How to create a wifi hotspot which forwards all web request to online content filtering proxy.

We use a hosted content filtering proxy on our company network to block inappropriate web content. The client PCs are configured in IE using a .pac file to point to the proxy filter.

I would like to set up a wifi access point which out clients can use to access the Internet, which will force their web requests to also be directed to the proxy filter. However I do not have access to their devices and so can't configure IE or other browser.

Is this possible?  

Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Yes, Depending on your wifi ap, there are different ways to achieve this including transparent proxy.

It might also be possible to achieve this on the router to forward all requests from the wifi (vlan) to a transparent proxy.

Does the hosted proxy support wccp?
EICTAuthor Commented:
Thanks Arnold I shall find out if the hosted proxy supports wccp. Having googled this - if they did would I need a cisco AP?

Will be back soon. Thanks.
No, you would need your router to support wccp and you would configure an ACL on the wifi feed to redirect the requests to the proxy.
The "benefit" of wccp, should the proxy become inaccessible, the user will not be impacted though the users' requests will sent directly through to the destination.
Check Out How Miercom Evaluates Wi-Fi Security!

It's not just about Wi-Fi connectivity anymore. A wireless security breach can cost your business large amounts of time, trouble, and expense. Plus, hear first-hand from Miercom on how WatchGuard's Wi-Fi security stacks up against the competition plus a LIVE demo!

EICTAuthor Commented:
Unfortunately websense tell me they do not support WCCP.
You can on your router setup a rule that any port 80 requests from the wifi lan need to be forwarded through/redirected to the websense IP:port

The auto proxy detection relies on/requires the client have that option set and the browser they use.

The difficulty you say you want this to be transparent to the users to avoid users running into issues when they try to use the laptops/devices outside your network.

What router do you have?

Websense does not, but does your proxy?
one option if you can is to setup a VM running linux with squid with the websense box as the upstream peer.
the WCCP for wifi will be setup with the linux/squid.


There are a bunch of examples wccp transparent squid proxy setup.

in your case, you will have this squid proxy subordinated.
Out of curiosity, found the following websense doc/reference
EICTAuthor Commented:
Hi Arnold,
Sorry I have been away.
Websense Cloud solution does not support WCCP only their hardware solution.
A couple of other options I've discovered are:
1. use content filtering within the Draytek router. this can we applied to a particular VLAN using firewall rules.
2. Or configure the hotspot to use "Open DNS" i.e. push the open DNS IP addresses to the clients using DHCP. Open DNS includes content filtering.

Thanks for your help

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
EICTAuthor Commented:
The solution suggested was helpful but did not directly resolve the problem.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Wireless Networking

From novice to tech pro — start learning today.