Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Sophos Web Appliance and Cisco ASA5512

Posted on 2013-11-01
2
Medium Priority
?
555 Views
Last Modified: 2016-02-25
Good day all,

I have a problem in that I've recently purchased a sophos WS100 web filtering appliance. At present, just to make it work I've got all domain users pointing their default gateway at the sophos device. This is fine for HTTP & HTTPS traffic, but any non web ports immediately get blocked as the sophos device doesn't recognise them.

Could anyone advise me on the best way without using explicit proxy to make this work? Also please understand I don't understand the cisco CLI - I'm using the GUI ASDM interface to control it.

Many thanks...
0
Comment
Question by:CDA_Administrator
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 1500 total points
ID: 39623638
You could do a bridged deployment of the appliance. From the Sophos config guide:

Bridged Deployment: All outbound network traffic is routed through the Web Appliance's bridge card, but only port 80 and port 443 traffic is examined. This deployment requires the optional bridge card included with some appliance models. With a Bridged Deployment, network traffic continues to flow in the event of an appliance failure.

That way you only need to configure the appliance, but as stated you'll need a bridge card for that (not sure if you have one).
0
 

Author Closing Comment

by:CDA_Administrator
ID: 39701635
I did manage to get it working via WCCP - however your solution would have don it too, thanks!
0

Featured Post

Cyber Threats to Small Businesses (Part 2)

The evolving cybersecurity landscape presents SMBs with a host of new threats to their clients, their data, and their bottom line. In part 2 of this blog series, learn three quick processes Webroot’s CISO, Gary Hayslip, recommends to help small businesses beat modern threats.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question