<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy server behind firepower in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495940#M1084761</link>
    <description>&lt;P&gt;I use a windows without proxy is okay.&lt;/P&gt;&lt;P&gt;Strange is the proxy server is actual build on linux (no sure which brand), if download inside the linux level (wget), the speed also slow. I have no other linux box on hand, but I think it will be also slow when download from the specific websites.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Nov 2021 08:16:20 GMT</pubDate>
    <dc:creator>Roy Lee</dc:creator>
    <dc:date>2021-11-01T08:16:20Z</dc:date>
    <item>
      <title>Proxy server behind firepower</title>
      <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4494823#M1084702</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have implemented a 1 leg proxy appliance inside LAN and NATed by firepower and then a PacketShaper bandwidth controller then to Internet. The&amp;nbsp;internet bandwidth is 50Mbps.&lt;/P&gt;&lt;P&gt;Strange thing is when download files from some specific website like wetransfer / citrix file share, the download speed will be under 100Kbps.&lt;/P&gt;&lt;P&gt;While download from some other website like Microsoft download / Google drive / One drive, the download speed is at least 10Mbps.&lt;/P&gt;&lt;P&gt;Maybe it also affect some web browsing but not noticeable.&lt;/P&gt;&lt;P&gt;I tried to change the proxy applicant internal IP and also the NATed public IP, no luck.&lt;/P&gt;&lt;P&gt;I setup a software proxy (ccproxy, squid) using the same internal IP and NATed public IP of the appliance, working very good.&lt;/P&gt;&lt;P&gt;I changed the proxy appliance to go via another old ASA, it works fine!&lt;/P&gt;&lt;P&gt;So the problem should be related to firepower or the bandwidth controller.&lt;/P&gt;&lt;P&gt;I will try to take out Packetshaper bandwidth controller to test later, but want to know if any hints on firepower.&lt;/P&gt;&lt;P&gt;I didn't apply Qos or File inspection on the ACL of firepower related to the proxy appliance.&lt;/P&gt;&lt;P&gt;Is there steps/area in firepower that I can identify the problem and fix?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 08:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4494823#M1084702</guid>
      <dc:creator>Roy Lee</dc:creator>
      <dc:date>2021-10-29T08:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy server behind firepower</title>
      <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4494837#M1084704</link>
      <description>&lt;P&gt;Do you have any Firepower IPS Policies enabled ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what model of FTD and what code running ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 08:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4494837#M1084704</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-10-29T08:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy server behind firepower</title>
      <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4494856#M1084705</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;, I do have 1 Intrusion Policy but not applied to the Access Rules related to the proxy appliance.&lt;/P&gt;&lt;P&gt;I am using FirePower 2100 with FTD version 6.2.3.1&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 09:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4494856#M1084705</guid>
      <dc:creator>Roy Lee</dc:creator>
      <dc:date>2021-10-29T09:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy server behind firepower</title>
      <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495866#M1084750</link>
      <description>&lt;P&gt;Anybody have idea?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 02:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495866#M1084750</guid>
      <dc:creator>Roy Lee</dc:creator>
      <dc:date>2021-11-01T02:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy server behind firepower</title>
      <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495920#M1084760</link>
      <description>&lt;P&gt;Might have missed it here, what is the status if there is no proxy if you go directly (without proxy). does the Firepower serve the bandwidth as expected?&amp;nbsp; (or with or without proxy same status ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 07:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495920#M1084760</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-01T07:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy server behind firepower</title>
      <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495940#M1084761</link>
      <description>&lt;P&gt;I use a windows without proxy is okay.&lt;/P&gt;&lt;P&gt;Strange is the proxy server is actual build on linux (no sure which brand), if download inside the linux level (wget), the speed also slow. I have no other linux box on hand, but I think it will be also slow when download from the specific websites.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 08:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495940#M1084761</guid>
      <dc:creator>Roy Lee</dc:creator>
      <dc:date>2021-11-01T08:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy server behind firepower</title>
      <link>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495958#M1084763</link>
      <description>&lt;P&gt;So here is our findings :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Firepower without proxy works fine&lt;/P&gt;
&lt;P&gt;2. Firepower with proxy not working as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any high-level diagram of how this is connected?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In most cases, Linux based is Squid (mostly used, so you mentioned single interface doing in and out traffic)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try adding one ACL Top of all ACL allow any for the Proxy IP and test it. ( at the same time capture the logs on Firepower also beneficial, if not it is hard to find the issue)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 09:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-server-behind-firepower/m-p/4495958#M1084763</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-01T09:36:37Z</dc:date>
    </item>
  </channel>
</rss>

