This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web filtering for remote site

hello,
I have a question regarding enabling web filtering for a remote site. It is connected via a site-2-site vpn tunnel. This tunnel is not part of the astaro appliance. Here is the network setup:
Main Office: 10.10.1.X network
Remote Office: 10.10.10.X network
Connected via site-2-site vpn tunnel using sonicwall firewall

At the main office, I have installed astaro appliance and web filtering is working just fine.

I want web filtering to be enabled for the remote office users, without having to rework the tunnel to route through astaro appliance.

Any help would be greatly appreciated.
Thanks!


This thread was automatically locked due to age.
Parents
  • Not sure why you would want to keep that Sonicwall... [;)]

    Can we assume that all of the Remote Office traffic comes through the tunnel - that it's not a split tunnel?  If so, then you'll need a policy route in the Sonicwall to redirect traffic to the Astaro.

    If you're in "Transparent" mode, you only need to redirect port-80 traffic to the Astaro.  If you're in a non-transparent mode, you'll want all of the ports that are identified in 'Allowed target services' on the 'Advanced' tab of HTTP/S.

    Cheers -Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Not sure why you would want to keep that Sonicwall... [;)]

    Can we assume that all of the Remote Office traffic comes through the tunnel - that it's not a split tunnel?  If so, then you'll need a policy route in the Sonicwall to redirect traffic to the Astaro.

    If you're in "Transparent" mode, you only need to redirect port-80 traffic to the Astaro.  If you're in a non-transparent mode, you'll want all of the ports that are identified in 'Allowed target services' on the 'Advanced' tab of HTTP/S.

    Cheers -Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data