• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 251
  • Last Modified:

Networking Question - Web Browsing

Hi,

We have an older network (please don't say it, i been pushing to upgrade it for years) consisting of 6 sites, 5 branches and 1 Head Office.

All the branches are meshed to the head office network via permanent VPN's (handled by Cisco PIX's). The branch sites do not have IP access to directly connect out to the internetand must pass through the head office network to where a proxy server and content management appliance resides. Each PC has the Proxy configuration set and it all works well.

Question is, i want to pull out the proxy server and put a new Sonicwall UTM solution between the PIX and network but to do this i will need to turn off the proxy settings in the browsers as no proxy servers will exist. The trouble is when doing this the browsers do not connect to the internet and do not seem to route through the head office network and back out the internet.

They seem to want to use the gateway of the branch router/PIX to which has rules to prevent access directly out through the Internet but i want the http traffic to flow through the head office network and through the UTM.

Hope that makes sense?
0
tmaster100
Asked:
tmaster100
2 Solutions
 
karllangstonCommented:
you should be able to create a route on the branch PIX that tells http and https traffic to go via the IP of the sonicwall at head office
0
 
jhyieslaCommented:
I'm not familiar with that specific product, but many security appliances will allow you to run them in some mode where you can specify it's IP address in the proxy settings of IE.

For example, we use an iPrism web appliance device that sits between our LAN and the firewall. It's set to pass thru mode so that users at our main facility can just point to the Internet and go; no proxy settings.  But it also has an IP and for users on remote network who get their Internet access through our main facility, we can set the IP address and port of the device in their IE settings and it works fine.

You might check with the company to see if that functionality exists.
0
 
mwiener1Commented:
Cant you just give the pix a static route for http/s to the main office gateway and set an access list to allow it to happen?
0
 
tmaster100Author Commented:
I will give that a go.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now