proxy config on ASA

Unanswered Question
Feb 25th, 2009

The customer's proxy server is MS ISA. After http and https proxies are added on ASA, will the end users have to configure their web browser to use proxy? or they don't, the ASA just intercepts the web traffics and redirect them to proxy server?



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 3 (1 ratings)
Yudong Wu Wed, 02/25/2009 - 15:15

Do you mean Cut-through proxy on ASA? If yes, it's different from web proxy. I don't think ASA has "web proxy server" feature. So, if you need web proxy for users, their web browser should still point to MS ISA.

xiaoliangyue Fri, 02/27/2009 - 11:51

Thanks, Kevin.

So if I deploy a MS ISA in a DMZ, the users' web browser need to point to MS ISA. do I need to configure sth special? this DMZ's security level is between inside interface and outside interface.

How does the cut-through on ASA work? I never used it.

Yudong Wu Fri, 02/27/2009 - 14:35

First of all, you need to make sure your MS ISA server can access the internet, such as NAT, ACL config.

Second, make sure your internal user can access MS ISA in DMZ. Since internal user has high security level, they should be abel to access DMZ by default unless you have ACL configured to control outgoing traffic.

Cut-through is for authentication purpose.


This Discussion