NETAsq Firewall F200

Apr 19, 2006 8 Replies

HI to all, at work we use NETAsq Firewall F200 as Firewall and Proxy too, But I've a problem on the Proxy module. All traffic is proxed but every 4 hours (the max time for each login) a new login is required.



For users is not a problem, but for Servers, is a big problem. I don't know how to improve a good solution for a permanent navigation for some PC!



Anyone have any idea?



Sorry for my english.



Bye!



Gian Pietro Camisa Parma Italy



Hello,

In the "implicit rules" screen, you can uncheck the use of proxy implict rules.

And you can create a NAT rules which exclude yours servers, this action permit the bypass of the proxy, only for yours servers.

NAT rules can looks-like this:

Action Original Destination Port destination Translated Translated port Redirect Workstations Any HTTP loopback 8080

This rule redirect all http traffic from Workstation to the proxy, but not for servers. You can also use the "not equal" object to specify for example "all but not this server"... I hope that is clear for you ??

In fact, implicit rules create automatic translation rules. So, when you not use implicit rules, you must create NAT rules Manually.

Sorry for my english ! ;o)

Julien Lille, France

snipped-for-privacy@gmail.com a =E9crit :

thanks. I'm trying your tips but i don't understand wath is for you LOOPBAK. Workstation in your case is a range of IP addresses for users pc, true?

Loopback => 127.0.0.1 (Proxy listen to this interface)

Workstation => A range of PC addesses or objects in a group, or anything else, but not the Servers. (it's like another translation rule)

sigh... In any mode the browser send me to the authentication page of FW.....

For lookback i've created an object called LOOPBACK with ip 127.0.0.1

your Proxy is still activated?

Do you use authentication on your Firewall ?

the http proxy is always activated (and for users is ok). Yes the users can insert user and passwrod (the same of domain) and if they are in the rules they can go on internet.

I unchecked only the implicit rules and insert the nat rules, but nothing.. sigh

OK.

On the content filtering menu, specifically in your URL filtering filter, you've certainly create rules like that: user@any Pass or User@network_In ?

So you can create new rules to exclude your servers from authentication.

Example:

Rule number Origin Action

1 Servers Pass 2 Any@Network_In Pass

With this action, your servers do not need to be authenticate but Users must be authenticatd for Internet access.

I hope this tips will work...

You can forget previous tips and checked implicit rules before doing this new tips.

Julien

Thanks!!!!! It's ok! Now i'm tring to make some test!

You're my hero!

:-)

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required