This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Client does not use WebProtection feature although transparent proxy for network is active

Hi folks,

 

as already in the subject described, i've got a client that uses a ftp connection to an external ip (TCP 21) and the network is listed within the networks for the transparent proxy that also services for FTP service. Unfortunately all clients in this network try to go to this external ip through "Network Firewall". There is also no skip list so i just don't get why the proxy for FTP is not working. Any ideas?



This thread was automatically locked due to age.
Parents
  • I think the problem may be hidden in this statement:

    ...for the transparent proxy that also services for FTP service...

    The transparent FTP proxy is separate from the web proxy profiles.

    It is configured here:

    Web Protection... FTP...

    • The Global tab is used to specify its own Allowed Networks list, and to specify whether to use Standard or Transparent mode.   Note that there is effectively only one profile, represented by the Global tab alone, because there is only one Allowed Networks list.
    • The Advanced tab is used to configure the Allowed Destinations list as well as its Skip List

    So for the proxy to activate, your client IP has to be in this Allowed Networks List on the Global tab.   

    Once activated:

    • For traffic to be allowed with proxy, the destination IP has to be in the Allowed Servers list on the Advanced tab.
    • For traffic to be allowed without proxy, you can either remove the source IP from the Allowed Networks list on the Global tab, or add the server to the Skip List on the Advanced tab.

    Hope this helps.

Reply
  • I think the problem may be hidden in this statement:

    ...for the transparent proxy that also services for FTP service...

    The transparent FTP proxy is separate from the web proxy profiles.

    It is configured here:

    Web Protection... FTP...

    • The Global tab is used to specify its own Allowed Networks list, and to specify whether to use Standard or Transparent mode.   Note that there is effectively only one profile, represented by the Global tab alone, because there is only one Allowed Networks list.
    • The Advanced tab is used to configure the Allowed Destinations list as well as its Skip List

    So for the proxy to activate, your client IP has to be in this Allowed Networks List on the Global tab.   

    Once activated:

    • For traffic to be allowed with proxy, the destination IP has to be in the Allowed Servers list on the Advanced tab.
    • For traffic to be allowed without proxy, you can either remove the source IP from the Allowed Networks list on the Global tab, or add the server to the Skip List on the Advanced tab.

    Hope this helps.

Children
No Data