<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Transparent Proxy in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160672#M3111</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can engage the Account Team in order to expedite the resolution of the enhancement request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis Silva &lt;BR /&gt; &lt;BR /&gt;"If you need PDI (Planning, Design, Implement) assistance feel free to reach" &lt;BR /&gt; &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/web/partners/tools/pdihd.html"&gt;http://www.cisco.com/web/partners/tools/pdihd.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jul 2013 16:49:53 GMT</pubDate>
    <dc:creator>Luis Silva Benavides</dc:creator>
    <dc:date>2013-07-16T16:49:53Z</dc:date>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160665#M3104</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Day!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have just changed our IronPort WSA proxy from Explicit Forward to Transparent Mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using Cisco ASA inside interface to redirect traffic to IronPort WSA. The WSA is also reachable via the inside interface per Cisco requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are able to browse internet through this proxy from PC as well as from mobile devices. Also most of the mobile applications are working too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The query is that if we need to do any specific changes in WSA or ASA in order to enable applications using ports other than 80 and 443. For example, there are some online games or whatsapp that needs to access internet on ports other than 80 and 443. Is there any change required for these mobile applications to work through WSA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please assist. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WSA Model: S670&lt;/P&gt;&lt;P&gt;Version: &lt;SPAN style="font-size: 10pt;"&gt;7.1.4-053&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2013 13:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160665#M3104</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2013-04-01T13:28:07Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160666#M3105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faiz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For sure you don't have to change anything on the ASA. On the WSA I don't think you have to do any change but are you facing any issues?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis Silva&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"If you need PDI (Planning, Design, Implement) assistance feel free to reach"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/web/partners/tools/pdihd.html"&gt;http://www.cisco.com/web/partners/tools/pdihd.html&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 21:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160666#M3105</guid>
      <dc:creator>Luis Silva Benavides</dc:creator>
      <dc:date>2013-05-30T21:27:11Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160667#M3106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Luis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, it appears that the WSA in transparent mode does not work as good as when it is in explicit forward mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are facing many issues with it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We were not able to get applications that use ports other than 80 or 443 to work throuhg the transparent proxy. For example, whatsapp uses port 5222 for initial connection and then sends the rest of the traffic over 443. But it never got connected while using transparent proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had started another discussion as well:&amp;nbsp; &lt;A _jive_internal="true" class="active_link" href="https://community.cisco.com/message/3930488#3930488"&gt;https://supportforums.cisco.com/message/3930488#3930488&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be great if you could assist me with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 10:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160667#M3106</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2013-06-05T10:09:08Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160668#M3107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you authenticating mobile dovices?&lt;/P&gt;&lt;P&gt;mobile devices shouldnt be authenticated in order to apps to work,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 10:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160668#M3107</guid>
      <dc:creator>bechara33</dc:creator>
      <dc:date>2013-06-05T10:13:26Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160669#M3108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Faiz, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Network/Transparent Redirection page, what ports do you have listed?&amp;nbsp; You can only have 8, and I don't think it allows ranges.&amp;nbsp; (its a WCCP limitation)&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/3/6/141636-TransRedir.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And on the ASA, what does your redirect acl look like?&amp;nbsp; Here's mine, (don't redirect inbound traffic, don't bounce traffic from WSA on .11 and wsa on .20, redirect all outbound)&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/3/6/141637-rediracl.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jun 2013 15:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160669#M3108</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2013-06-05T15:48:23Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160670#M3109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sorry for the delay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not using authentication for mobile devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My WSA transparent proxy configuration is similar to what is there in the screenshot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the ACLs are not exactly the same. I do not have the Deny ACLs in place. I have just allowed the subnet that requires internet access in the WCCP redirect ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand why you have the Deny ACLs. But the WCCP redirection works fine for all HTTP and HTTPS traffic. It just doesnt work for sites that work on other ports. So, do I really need to add those deny ACLs as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please assist. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 12:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160670#M3109</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2013-06-12T12:41:36Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160671#M3110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed authenticaiton for one of my smartphones, and it's working know. Also I understand that there's a feature request, &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2208540"&gt;https://supportforums.cisco.com/thread/2208540&lt;/A&gt;&lt;SPAN&gt; but there's no current workaournd?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 15:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160671#M3110</guid>
      <dc:creator>Mustapha Arakji</dc:creator>
      <dc:date>2013-07-16T15:15:06Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160672#M3111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can engage the Account Team in order to expedite the resolution of the enhancement request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis Silva &lt;BR /&gt; &lt;BR /&gt;"If you need PDI (Planning, Design, Implement) assistance feel free to reach" &lt;BR /&gt; &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/web/partners/tools/pdihd.html"&gt;http://www.cisco.com/web/partners/tools/pdihd.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 16:49:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160672#M3111</guid>
      <dc:creator>Luis Silva Benavides</dc:creator>
      <dc:date>2013-07-16T16:49:53Z</dc:date>
    </item>
    <item>
      <title>Transparent Proxy</title>
      <link>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160673#M3112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i have my WSA in Explicit mode, SmartPhones are not authenicated, but i can't get the WhatsApp working...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas? Should I intercept the port 5222 on my WSA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jul 2013 06:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-proxy/m-p/2160673#M3112</guid>
      <dc:creator>Mustapha Arakji</dc:creator>
      <dc:date>2013-07-31T06:38:02Z</dc:date>
    </item>
  </channel>
</rss>

