This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

HTTP Proxy not performing as per manual

The configuration is
HTTP proxy in "standard" mode with anonimity = none
Cobion enabled
block connect method enabled
filter rules = ntp and all ports above 1024 only
masq internal network to external interface

Manual says proxy in standard mode and users in access list need "use proxy" on port 8080 in PC (eg internet explorer)

Remove proxy info from PC
what happens is
1/. www access works
2/. no scanning or download manager (not good)
3/. access works faster
4/. sites that don't work through the proxy when specified work okay eg I can download.
5/. The PC download information shows progressive collection details

Why does the www still work?

Do I need to reduce the general packet range allowed out?

Do I dis-able "block connect method"?

Without continually configuring the kids PCs everytime the rebuild them about once a week (game problems), how do I ensure that the proxy works correctly?

Ian M


This thread was automatically locked due to age.
Parents
  • It's pretty simple.. and it's not a "manual" thing.  It seems you are allowing port 80 (http) outbound via a packet filter.  The way we normally deploy this product, we turn off outbound port 80, and point the clients (using the proxy settings) at the Astaro.. you can also configure the HTTP Proxy for "transparent" mode, which WILL intercept outbound port 80 traffic.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • It's pretty simple.. and it's not a "manual" thing.  It seems you are allowing port 80 (http) outbound via a packet filter.  The way we normally deploy this product, we turn off outbound port 80, and point the clients (using the proxy settings) at the Astaro.. you can also configure the HTTP Proxy for "transparent" mode, which WILL intercept outbound port 80 traffic.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data