cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
260
Views
0
Helpful
1
Replies

PIX and http proxy setup and filtering questions

jniederauer
Level 1
Level 1

Hi, I'm about to unleash a 525 to replace our old firewall, but I have some questions about some issues I haven't been able to figure out yet:

1. Our old firewall did stateful http inspection, etc, and also acted as a http proxy. In short, people without any proxy config could access websites on port 80 and those who had their proxy config'd to point to the firewall could http to any port. It doesn't appear that the pix does http proxy. Or does it? What are some recommended ways to set something up (we're windows based). Other than learning what ports all of our mission critical external websites use and doing fixups on them, what are my options (also taking into account my next question)?

2. URL filtering is very important to us (we have school sites). We're looking at the standard websense and n2h2 offerings, currently leaning slightly towards n2h2, and I'm wondering: Do I want the PIX-integrated version, or should I be getting a proxy-integrated version because of q#1?! Unfortunately, I don't want to force people to know the proxy info, because we have 600+ students who commute home to school with laptops and don't really want to throw proxy configuration drama into the mix. If I do URL filtering on the PIX, does that preclude me from doing it on the proxy?, or does the proxy ask the PIX if URLs are permitted based on filtering?!

Any guidance, suggestions, or revelations are greatly appreciated!

-JDN

1 Reply 1

nkhawaja
Cisco Employee
Cisco Employee

Hi,

Little bit confused about http proxy description you said. PIX doesnot act like proxy. PIX does port address translation like any other firewall. Microsoft Pxory Server or similiar product is what you meant right? But all your inside clients will be able to browse or initiate any traffic using PAT on PIX.

PIX supports N2H2 and Web Sense integration.

Unless you have something specific in mind, i would say dont confuse with PROXY thing. PIX will do the job here.

Thanks

Nadeem

Review Cisco Networking for a $25 gift card