Virtual Secure Web Gateway

 View Only
Expand all | Collapse all

Proxy on Web gateway

Migration User

Migration UserDec 21, 2011 09:38 AM

  • 1.  Proxy on Web gateway

    Posted Dec 14, 2011 11:50 PM

    hi guys,

    we have a symantec web gateway for content filtering.  we  are trying to set it up to be used as proxy also.  there are not too many tutorials on the internet.   we are having problem to set it up.  can anybody help please

     

    thanks



  • 2.  RE: Proxy on Web gateway

    Posted Dec 15, 2011 04:53 AM

    Can you give some detail on the problems you are having? Is it a physical or virtual appliance you are setting up?  Have you read through the Administration Guide and do you have any questions based on what you've read?  It's just hard to help when you haven't really given any details as to what your problem is.

    Cheers,

    Kevin



  • 3.  RE: Proxy on Web gateway

    Posted Dec 15, 2011 03:57 PM
      |   view attached

    I have attached the product manual which should help you with the process of configuring and using the Symantec Web Gateway.

    If you come up with any specific questions please feel free to post them.



  • 4.  RE: Proxy on Web gateway

    Posted Dec 19, 2011 01:45 AM
      |   view attached

    Thank you very much for your reply.

    i have gone through the administration guide but it is not of much help.

    in fact my problem is that i have followed the instruction manual, but unable to set up the proxy.

    It is a physical web gateway. 

    i am attaching the topology of my network and the position of the web gateway.

    thank a lot for your support

     

     

    Attachment(s)

    pdf
    Network topology.pdf   75 KB 1 version


  • 5.  RE: Proxy on Web gateway

    Posted Dec 19, 2011 01:46 AM
      |   view attached

    thank you very much.

    Please find attached my network topology.  the documentation is not of great help

     

    Attachment(s)

    pdf
    Network topology_0.pdf   75 KB 1 version


  • 6.  RE: Proxy on Web gateway

    Posted Dec 19, 2011 09:26 AM

    Are you having a specific problem? So far you havent asked for anything other than help, but without specific questions we won't be able to provide any guidance.



  • 7.  RE: Proxy on Web gateway

    Posted Dec 19, 2011 11:35 PM

    in fact we have tried to follow the documentation but was unable to make it work.

    what must be the ip the management port and the lan port.  i have tried to put some ip but my content filtering was not working and had to revert back.

    if my network address is 192.9.200.0/24 what must be the ip of my lan port and management port.

     

     



  • 8.  RE: Proxy on Web gateway

    Posted Dec 20, 2011 09:34 AM

    Are you using an applaince or a virtual edition of the SWG?

    If you can access the console of the SWG. You can find the Management port IP via the menu option 3 - Display Current IP. So long as the system you are working on is on the same network you should be able to access the SWG UI via that IP address.



  • 9.  RE: Proxy on Web gateway

    Posted Dec 20, 2011 11:23 AM

    ...as it says in the SWG documentation, in order to enable proxy mode, you must first enable the option under Configuration -> Network to 'Separate Inline and Management NICs".  A further requirement of this is that the two interfaces cannot reside in the same subnet, so you'll have to do some fiddling to ensure both are accessible...

    Once these have been separated, you'd then need to change the operation mode to Inline+Proxy, as your diagram suggest it is currently implemeted Inline.

    Now that the SWG is in proxy mode, additional options are now available under the Configuration -> Proxy tab for controlling the proxy options.  Once setup, it should be a simple matter of pointing a browser at the SWG's LAN interface IP address, to start utilising the proxy.

    This is a simplified overview of how to set up proxy mode.  More info is in the documentation wink



  • 10.  RE: Proxy on Web gateway

    Posted Dec 21, 2011 12:27 AM

    are you saying that my lan port should be on the network address 192.9.220.0/24 and management port on a different subnet?



  • 11.  RE: Proxy on Web gateway

    Posted Dec 21, 2011 03:34 AM

    ...is addressible by the users' browsers, and can route out to the internet, then yeah.



  • 12.  RE: Proxy on Web gateway

    Posted Dec 21, 2011 09:38 AM

    This is also covered in the manual.



  • 13.  RE: Proxy on Web gateway

    Posted Dec 26, 2011 05:55 AM

    hi

    i have completed the installation .  when setting up my browser for using proxy, i am getting the messages

     

    The requested URL could not be retrieved


    While trying to retrieve the URL: http://www.bbc.co.uk/news/world-europe-16265665

    The following error was encountered:

    Unable to determine IP address from host name for www.bbc.co.uk

    The DNS server returned:

    Timeout

    This means that:

     The proxy was not able to resolve the hostname presented in the URL. 
     Check if the address is correct. 
    

    test

     



  • 14.  RE: Proxy on Web gateway

    Posted Dec 27, 2011 06:16 AM

    hi i have completed the

    hi

    i have completed the installation .  when setting up my browser for using proxy, i am getting the messages

     

    The requested URL could not be retrieved

    While trying to retrieve the URL: http://www.bbc.co.uk/news/world-europe-16265665

    The following error was encountered:

    Unable to determine IP address from host name for www.bbc.co.uk

    The DNS server returned:

    Timeout

    This means that:

     The proxy was not able to resolve the hostname presented in the URL. 
     Check if the address is correct. 
    

    test



  • 15.  RE: Proxy on Web gateway

    Posted Jan 03, 2012 09:27 AM

    Set a client to use the same DNS server(s) as SWG then test try an NS lookup from the client.



