<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wsa design and deployment guide in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280853#M3633</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a specific reason why you would want your WSA in the DMZ?&amp;nbsp; Deployments where you are servicing traffic from hosts behind a different interface of the firewall is typically not supported.&amp;nbsp; But if you must, can you be a little more specific as to how you will be directing the traffic via the load balancer?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Vance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Aug 2013 05:48:00 GMT</pubDate>
    <dc:creator>Vance Kwan</dc:creator>
    <dc:date>2013-08-22T05:48:00Z</dc:date>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280852#M3632</link>
      <description>&lt;P&gt;folks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have 2 data centres to deploy a number of wsa appliances into&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'll have 4 in each&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ironports will be deployed into dmzs on an internet facing firewall&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on my internal network i'll have an load blancer directing traffic to the appliances in both data centres&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there a deployment guide for such a design setting out pros and cons or have any of you a link to a guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks to anyone taking the time to read this or to reply&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 23:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280852#M3632</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2013-08-21T23:10:41Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280853#M3633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a specific reason why you would want your WSA in the DMZ?&amp;nbsp; Deployments where you are servicing traffic from hosts behind a different interface of the firewall is typically not supported.&amp;nbsp; But if you must, can you be a little more specific as to how you will be directing the traffic via the load balancer?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Vance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 05:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280853#M3633</guid>
      <dc:creator>Vance Kwan</dc:creator>
      <dc:date>2013-08-22T05:48:00Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280854#M3634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;vance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;apologies for taking so long to get to you but i'm been off on other tasks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the proxies are in a dmz for policy reasons and they will also service traffic from other dmzs &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clients will have the load balancer's ip configured as their explicit proxy and so forward all traffic, unless defined as an exception, to the load balancer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the load balancers will then forward traffic to the upstream ironports using round robin or least connections as the load balancing algorithm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i need to consider how to authenticate users from the dmz to the internal ad servers (i may just have to open a firewall rule for specific traffic) the context directory agent look like a viable option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at a later stage i may use the load balancer to send traffic for particular urls to particular ironports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Sep 2013 12:28:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280854#M3634</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2013-09-03T12:28:12Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280855#M3635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is going to be a complex deployment and there are things you need to consider.&amp;nbsp; I do not believe there is a guide for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First off, when the traffic leaves the load balancer, what source IP will it have?&amp;nbsp; Clients'?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Vance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 04:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280855#M3635</guid>
      <dc:creator>Vance Kwan</dc:creator>
      <dc:date>2013-09-05T04:48:50Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280856#M3636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the authentication, the thing to remember this all goes by the management port, I don't know what ports it uses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could the management port be on the internal network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 08:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280856#M3636</guid>
      <dc:creator>Chris Illsley</dc:creator>
      <dc:date>2013-09-05T08:07:27Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280857#M3637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;vance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for getting back in touch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when the traffic leaves the load balancer the source ip will be the client address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've installed the c670s today with m1 in my management dmz and p1in the proxy dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've a bit to learn on these boxes it think&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 22:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280857#M3637</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2013-09-05T22:32:30Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280858#M3638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mooncat76&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the management port has to be in the dmz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2013 22:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280858#M3638</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2013-09-05T22:34:08Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280859#M3639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming that you can overcome the challenges of crossing the security zones on your Firewall, these deployments will work.&amp;nbsp; Will you be giving your Intranet full access to the DMZ?&amp;nbsp; Because that's what it sounds like you will need to do with this setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 04:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280859#M3639</guid>
      <dc:creator>Vance Kwan</dc:creator>
      <dc:date>2013-09-06T04:37:49Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280860#M3640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or just put the intranet as an exception either in the PAC file or browser settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2013 13:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280860#M3640</guid>
      <dc:creator>Chris Illsley</dc:creator>
      <dc:date>2013-09-06T13:24:16Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280861#M3641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;vance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've implemented my topology&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the internal lan has a load balancer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the web dmz manages web requests&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the management dmz handles ssh/https management requests to the box&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i now have to consider authentication methods&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have users in a number of domains that i need to authenticate, how can i do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i don't want to join a domain as the c670s are in a dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Sep 2013 21:59:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280861#M3641</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2013-09-08T21:59:04Z</dc:date>
    </item>
    <item>
      <title>wsa design and deployment guide</title>
      <link>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280862#M3642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure one NTLM realm, for additional realms you will need to use LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 06:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-design-and-deployment-guide/m-p/2280862#M3642</guid>
      <dc:creator>Chris Illsley</dc:creator>
      <dc:date>2013-09-09T06:54:24Z</dc:date>
    </item>
  </channel>
</rss>

