Quick overview of our set up.
We have multiple sites with their own XGs (SFOS 17.1.1 MR1). Each site XG is in Bridge mode. Each site is connected to the WAN via a router. An Upstream Proxy (Parent Proxy) (hosted on the WAN) is required to access the internet.
Internet > (Upstream Proxy) > WAN > (many sites) Router > XG > LAN
Internet > (Upstream Proxy) > WAN are shared amongst all sites.
We have the Upstream Proxy configured under Routing.
We have some sites and services hosted on the WAN that require us to NOT use the Upstream Proxy.
A Firewall Rule with a Web Policy specified allows internet access through the Upstream Proxy.
A Firewall Rule without a Web Policy does not allow internet access even if the Firewall Rule explicitly specifies allowed domains/Internet IPs etc.
The Upstream Proxy only seems to be used when the Internet is accessed through a Web Policy. A Firewall Rule, without a Web Policy, does not appear to use the Upstream Proxy. Is this the expected behavior?
Do Web Exceptions bypass the Upstream Proxy or only the selected features to bypass (HTTPS, Malware scanning etc)?
Cheers,
Ben
This thread was automatically locked due to age.