01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Proxies and caching<br />

Network modes 3<br />

Sample configuration – Director and scanning nodes in transparent router mode<br />

This section describes a procedure for setting up two appliances in transparent router mode.<br />

One of them is configured as a director node that directs data packets, the other as a scanning node<br />

that only filters data packets, but does not direct them.<br />

Set up a director node<br />

To configure an appliance as a director node in transparent router mode, you need to enable this mode<br />

and configure network interfaces for inbound and outbound web traffic. The director role is configured<br />

by giving the node an appropriate priority value.<br />

Complete the following procedure to set up a director node:<br />

1 Go to Configuration | Appliances.<br />

2 On the appliances tree, go to the appliance you want to set up as a director node and select Network.<br />

3 Configure network interfaces as is suitable for your network. You need at least one interface for<br />

inbound and one for outbound web traffic.<br />

4 Click Save Changes. You are logged out and logged on to the appliance again.<br />

5 Go to Configuration | Appliances.<br />

6 On the appliances tree, go to the appliance you are setting up as a director node and select Proxies<br />

(HTTP(S), FTP, ICAP, and IM).<br />

7 Under Network Setup, select Transparent Router.<br />

Note: After selecting this mode, specific Transparent Router settings appear below the Network Setup<br />

settings.<br />

8 Set Director priority to a value > 0.<br />

9 Configure proxy ports and port redirects for HTTP and FTP as needed.<br />

10 Configure virtual IP addresses for the inbound and outbound network interfaces, using free IP<br />

addresses for this purpose.<br />

11 In the Management IP field, type an IP address for reaching the scanning node.<br />

12 Leave the number under Virtual router ID as it is.<br />

13 From the VRRP interface list, select the interfaces for heartbeats under this protocol.<br />

14 Configure IP spoofing as needed.<br />

15 Click Save Changes.<br />

16 Configure the clients of your network to let them direct their web traffic to the virtual IP addresses<br />

you configured for the inbound network interfaces.<br />

If you are going to configure another appliance as a director node, be sure to configure the same virtual<br />

IP addresses as for the initial director node. The proxy ports and port redirects and the order of the port<br />

redirects must also be the same as for that node.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 51

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!