<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix and transparent proxy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-and-transparent-proxy/m-p/360414#M552963</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi simpdou,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the proxy is intended for internet browsing, you can defnitely configure pix to allow connections from inside to DMZ. you can configure statics and put access-lists to allow ur inside network access the proxy server on the desired port. You have to do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) configure static or nonats between inside network and DMZ network.&lt;/P&gt;&lt;P&gt;2) configure access-lists on dmz (&amp;amp;inside) to allow communication between the inside network &amp;amp; proxy&lt;/P&gt;&lt;P&gt;3) do a nat for the proxy to access internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your scenario is doing caching for specific subnets based on the destination port, i think pix wont do redirection for such requests. you should have a L4 switch and do port redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. rate replies if found useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Jan 2005 08:44:10 GMT</pubDate>
    <dc:creator>sachinraja</dc:creator>
    <dc:date>2005-01-08T08:44:10Z</dc:date>
    <item>
      <title>Pix and transparent proxy</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-transparent-proxy/m-p/360413#M552962</link>
      <description>&lt;P&gt;I would like to redirect my port 80 traffic from my inside interface to the dmz interface.&lt;/P&gt;&lt;P&gt;I have a pix 515e and three interfaces - inside (private net), outside (pub net Internet) and dmz1 (which has a squid proxy)&lt;/P&gt;&lt;P&gt;What I want is when a user makes a webrequest (opens his/her browser) the request is redirected to the suid proxy on the dmz.&lt;/P&gt;&lt;P&gt;I know that one can use a layer 4 switch to do this.  Can I use my pix to redirect traffic/ports etc.  If you would like more info please ask.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-transparent-proxy/m-p/360413#M552962</guid>
      <dc:creator>simpdou</dc:creator>
      <dc:date>2020-02-21T07:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pix and transparent proxy</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-transparent-proxy/m-p/360414#M552963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi simpdou,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the proxy is intended for internet browsing, you can defnitely configure pix to allow connections from inside to DMZ. you can configure statics and put access-lists to allow ur inside network access the proxy server on the desired port. You have to do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) configure static or nonats between inside network and DMZ network.&lt;/P&gt;&lt;P&gt;2) configure access-lists on dmz (&amp;amp;inside) to allow communication between the inside network &amp;amp; proxy&lt;/P&gt;&lt;P&gt;3) do a nat for the proxy to access internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your scenario is doing caching for specific subnets based on the destination port, i think pix wont do redirection for such requests. you should have a L4 switch and do port redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. rate replies if found useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Jan 2005 08:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-transparent-proxy/m-p/360414#M552963</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2005-01-08T08:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Pix and transparent proxy</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-transparent-proxy/m-p/360415#M552964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot figure out the "access-list / access-group" part.  I want to redirect port 80 on the inside interface.  I would think it would be something like "access-list acl_name permit any www host 10.240.240.2" &lt;/P&gt;&lt;P&gt;"access-group acl_name in interface inside"&lt;/P&gt;&lt;P&gt;However, when I do this or a variation of redirecting port 80 from inside to dmz, the syslog shows that port 80 is trying the outside interface and being denied.&lt;/P&gt;&lt;P&gt;Do I have the right idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2005 19:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-transparent-proxy/m-p/360415#M552964</guid>
      <dc:creator>simpdou</dc:creator>
      <dc:date>2005-01-11T19:49:07Z</dc:date>
    </item>
  </channel>
</rss>

