Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What is Proxied, Via: HTTP/1.1 sophos.http.proxy:3128

I am troubleshooting the streaming issue with HTTP malware scanning enabled and noticed this which I do not see in UTM 9.  Still need to keep HTTP malware checks off when using XG.  Testing before I switch from UTM 9 to XG.  On UTM 9 I do not see the proxy listed on sites I go to such as http://test-ipv6.com/ .  I see the setting in XG however I have it unchecked under Routing - Upstream Proxy (both IP settings off).  What component of XG uses this proxy?  Does this mean all traffic from my LAN goes through a XG host before the Internet destination?  Can it be disabled?   

XG will be a good move forward once the bugs are minimized but still has some issues to deal with.  Any info would be good.  Thanks.



This thread was automatically locked due to age.
Parents
  • Hi Mike,

    As when we apply any web filter policy or any http/s scanning or both then XG works as an transparent proxy.

    If you do not want to show that "this is the proxied connection" then you can disable it via below commands. By default it is enabled.

    console> set http_proxy add_via_header off

    Hope this answer will help you. [:)]

    Regards,

    Vishal Patel

  • Thanks for the info.  Looks like the proxy will remain on based on the features I intend to use once they get them working where the malware filters do not kill the streams.  Just need to note that the server will always show in the traceroute.  Odd that I am connecting to HTTPS streams but the proxy is HTTP.  I assume after the initial connection the proxy is no longer involved.  Thanks.

Reply
  • Thanks for the info.  Looks like the proxy will remain on based on the features I intend to use once they get them working where the malware filters do not kill the streams.  Just need to note that the server will always show in the traceroute.  Odd that I am connecting to HTTPS streams but the proxy is HTTP.  I assume after the initial connection the proxy is no longer involved.  Thanks.

Children
No Data