<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTPS and transparent mode in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421535#M4388</link>
    <description>&lt;P&gt;Hello support,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should I enable HTTPS proxy if I am going to use transparent mode for WSA deplyoment ? &lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2013 18:51:56 GMT</pubDate>
    <dc:creator>davidbart8</dc:creator>
    <dc:date>2013-12-04T18:51:56Z</dc:date>
    <item>
      <title>HTTPS and transparent mode</title>
      <link>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421535#M4388</link>
      <description>&lt;P&gt;Hello support,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should I enable HTTPS proxy if I am going to use transparent mode for WSA deplyoment ? &lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2013 18:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421535#M4388</guid>
      <dc:creator>davidbart8</dc:creator>
      <dc:date>2013-12-04T18:51:56Z</dc:date>
    </item>
    <item>
      <title>HTTPS and transparent mode</title>
      <link>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421536#M4389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are planning to do decryption then you MUST enable the HTTPS proxy. If you do not plan to do decryption then you don't have to enable it but do not redirect port 443 to the WSA if the HTTPS proxy is not enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 17:18:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421536#M4389</guid>
      <dc:creator>Tom Foucha</dc:creator>
      <dc:date>2013-12-06T17:18:57Z</dc:date>
    </item>
    <item>
      <title>HTTPS and transparent mode</title>
      <link>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421537#M4390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tommy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response ,&lt;SPAN style="font-size: 10pt;"&gt;would you please describe the side effects of redirecting port 443 to WSA if https is not enabled ? we are planning to set the WSA in transparent mode as I have read in the user guide that the transparent can accept both explicitly forwarded and transparent requests. My concern is that i have some users working on Citrix server with cookie-based surrogate and some other fat clients. The guide stated that there are problems in using cookie-based and transparent,appreciate your help as I am not much that familiar with WSA &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I configure my policies so it works for both fat clients and Citrix server users??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 17:43:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421537#M4390</guid>
      <dc:creator>davidbart8</dc:creator>
      <dc:date>2013-12-06T17:43:42Z</dc:date>
    </item>
    <item>
      <title>HTTPS and transparent mode</title>
      <link>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421538#M4391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As with any TCP device it has to listen on a port for connections to accept the socket. If you do not enable HTTPS proxy then we do not listen on port 443 for connections so any connection redirected to the proxy on port 443 will simply fail when using transparent mode. In explicit mode the browser is told to send HTTPS traffic to the proxy on the proxy port 80, 3128, 8080 etc. so the proxy is listening on that specific port for any traffic. The same would happen to HTTP traffic if you redirect traffic to the proxy on port 9999 but didn't configure the proxy to accept traffic on port 9999.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on the version of WSA code you are running you can set the surrogate type in the Access Policy. Not being familair with your network I would say if you have Citrix servers then create an identity for the servers based on IP address and authentication and set the surrogate to session based cookies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 18:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421538#M4391</guid>
      <dc:creator>Tom Foucha</dc:creator>
      <dc:date>2013-12-06T18:02:49Z</dc:date>
    </item>
    <item>
      <title>HTTPS and transparent mode</title>
      <link>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421539#M4392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much for your explanation Tommy and making me aware of this. much thanks for support &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Dec 2013 18:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-and-transparent-mode/m-p/2421539#M4392</guid>
      <dc:creator>davidbart8</dc:creator>
      <dc:date>2013-12-06T18:40:40Z</dc:date>
    </item>
  </channel>
</rss>

