Solved

Watchguard and Access Control Allow Origin

Posted on 2014-12-09
2
2,144 Views
Last Modified: 2014-12-15
Our media department here uses an external service for streaming that includes live comments. However, when the live feed is running they have to manually refresh the browser to see that chat updates (and refreshing causes the hit count to go up therefore meaning we don't get an accurate count of people viewing the session). This does not occur if a user is not behind our firewall.
I've contacted the streaming host and they said to make sure one website was allowed (pubnub) and that's all that should be necessary but that didn't fix it. They then said I may need to "allow"  Access Control Allow Origin in the header fields in the appropriate policy. I went there and have no idea how to implement it. Is this the path I should be taking? They aren't familiar with Watchguard products.

I have an XTM510 running 11.8 and WSM 9

Thanks for any input you may have.
0
Comment
Question by:perkwerx
2 Comments
 
LVL 61

Accepted Solution

by:
btan earned 500 total points
Comment Utility
WG by default will block e.g. removes HTTP headers it considers dangerous, including Access-Control-Allow-Origin
http://www.garysieling.com/blog/dont-use-access-control-allow-origin

You may want to check out the pdf. Specifically is to under HTTP-proxy policy> Proxy Action > HTTP Response > Header Fields, to add "Access-Control-Allow-Origin:*" into it. Note that header fields not in the list are stripped by default.
(see "HTTP Response - General Settings" section)
http://www.watchguard.com/support/fireware_howto/83/HTTP_Proxy_OutgoingProxyAction.pdf

there is another EE reference that may be useful in configuring an HTTP-Server Proxy Action (though not specific to this use case) - http://www.experts-exchange.com/Software/Anti-Virus/Q_26374271.html#a33363331
0
 

Author Comment

by:perkwerx
Comment Utility
Thanks for the information. Now I just need to decide if it's worth allowing (and I'm leaning to the "no" side).
Thank you!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video discusses moving either the default database or any database to a new volume.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now