Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Network fundamentals

Posted on 2014-01-16
4
Medium Priority
?
428 Views
Last Modified: 2014-01-31
I have inherited a network that has a proxy appliance. One side of the proxy appliance is plugged into the LAN and the other into the Firewall. Some of the client machines on the network are configured with proxy details in their browser and everything works as normal.

Some of the users do not have proxy details but they can still get out on the web. They are using a default gateway of the router that is attached to the proxy appliance. Regardless of what way the proxy appliance is setup I am confused as to how the users can even find the firewall!  even if the proxy appliance is incorrectly configured and wide open I would have thought no one should be able to contact the firewall as it is not directly plugged into the LAN.

Any ideas how I can see how this is occuring. I have checked arp tables wireshark etc.
0
Comment
Question by:Sid_F
4 Comments
 
LVL 26

Assisted Solution

by:pony10us
pony10us earned 600 total points
ID: 39785845
If the firewall is physically isolated (only connection is to the proxy appliance) then it is not possible to bypass the proxy.  Even though the information is not supplied in the browser settings.

If you have the proxy blocking/filtering a specific website then try to get to that site both with the proxy settings in place and not. You should be blocked both ways.
0
 
LVL 8

Accepted Solution

by:
Surrano earned 800 total points
ID: 39786678
sounds like the proxy acts as an ordinary gateway between LAN and the firewall. Try to traceroute (*nix) or tracert (windows) the firewall's IP and check the routing tables as well on a machine that "bypasses" the proxy and see how it is routed.
If it is routed through the proxy then the proxy acts as a gateway (it shouldn't).
If it is routed through different nodes then you'll see where to look for the gateway.
If the gateway is accessed directly (i.e. listed as first and only hop in traceroute) then it is on the same LAN as the clients and whatever switches/routers are in place should segregate them.
0
 
LVL 8

Assisted Solution

by:amatson78
amatson78 earned 600 total points
ID: 39794432
I would recommend running Packet Captures on the firewall and proxy appliance to see if and how traffic is flowing through the proxy. What type of proxy appliance is this? Are there any other cable terminations from the firewall to the LAN? The proxy may just be routing traffic, what is the route table of the proxy?

Cheers,
Alan
0
 
LVL 6

Author Closing Comment

by:Sid_F
ID: 39823834
Thanks
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question