<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WSA 390 Explicit Proxy Mode in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070732#M7322</link>
    <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I have two Cisco WSA 390 boxes and I have the below types of users&lt;/P&gt;
&lt;P&gt;1. Domain users which I am planning to integrate with WSA and apply the policies from WSA for Internet Access.&lt;BR /&gt;2. Wireless Guest which are authenticated by WLC and access the internet and these users are not part of any domain.&lt;BR /&gt;3. Tenant users which are located in my remote branches and are part of different domain which I have no control but these users come to my network for internet access.&lt;/P&gt;
&lt;P&gt;For #1 I can simply use explicit proxy and I can push the proxy setting from AD group policy and users will use WSA as a proxy.&lt;BR /&gt;For #2 and #3 I am planning to use the PBR in my cisco Core switch. Since internet traffic from both 2 and 3 are passing through the core , can I use a PBR and direct all traffic to WSA IP? Will that work for me as I don't have the option of pushing the proxy IP in these clients.&lt;/P&gt;
&lt;P&gt;Please advice&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 29 Jan 2017 13:52:43 GMT</pubDate>
    <dc:creator>Bilal Ahmad</dc:creator>
    <dc:date>2017-01-29T13:52:43Z</dc:date>
    <item>
      <title>WSA 390 Explicit Proxy Mode</title>
      <link>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070732#M7322</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I have two Cisco WSA 390 boxes and I have the below types of users&lt;/P&gt;
&lt;P&gt;1. Domain users which I am planning to integrate with WSA and apply the policies from WSA for Internet Access.&lt;BR /&gt;2. Wireless Guest which are authenticated by WLC and access the internet and these users are not part of any domain.&lt;BR /&gt;3. Tenant users which are located in my remote branches and are part of different domain which I have no control but these users come to my network for internet access.&lt;/P&gt;
&lt;P&gt;For #1 I can simply use explicit proxy and I can push the proxy setting from AD group policy and users will use WSA as a proxy.&lt;BR /&gt;For #2 and #3 I am planning to use the PBR in my cisco Core switch. Since internet traffic from both 2 and 3 are passing through the core , can I use a PBR and direct all traffic to WSA IP? Will that work for me as I don't have the option of pushing the proxy IP in these clients.&lt;/P&gt;
&lt;P&gt;Please advice&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2017 13:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070732#M7322</guid>
      <dc:creator>Bilal Ahmad</dc:creator>
      <dc:date>2017-01-29T13:52:43Z</dc:date>
    </item>
    <item>
      <title>You can also use WCCP. WCCP</title>
      <link>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070733#M7323</link>
      <description>&lt;P&gt;You can also use WCCP. WCCP enables supported Cisco routers and switches to transparently redirect content requests. With transparent redirection, users do not have to configure their browsers to use a web proxy. Instead, they can use the target URL to request content, and their requests are automatically redirected to an application engine. For more information please see the below link&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750e_3560e/software/release/12-2_37_se/configuration/guide/3750escg/swwccp.pdf"&gt;Configuring WCCP - Cisco&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2017 19:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070733#M7323</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2017-02-01T19:58:53Z</dc:date>
    </item>
    <item>
      <title>Hi Ravi</title>
      <link>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070734#M7324</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi Ravi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the answer. I would have been using WCCP &amp;nbsp;but the customer is not ready for using it. I have to use the explicit proxy mode. Can I configure it the way I have mentioned in my first topic?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please advice&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 05:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070734#M7324</guid>
      <dc:creator>Bilal Ahmad</dc:creator>
      <dc:date>2017-02-02T05:48:07Z</dc:date>
    </item>
    <item>
      <title>Bilal What I think You can</title>
      <link>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070735#M7325</link>
      <description>&lt;P&gt;Bilal What I think You can configure PBR on core switch and host the PAC file on WSA to push the proxy setting for #2 and #3. Hope this work for you&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 15:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070735#M7325</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2017-02-02T15:35:26Z</dc:date>
    </item>
    <item>
      <title>Hi Bilal,</title>
      <link>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070736#M7326</link>
      <description>&lt;P&gt;Hi Bilal,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you want to configure Explicit Proxy in your network, you can check the WPAD configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Web Proxy Auto-Discovery (WPAD) protocol is a method used by Web browsers to locate a Proxy Auto-Config (PAC) file automatically.&lt;/P&gt;
&lt;P&gt;WPAD can use DNS or DHCP to locate a PAC file.&lt;/P&gt;
&lt;P&gt;A DHCP server must be configured to serve an additional setting in an IP address assignment; option 252. This option specifies the exact location of the PAC file.&lt;/P&gt;
&lt;P&gt;The file name does not need to follow any specific naming convention, however if WPAD DNS is to be used also, the file must have the file name wpad.dat.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For more information, you can refer to:&amp;nbsp;http://www.cisco.com/c/en/us/td/docs/security/web_security/connector/connector3000/WPADAP.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;Kushagra Srivastava&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 09:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070736#M7326</guid>
      <dc:creator>kushsriva</dc:creator>
      <dc:date>2017-02-07T09:01:40Z</dc:date>
    </item>
    <item>
      <title>Check the link below</title>
      <link>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070737#M7327</link>
      <description>&lt;P&gt;Check the link below&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/web_security/connector/connector3000/WPADAP.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/web_security/connector/connector3000/WPADAP.html&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt; Moreover Web Proxy Auto-Discovery (WPAD) protocol is a method used by Web browsers to locate a Proxy Auto-Config (PAC) file automatically.&lt;BR /&gt; &lt;BR /&gt; WPAD can use DNS or DHCP to locate a PAC file.&lt;BR /&gt; &lt;BR /&gt; A DHCP server must be configured to serve an additional setting in an IP address assignment; option 252. This option specifies the exact location of the PAC file.&lt;BR /&gt; &lt;BR /&gt; The file name does not need to follow any specific naming convention, however if WPAD DNS is to be used also, the file must have the file name wpad.dat.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jul 2017 01:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-390-explicit-proxy-mode/m-p/3070737#M7327</guid>
      <dc:creator>gohussai</dc:creator>
      <dc:date>2017-07-29T01:15:02Z</dc:date>
    </item>
  </channel>
</rss>

