This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Transparent Mode Skiplist Questions

I'm working with an SG330 running UTM 9.405-5

Web Protection>Filtering Options>Misc Tab>Transparent Mode Skiplist

I have created two group definitions:

SOURCE-SKIP-PROXY > added to Skip Transparent Mode Source Hosts/Nets

DEST-SKIP-PROXY > added to Skip Transparent Mode Destination Hosts/Nets

 Questions:

1.  When I use Web Protection>Policy Helpdesk>Policy Test, does it consider the Skiplist?  it does not seem to do so.

2.  Do I also require Firewall Rules to permit packets for the Hosts/Nets defined in the Transparent Mode Skiplist?

 

Thank you!



This thread was automatically locked due to age.
  • Hi Kris,

    When you add a Skiplist irrespective of source or the destination, it will not be reflected as allowed in the policy helpdesk test output. You need to look into the http.log for this information.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • 1) No it does not.

    2) No you do not.

    Normally when you turn on the Web Filter it creates a hidden firewall rule that says any incoming packet on port 80 should be redirected to the web proxy.  The web proxy then handles it.

    When you do a skiplist it puts another hidden firewall rule above that which says for this given src/dst if there is an incoming packet on port 80 just let it through.

  • Very good, thank you Michael!

    ____________________________
    Kris Jacobs
    Network Administrator
    Calhoun County IT Department
    Battle Creek, Michigan   USA