Thanks for the quick answer [:)] So how should the rule look like for a transparent http proxy? Is the attached config OK? "WebSurfing" Servis type includes http/https definitions.
Ok, setting the traffic source to "External İnterface ip" did the trick [:)] It seems Web proxy has a higer priority over SNAT so setting traffic source to "Local interface" has no effect.
But will it has any side effects? Is it safe to use External ip as source network in SNAT rules?
You have the correct SNAT rule now using Scott's suggestion.
One fundamental rule is that SNAT is the last thing that happens before a packet leaves an interface. A key rule for inbound traffic is: a DNAT handles traffic before it's seen by a proxy and a proxy handles traffic before the traffic can be considered by manual routes and packet filter rules.
Cheers - Bob
Sophos UTM Community Moderator Sophos Certified Architect - UTM Sophos Certified Engineer - XG Gold Solution Partner since 2005