<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to make PIX to redirect incoming http traffic to a proxy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191754#M590365</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not possible.&lt;/P&gt;&lt;P&gt;Also, "filter url" doesn't do HTTP redirection, it sends an URL to the URL-filtering server (Websense/N2H2). The original HTTP request is sent to the Internet in parallel to this filtering request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oleg Tipisov,&lt;/P&gt;&lt;P&gt;REDCENTER,&lt;/P&gt;&lt;P&gt;Moscow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Aug 2003 14:50:33 GMT</pubDate>
    <dc:creator>ovt</dc:creator>
    <dc:date>2003-08-28T14:50:33Z</dc:date>
    <item>
      <title>How to make PIX to redirect incoming http traffic to a proxy server?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191751#M590362</link>
      <description>&lt;P&gt;How to configure PIX such that it redirect incoming http traffic to a internal proxy server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:57:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191751#M590362</guid>
      <dc:creator>lehpoh</dc:creator>
      <dc:date>2020-02-21T06:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to make PIX to redirect incoming http traffic to a proxy</title>
      <link>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191752#M590363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q. Are you filtering ALL internet browsing via the proxy server, Is the proxy server a MS ISA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please post your PIX config here or if you like to me at &lt;A href="mailto:noc1@vodafone.net"&gt;noc1@vodafone.net&lt;/A&gt; (Please change passwords + inside IP's)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, which PIX IOS are you running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Aug 2003 16:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191752#M590363</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2003-08-27T16:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to make PIX to redirect incoming http traffic to a proxy</title>
      <link>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191753#M590364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since you are asking the question, i suppose your proxy isn't MS-ISA which the redirection is done on each station.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you call, incoming HTTP traffic is, in term of PIX, outgoing HTTP connection.  PIX supports Websense &amp;amp; Bess's N2H2 filter products, in those case redirection is done with url-server + filter url commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question, is those commands are compatible with other proxy boxes ?  I don't know.  Hope someone else will respond to this one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, you will be obliged to redirect traffic with a layer 7 switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Aug 2003 19:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191753#M590364</guid>
      <dc:creator>bdube</dc:creator>
      <dc:date>2003-08-27T19:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to make PIX to redirect incoming http traffic to a proxy</title>
      <link>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191754#M590365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not possible.&lt;/P&gt;&lt;P&gt;Also, "filter url" doesn't do HTTP redirection, it sends an URL to the URL-filtering server (Websense/N2H2). The original HTTP request is sent to the Internet in parallel to this filtering request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oleg Tipisov,&lt;/P&gt;&lt;P&gt;REDCENTER,&lt;/P&gt;&lt;P&gt;Moscow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2003 14:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191754#M590365</guid>
      <dc:creator>ovt</dc:creator>
      <dc:date>2003-08-28T14:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to make PIX to redirect incoming http traffic to a proxy</title>
      <link>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191755#M590367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this month's Windows &amp;amp; .NET magazine, there was an MS publication called something like "Security Advertising/Special Report".  Unfortunately, I did not keep it.  However, there was a few design examples where you would only have one host in the DMZ which would be a MS ISA 2000 proxy server.  It did not specify that the firewalls were Cisco (or any other).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I remember correctly, ALL traffic was directed to the proxy server for layer 7 filtering.  In turn, the packets were sent to the appropriate HTTP server which resided in the inside subnet.  This way, it was easy for the internal HTTP servers to access other internal RDBMS servers since all were together.  I think an IPSec tunnel was also an option to secure traffic from the DMZ proxy server to any server inside.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The benefits of this were that you only have one bastion host to configure and the solution took care of filtering all the way up to the application layer.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may be what the initial question was??? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regardless, did any of you keep this special report?  What do you think about this design?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2003 08:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-make-pix-to-redirect-incoming-http-traffic-to-a-proxy/m-p/191755#M590367</guid>
      <dc:creator>plemieux72</dc:creator>
      <dc:date>2003-08-29T08:49:43Z</dc:date>
    </item>
  </channel>
</rss>