  • 16.  RE: Proxy on Web gateway

    Posted Jan 05, 2012 11:43 PM

    my client and the dns server of the SWG are the same.  i have try nslookup and is fine.



  • 17.  RE: Proxy on Web gateway

    Posted Jan 26, 2012 12:39 AM

    hi guys,

     

    please help...still not working..i need to make it work urgently



  • 18.  RE: Proxy on Web gateway

    Posted Jan 26, 2012 10:05 AM

    Can the SWG reach threatcneter? This test can be found in Adminstration -> configuration -> Network. There is a test connection to threat center.

    If not you have a networking issue that prevents it from connecting to the internet.



  • 19.  RE: Proxy on Web gateway

    Posted Jan 27, 2012 02:13 AM

    i cannot connect to the threat center or perform an update but the Content Filter Version has been updated

    Content Filter Version 5.32060 (installed at 01/26/12 12:34:28)



  • 20.  RE: Proxy on Web gateway

    Posted Jan 27, 2012 12:35 PM

    LAN and Management port should have connection to the internet. is the SWG able to ping sites such as google.com with the lan and management ports?



  • 21.  RE: Proxy on Web gateway

    Posted Jan 30, 2012 01:06 AM

    Now i am able to get update.

    Something is not clear.is the web gateway in the inline + proxy mode work as proxy server?



  • 22.  RE: Proxy on Web gateway

    Posted Jan 30, 2012 01:52 AM

    do i need to configure my asa to allow the mgtm port to get access to the internet.have you seen the network topology?

    my current config is

     

    inline ip address : 192.9.227.202

    inline gateway : 192.9.227.125

     

    mgmt ip address : 192.9.200.202

    mgmt gateway : 192.9.200.125

    all my pcs are in the subnet 192.9.227.x

     

    with the above config i test connection to symantec threat center unsuccessfully

     

    but last week we swap both set of addresses that is

    inline ip address : 192.9.200.202

    inline gateway : 192.9.200.125

     

    mgmt ip address : 192.9.127.202

    mgmt gateway : 192.9.127.125

    and we could test the sym. threat center. successfully

     

    i am quite confused now



  • 23.  RE: Proxy on Web gateway

    Posted Jan 30, 2012 03:52 AM

    What operating mode do you have the SWG configured in?  If using "Inline+Proxy" can you confirm what you have the WAN port connected to?



  • 24.  RE: Proxy on Web gateway

    Posted Jan 30, 2012 04:36 AM
      |   view attached

    THANKS

    --iNLINE + pROXY

     

    --CURRENTLY WAN IS CONNECTED TO AN ASA. - 192.9.227.125

     

    INLINE IP - 192.9.227.202

    INLINE GATEWAY - 192.9.227.125

     

    MGT IP 192.9.200.202

    MGT GATEWAY - 192.9.200.125 (NOT SURE WHAT TO PUT)

     

    I AM NOT ABLE TO CONNECT TO THE THREAT CENTER...

    WHEN CONFIGURING THE WEB BROWSER I AM NOT CONNECT TO ANY WEB SITE ..FOLLOWING MESSAGES

     

     

    The requested URL could not be retrieved


    While trying to retrieve the URL: http://www.defimedia.info/

    The following error was encountered:

    Unable to determine IP address from host name for www.defimedia.info

    The DNS server returned:

    Timeout

    This means that:

     The proxy was not able to resolve the hostname presented in the URL. 
     Check if the address is correct. 
    
    test

     

    PLEASE FIND ATTACHED NETWORK TOPOLOGY

    Attachment(s)

    pdf
    Network topology_1.pdf   75 KB 1 version


  • 25.  RE: Proxy on Web gateway

    Posted Jan 30, 2012 06:49 AM

    Can you advise what IP addresses you're using for the DNS Servers and confirm if they can be contacted by both the Inline and MGMT interfaces.

    Oh, and please review the below article on the requirements behind the 'separate managment and inline interfaces' option:

    http://www.symantec.com/docs/TECH158913



  • 26.  RE: Proxy on Web gateway

    Posted Jan 30, 2012 09:28 AM

    This would indicate you have something with your network configuration you must resolve. We can tell you what we need but not how to configure your network. Both ports Management and Inline should be able to access the internet.