?
Solved

Sophos Web Appliance and Cisco ASA5512

Posted on 2013-11-01
2
Medium Priority
?
549 Views
Last Modified: 2016-02-25
Good day all,

I have a problem in that I've recently purchased a sophos WS100 web filtering appliance. At present, just to make it work I've got all domain users pointing their default gateway at the sophos device. This is fine for HTTP & HTTPS traffic, but any non web ports immediately get blocked as the sophos device doesn't recognise them.

Could anyone advise me on the best way without using explicit proxy to make this work? Also please understand I don't understand the cisco CLI - I'm using the GUI ASDM interface to control it.

Many thanks...
0
Comment
Question by:CDA_Administrator
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 1500 total points
ID: 39623638
You could do a bridged deployment of the appliance. From the Sophos config guide:

Bridged Deployment: All outbound network traffic is routed through the Web Appliance's bridge card, but only port 80 and port 443 traffic is examined. This deployment requires the optional bridge card included with some appliance models. With a Bridged Deployment, network traffic continues to flow in the event of an appliance failure.

That way you only need to configure the appliance, but as stated you'll need a bridge card for that (not sure if you have one).
0
 

Author Closing Comment

by:CDA_Administrator
ID: 39701635
I did manage to get it working via WCCP - however your solution would have don it too, thanks!
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question