?
Solved

Watchguard and Access Control Allow Origin

Posted on 2014-12-09
2
Medium Priority
?
2,941 Views
Last Modified: 2014-12-15
Our media department here uses an external service for streaming that includes live comments. However, when the live feed is running they have to manually refresh the browser to see that chat updates (and refreshing causes the hit count to go up therefore meaning we don't get an accurate count of people viewing the session). This does not occur if a user is not behind our firewall.
I've contacted the streaming host and they said to make sure one website was allowed (pubnub) and that's all that should be necessary but that didn't fix it. They then said I may need to "allow"  Access Control Allow Origin in the header fields in the appropriate policy. I went there and have no idea how to implement it. Is this the path I should be taking? They aren't familiar with Watchguard products.

I have an XTM510 running 11.8 and WSM 9

Thanks for any input you may have.
0
Comment
Question by:perkwerx
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 64

Accepted Solution

by:
btan earned 2000 total points
ID: 40491082
WG by default will block e.g. removes HTTP headers it considers dangerous, including Access-Control-Allow-Origin
http://www.garysieling.com/blog/dont-use-access-control-allow-origin

You may want to check out the pdf. Specifically is to under HTTP-proxy policy> Proxy Action > HTTP Response > Header Fields, to add "Access-Control-Allow-Origin:*" into it. Note that header fields not in the list are stripped by default.
(see "HTTP Response - General Settings" section)
http://www.watchguard.com/support/fireware_howto/83/HTTP_Proxy_OutgoingProxyAction.pdf

there is another EE reference that may be useful in configuring an HTTP-Server Proxy Action (though not specific to this use case) - http://www.experts-exchange.com/Software/Anti-Virus/Q_26374271.html#a33363331
0
 

Author Comment

by:perkwerx
ID: 40500881
Thanks for the information. Now I just need to decide if it's worth allowing (and I'm leaning to the "no" side).
Thank you!
0

Featured Post

Cyber Threats to Small Businesses (Part 2)

The evolving cybersecurity landscape presents SMBs with a host of new threats to their clients, their data, and their bottom line. In part 2 of this blog series, learn three quick processes Webroot’s CISO, Gary Hayslip, recommends to help small businesses beat modern threats.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ever wonder what it's like to get hit by ransomware? "Tom" gives you all the dirty details first-hand – and conveys the hard lessons his company learned in the aftermath.
Check out the latest tech news, community articles, and expert highlights in August's newsletter.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question