This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Filtering Transparent Mode - Best Practice

We have an SG310 and we have implemented Transparent Mode web filtering. When everything works well, users on the network can browse to safe websites. But occasionally the Sophos will block them from visiting a site that they have used before (and that we have deemed safe). As a workaround, we tell the user to browse to any non-https site, and then try again and this usually fixes the problem.

How/Why does this work as a quick fix? What's happening when the user goes to an http site (vs https)?

Is there a more elegant way to resolve these occasional authentication issues? And while we are on this topic, it looks like this just does not work for our Mac users. The Mac users end up enabling Wi-Fi on their Macs so that they can browse the Internet. Having that turned on in addition to the Ethernet on the corporate LAN causes weirdness.

Just wondering what's best practice for implementing Transparent Mode.

We tried using the standard proxy mode, but this quickly became a headache because every software app on the network that needed internet access had to be configured to point to the proxy server. (For example, UPS WorldShip or FedEx Ship Manager). This, plus our corporate policy that forces users to change their password every 90 days caused a lot of IT headaches. So I guess I am looking for the best of both worlds - a proxy but none of the manual work of using a proxy, and none of the glitches in transparent proxy.



This thread was automatically locked due to age.
Parents
  • Also, you might want to consult a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, PM me your email address.  I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.

    With a little practice, the Web Filtering log is easy to search and will tell you why a particular person/device had a problem with a particular site.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Also, you might want to consult a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, PM me your email address.  I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.

    With a little practice, the Web Filtering log is easy to search and will tell you why a particular person/device had a problem with a particular site.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children