Configuring Automatic Proxy Forwarding (Web Only)

To configure Automatic Proxy Forwarding (Web Only):
1
2
Go to Network > Web Proxy.
3
Under Automatic Proxy Forwarding (Web Only), type the name or IP address of the proxy server in the Proxy Web Server (name or IP address) field.
4
Type the proxy IP port in the Proxy Web Server Port field.
5
To bypass the proxy servers if a failure occurs, select the Bypass Proxy Servers Upon Proxy Server Failure check box.
NOTE: The Bypass Proxy Servers Upon Proxy Server Failure check box allows clients behind the firewall to bypass the Web proxy server in the event it becomes unavailable. Instead, the client’s browser accesses the Internet directly as if a Web proxy server is not specified.
6
Select Forward Public Zone Client Requests to Proxy Server if you have clients configured on the DMZ.
7
Select Divert traffic to the WXA series appliances’s Web Cache if you have a WXA series appliance connected to your NSA/TZ series appliance and the Web Cache feature is enabled.
8
To forward all traffic initiated within an IP source address to the WXA Web Cache, select an address object from the Client Inclusion Address Object: drop-down menu. The default value is Any, which forwards any IP source address value to the WXA Web Cache. If the address object selected is LAN Primary Subnet, then only traffic within the subnet of X0 interface will be forwarded to the WXA Web Cache.

In the example below, the Server Inclusion Address Object drop-down menu is set to WebCache_Inclusion. Policies 32, 33, and 36 are modified so that only traffic initiated in the subnet of the source address defined in the WebCache_Inclusion address object will be forward to the WXA Web Cache. In this example, only a connection initiated from a client/pc/device in the 10.20.11.0/25 subnet will be forwarded to the WXA Web Cache.

9
To exclude traffic with a web server address destination from the WXA Web Cache, select an address object from the Server Exclusion Address Object drop-down menu. The default value is None, which allows all traffic destined for a web server will be forwarded to the WXA Web Cache.

In the example below, the Server Exclusion Address Object drop-down menu is set to WebCache_exclusion. Policies 32, 34, and 38 are created. These policies determine that connections destined to the web servers defined in the WebCache_exclusion address object will not be forwarded to the WXA Web Cache. The respective connections, instead, will be translated to a WAN IP address.

10
Click Accept.

Once the firewall has been updated, a message confirming the update is displayed at the bottom of the browser window.

The WAN Acceleration > Web Cache page shows the status of the included and excluded address objects.