08-27-2014 02:32 AM - edited 03-11-2019 09:41 PM
Hi All,
I am planing to implement asa 5545X firewall in place of juniper firewall. We have having cloud proxy now, but we have much problem with cloud proxy for some applications and trusted sites. Now i want to know
Thanks in advance.
Regards,
Satya.M
Solved! Go to Solution.
08-27-2014 03:39 AM
> we are have a plan to get SF-ASA-CX-9.1-K8, which is software based. Now i want to know can we do Proxy on this.
No, the ASA-CX is not a proxy. A Cisco Web Security Appliance (WSA) for example is a proxy. The CX is a transparent gateway where then data gets inspected and allowed/denied while the data flows through.
08-27-2014 03:08 AM
1) First of all, you have to define what you want from that proxy. The ASA is an application inspection gateway that sits transparently in the traffic-flow. That's much different then what a traditional proxy does. Of course you can provide extra security with L7-inspection. For that you need a software module which can be the ASA CX or the FirePower (SourceFire).
2) No, the standby ASA is *only* a backup for the primary ASA in case of a failure. There is no loadsharing in active/standby.
08-27-2014 03:32 AM
Tnx Karsten, we are have a plan to get SF-ASA-CX-9.1-K8, which is software based. Now i want to know can we do Proxy on this.Any document on proxy config will be helpful.
Thanks,
Satya.M
08-27-2014 03:39 AM
> we are have a plan to get SF-ASA-CX-9.1-K8, which is software based. Now i want to know can we do Proxy on this.
No, the ASA-CX is not a proxy. A Cisco Web Security Appliance (WSA) for example is a proxy. The CX is a transparent gateway where then data gets inspected and allowed/denied while the data flows through.
08-27-2014 03:19 AM
Hi,
I am not sure, how better you can do proxy using cisco asa... but for your question 2: you cannot make use of the standby one to do anything... that can take traffic only when it becomes traffic... it takes only management and sync traffic when it is in standby mode.
Regards
Karthik
08-27-2014 03:33 AM
Thnaks Karthik, wish Cisco does such things in future :)
Regards,
Satya.M
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide