I have a normal internal network working through the HTTP Proxy service to get the security goodies etc. I have been asked to set up a second network as a form of DMZ allowing users in this network to have the same level of security, but no access to the main internal one.
I have set a filter to the top of the list which is DMZ to Internal drop all services.
The HTTP Proxy is in transparent mode, as we don't yet authenticate, and the DMZ users will never. Both are permitted in the proxy.
This is working OK with one exception, and that is the HTTP Proxy allows port 80 traffic from the DMZ to the Internal network. The packet filter is not effective.
I don't have any other filters set on port 80, so I am baffled.
Running V7.011 on an ASG220.
Anyone show me the errors of my ways?
Dave P
This thread was automatically locked due to age.