<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: redirect http traffic to an internal proxy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614325#M591775</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No possibilities ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Feb 2011 15:15:02 GMT</pubDate>
    <dc:creator>avburren1</dc:creator>
    <dc:date>2011-02-24T15:15:02Z</dc:date>
    <item>
      <title>redirect http traffic to an internal proxy</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614322#M591763</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am using ASA5510 and i want to know if it is possible to redirect http traffic to an internal proxy software.&lt;/P&gt;&lt;P&gt;I explain :&lt;/P&gt;&lt;P&gt;PC from the LAN use a internal proxy in their IE browser but some other PC doesn't use it.They are directy connected to the Internet using the Public IP from the WAN interface ( via NAT). Can we redirected this HTTP Traffic from the WAN interface to the Proxy in the LAN ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Http Traffic will be routed like that : PC -&amp;gt;&amp;nbsp; WAN interface -&amp;gt; Proxy -&amp;gt; WAN interface -&amp;gt; Internet&lt;/P&gt;&lt;P&gt;In fact,can we create a rule saying : All http traffic which doesn"t come from the IP Proxy must be redirected toward proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you understand.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614322#M591763</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2019-03-11T19:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: redirect http traffic to an internal proxy</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614323#M591767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at the config guides for WCCP and URL filtering. Depending on what you want to achieve, one of those 2 features should accomplish what you're looking for:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WCCP:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_wccp.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_wccp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL filtering:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_filter.html#wp1045692"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_filter.html#wp1045692&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 20:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614323#M591767</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-02-14T20:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: redirect http traffic to an internal proxy</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614324#M591772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;URL Filtering implies to have a Web Sense Server or a Secure Computing SmartFilter Server&amp;nbsp; and WCCP doesn't propose to redirect traffic toward a specifc IP + Port so i think its not possible to achieve what i want or maybe I don't understand those two features ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Feb 2011 10:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614324#M591772</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2011-02-15T10:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: redirect http traffic to an internal proxy</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614325#M591775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No possibilities ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 15:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614325#M591775</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2011-02-24T15:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: redirect http traffic to an internal proxy</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614326#M591776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA does not currently support transparent proxy feature, however, it is in the roadmap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After reading your post, you mention that some has explicit proxy settings, and some doesn't, hence you would like to redirect on the ASA if it's possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The easiest workaround:&lt;/P&gt;&lt;P&gt;- Block all outbound HTTP/HTTPS access on the ASA, except outbound from the proxy ip address. This will ensure that everyone else can't get to the Internet but via the proxy.&lt;/P&gt;&lt;P&gt;- Once you have implemented that, I am sure they learn that the only way to get internet access is via the proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second option is to use ASA DNAT feature (supported from ASA version 8.3 onwards). Your scenario of redirecting it after it gets out will definitely not work. I am thinking more on redirection on the inside interface - but I have never tested it.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Assuming that your internal network is 10.1.1.0/24, proxy server: 10.1.1.10:&lt;/P&gt;&lt;P&gt;object network obj-internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj-10.1.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 10.1.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-proxy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 10.1.1.10&lt;/P&gt;&lt;P&gt;object service original-http&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service tcp destination eq www&lt;/P&gt;&lt;P&gt;object service proxy-8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service tcp destination eq 8080&lt;/P&gt;&lt;P&gt;nat (inside,inside) source static obj-10.1.1.0 obj-10.1.1.0 destination static obj-internet obj-proxy service original-http proxy-8080&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, I have never tested DNAT in and out the same interface, but in theory, it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know your thoughts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Feb 2011 22:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614326#M591776</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-24T22:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: redirect http traffic to an internal proxy</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614327#M591779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.&lt;/P&gt;&lt;P&gt;I'am using ASA v8.2, Are you sure DNAT isn't supported ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 15:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614327#M591779</guid>
      <dc:creator>avburren1</dc:creator>
      <dc:date>2011-02-25T15:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: redirect http traffic to an internal proxy</title>
      <link>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614328#M591781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;YUP, 100% sure DNAT is not supported in 8.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 21:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/redirect-http-traffic-to-an-internal-proxy/m-p/1614328#M591781</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-25T21:54:12Z</dc:date>
    </item>
  </channel>
</rss>

