client side.<br />

• The destination servers still see the appliance IP address as the requestor.<br />

For an illustration of how the appliance processes HTTP, FTP, SMTP, or POP3 traffic<br />

in transparent proxy mode, see the figure below.<br />

Source IP:<br />

10.2.2.23<br />

Server Internet<br />

Source IP:<br />

10.2.2.23<br />

Router<br />

(Default gateway<br />

of <strong>InterScan</strong><br />

appliance)<br />

EXT<br />

port<br />

proxy handlers<br />

10.2.2.23<br />

Operation mode:<br />

Transparent proxy<br />

INT<br />

port<br />

10.2.211.136<br />

FIGURE 2-7. In transparent proxy mode, the client's IP address becomes<br />

that of the appliance<br />

Source IP:<br />

10.2.211.136<br />

Switch<br />

Client

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!