Hi,
I spent a lovely Fathers' Day Sunday afternoon experimenting with policies.
Sascha has provided screen shots of his policies that seem to work?
The only policy that seems to work for me is a service all type.
I setup a user policy, no traffic at all went through this one.
I setup a Business application policy for web browsing that required servers, that didn't work.
I setup a network policy with http, https, ftp with and without NAT, that didn't work. Enabled all services with NAT (MASQ) and that works.
So, for everything bar mail there is no proxy, all other services require the MASQ or local NAT rule to be configured. I am not sure how this will work with IPv6 where NAT is not a requirement.
Other issues, you cannot determine the policy action order? You can change policies within a policy group, but that is no way of determining which policy has the higher priority in the overall scheme of packet processing.
I have setup mail policies for each of the ISPs that I use for mail but the mail traffic does not appear to be registering in the mail policies but in the network policy. If I setup a generic mail policy that passes all mail, but does not register it, maybe not even scans it (shows in packet count). I know outgoing isn't scanned because my tail message was never appended.
Any guidance will be gratefully accepted.
ian
I am aware of the web proxy settings, but using port 3128 requires a batch file to change the webbrowser on each device, so basically there is no transparent web proxy?