01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3<br />

Proxies and caching<br />

Reverse HTTPS proxy configuration<br />

Reverse HTTPS proxy configuration<br />

You can use a reverse HTTPS proxy configuration to prevent clients from uploading unwanted data,<br />

such as malware or particular media types, to particular web servers under the HTTPS protocol. This<br />

section explains such a configuration and tells you how to set it up.<br />

In a reverse HTTPS proxy configuration, HTTPS traffic is redirected to the appliance, which serves as a<br />

proxy that inspects the traffic and eventually forwards or blocks it, according to the rules that are<br />

implemented.<br />

You can configure this in the following ways:<br />

• A transparent bridge or router configuration<br />

• A DNS configuration that points directly to the appliance when access to a particular web server is<br />

requested<br />

Note: The redirection to the appliance can also be achieved by configuring proxy-aware connections relying<br />

on the use of CONNECT headers.<br />

However, this method would require an additional network device to assemble these headers for incoming<br />

requests, so it is not recommended and further explained here.<br />

In addition to configuring your network in one of these ways, you need to configure the handling of SSL<br />

certificates. Optionally, you can configure some additional settings that are not SSL-related to ensure a<br />

smooth operation of the reverse HTTPS proxy configuration.<br />

Redirect HTTPS traffic in a transparent bridge or router configuration<br />

In a transparent bridge or router configuration, you can use a port redirect rule to direct HTTPS traffic<br />

to the proxy port on the appliance.<br />

Note: The term port forwarding rule is also used for a port redirect rule.<br />

Furthermore, you need to ensure that the redirected requests are treated as SSL-secured<br />

communication.<br />

1 Go to Configuration | Appliances.<br />

2 On the appliances tree, go to the appliance you want to redirect traffic to and select Proxies<br />

(HTTP(S), FTP, ICAP, and IM).<br />

3 In the Network Setup section, select Transparent bridge (or Transparent router). The section<br />

with the transparent bridge (or router) settings appears.<br />

4 Under Port redirects, click Add. The Add Port Redirects window opens.<br />

5 Configure the following for the new port redirect rule:<br />

• Protocol name — http<br />

Note: This setting covers connections under both the HTTP and HTTPS protocols.<br />

• Original destination ports — 443<br />

Note: If the web servers that are the destinations for requests can be reached under the HTTP protocol<br />

as well, you can add port 80 here (separated by a comma). This type of traffic is then also directed to<br />

the appliance.<br />

• Destination proxy port — 9090<br />

Note: This is by default the proxy port on the appliance.<br />

6 Click OK. The window closes and the new port redirect rule is added to the list.<br />

7 Under HTTP proxy port, make sure Enable HTTP proxy is selected and click Add. The Add HTTP<br />

Proxy Port window opens.<br />

60 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!