01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8 Make sure the following is configured:<br />

• Serve transparent SSL connections — Selected<br />

• Ports treated as SSL — 443<br />

Proxies and caching<br />

Reverse HTTPS proxy configuration 3<br />

9 Leave the other settings at their default values and click OK. The window closes and an appropriately<br />

configured HTTP proxy port is added to the list.<br />

10 Click Save Changes.<br />

For more information on setting up a transparent bridge or router configuration, see Transparent bridge<br />

mode and Transparent router mode.<br />

Let the appliance listen to requests redirected by DNS entries<br />

When web server requests under the HTTPS protocol are redirected to the appliance according to DNS<br />

entries, you can configure the appliance as a proxy that listens directly on the appropriate port. You<br />

also need to ensure that only SSL-secured connections are served.<br />

Note: A port redirect rule cannot be applied here since its purpose would be forwarding requests for other<br />

destinations to the appliance. However, due to the DNS entries, the appliance is already the destination.<br />

Before you begin to configure the appliance in this way, make sure of the following:<br />

• The host names of the web servers are not resolved to the appliance when the appliance does a DNS<br />

lookup.<br />

You can achieve this by entering the IP adresses of the web servers into the /etc/hosts file on the<br />

appliance or by using an appropriately configured internal DNS server.<br />

• A rule set that handles content inspection is implemented on the appliance and enabled.<br />

This rule set is typically provided as part of an overall SSL Scanner rule set under the default rule<br />

set system, as well as in the rule set library.<br />

To let the appliance listen to the redirected requests:<br />

1 Go to Configuration | Appliances.<br />

2 On the appliances tree, go to the appliance that should listen to requests and select Proxies<br />

(HTTP(S), FTP, ICAP, and IM).<br />

3 Under HTTP proxy port, make sure Enable HTTP proxy is selected and click Add. The Add HTTP<br />

Proxy Port window opens.<br />

4 Configure the following settings:<br />

• Listener address — 0.0.0.0:443<br />

This setting lets the appliance listen to requests for any web servers, regardless of their IP<br />

addresses. You can also specify a particular IP address here and restrict the appliance to<br />

listening for requests to the server in question.<br />

If you are running several network interface cards on your appliance, you can specify IP<br />

addresses (separated by commas) for as many web servers as there are network interface<br />

cards.<br />

• Serve transparent SSL connections — Selected<br />

• Ports treated as SSL — *<br />

5 Leave the other settings at their default values and click OK. The window closes and an appropriately<br />

configured HTTP proxy port is added to the list.<br />

Note: If a web server should also be accessible under the HTTP protocol, you need to add another HTTP<br />

proxy port with listener address 0.0.0.0:80 or the address of a particular web server.<br />

6 Click Save Changes.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 61

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!