Should I place my Web Proxy behind or in front of my firewall?

We are getting ready to implement a new BlueCoat SG-250 web proxy appliance on our network, but I'm not sure of the best place to put it in relation to my firewall.  One of the network admins in my shop thinks that we should connect it to an additional interface on our perimeter router which is just in front of the firewall.  We can then configure WCCP on the router to pass web traffic to the proxy and eliminate an "inline" configuration that would cause users not to be able to surf the net in case the proxy was down.

However, we can accomplish the same with the Cisco ASA firewall that we have in place that supports WCCP as well.  My thinking is that we can connect it to one of the DMZ interfaces and use WCCP to accomplish the same thing.

Another one of network admins in the shop suggested connecting it to the core switch and using WCCP there, with the idea that you can eliminate a lot of traffic hitting the perimeter router and firewall.

Any opinions as the best and most secure way of implementing a proxy in this environment?

Thanks
jmoney68Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

grbladesCommented:
Connecting it to the outside interface is not a good idea. If it has a vulnerability then in theory an attacker can redirect people or serve up malware.

I would say putting it on the internal interface is the best approach. It only makes outbound connections so the DMZ is not the perfect place for it unless it will be the only device in that DMZ. As you can use WCCP on the core switch that seems the ideal solution.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jmoney68Author Commented:
Thanks!!!!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.