Solved

Best open srouce Transperent Proxy to be used along with Cisco ASA5505

Posted on 2014-09-11
5
190 Views
Last Modified: 2014-10-20
Hi Experts,

My set up would be as follows;


```````````````````````````````````````````````````````````````
Public <<>> Cisco ASA <<>> (eth0)Transparent Proxy(eth1) <<>> Client
                                                                                                             >> Server(HTTP)
```````````````````````````````````````````````````````````````

`````````````````````````````````````
ASA outside: x.x.x.x
ASA inside: 192.168.1.254

Proxy eth0: 192.168.1.253
eth0 gateway: 192.168.1.254
Proxy eth1: Bridge

Client IP: 192.168.1.10
Client Gateway: 192.168.1.254
DNS: Internal DNS server + ISP DNS

Server IP: 192.168.1.11
Server Gateway: 192.168.1.254
DNS: Internal DNS server + ISP DNS
````````````````````````````````````
My requirements:
1. Client should be able to brows the Internet through the proxy
2. HTTP traffic should be able to forward to the internal web server

I have tried several open source products such as Zentyal, Untangle, but so far it's didn't work.
Can you please advise me on this ? Any recommendations/Howtos on anything products ?

Thanks a lot for your time !
0
Comment
Question by:Shakthi777
5 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 250 total points
Comment Utility
If it were my project, I would buy Websense - and itegrate that with the ASA (I do like websense,  but some find it a little expensive) the ASA traditionally only supports N2H2 and Websense, but that does NOT stop you deploying another proxy filtering solution behind the firewall and pointing your internal clients at that.

I'd NOT recommend anyhting WCCP based, they always tend to be a bit clunky (sorry Cisco).

PL
0
 
LVL 2

Accepted Solution

by:
vpnttg earned 250 total points
Comment Utility
Please check “Cisco ASA and Squid with WCCP2”:
http://wiki.squid-cache.org/ConfigExamples/Intercept/CiscoAsaWccp2
0
 
LVL 11

Expert Comment

by:sumeshbnr
Comment Utility
Please describe HTTP traffic should be able to forward to the internal web server .It is not clear
0
 
LVL 7

Expert Comment

by:unfragmented
Comment Utility
seconding squid and wccp.  For free/open source its pretty hard to beat.
0
 

Author Closing Comment

by:Shakthi777
Comment Utility
Thanks !
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Advice on setting up a new network for a small business 3 43
Quick cusco 2091 setup 5 19
Cisco NBAR 6 13
Cisco prime 3 15
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now