This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web proxy bypass web filtering.

I configured Web proxy on XG firewall and change the port to 8080.  my question is why the client computer bypass all web filtering policy and access prohibited site when I apply proxy to their browser? Thanks for response.

 



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Toni,

    that document is a little confusing when comparing to the UTM, the UTM proxy does not use MASQ.

    Also the document in my mind is a little unclear when you use both modes you need to use a MASQ which sort of defeats the proxy function?

    When using mixed mode there is no indication in the document as to where the policies for the direct mode are configured.

    Ian

     

    Sorted the policy thing out, still leaves the requirement of the MASQ in question?

  • In fact, UTM Proxy, like XG, uses MASQ per default. 

    Because the Traffic is generated by UTM itself, it most likely uses the Interface IP of the Gateway Interface. 

    There are no "Direct Mode Policy".

    Its like on UTM - If you use Transparent Mode in UTM, UTM will respond to 8080. (Its not well known, but its how it works).

    And XG does the same. You configure the Proxy, and it will respond to 8080, 443 and 80. 

     

    You will have to create a Firewall Policy with Port 8080 to attach the correct web policy. 

  • I knew about the 8080 on the UTM, I had played with that for many years. I was not aware of the MASQ and most experts do not appear to know either.

    I don't use the 8080 on the XG, but traffic seems to flow through all the appropriate policies.

    Currently playing with the direct proxy to see if there any benefits, but suspect there aren't because I have to disable those settings when out of home.

    Ian

     

    Update:- setup a new firewall rule using tcp 3128 and no MASQ and it successfully passes traffic.