Firewall-1

Re: [FW-1] Checkpoint and Microsoft ISA Server 2004 transparent proxying

Subject: Re: [FW-1] Checkpoint and Microsoft ISA Server 2004 transparent proxying
From: Hugo van der Kooij <hvdkooij AT VANDERKOOIJ DOT ORG>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Sat, 30 Dec 2006 19:26:45 +0100
On Sat, 30 Dec 2006, cisco4ng wrote:

Hi Gary and Hugo,

Gary's advise does work when I tried with my own http_map_service.  However,
I do not have a Microsoft ISA Server so I tried with Squid Proxy server.  So far
with my test, it only works with http and not  https.  I created another 
http_map
for https but it does not work.  I look at squid manual and it said that https 
is not
supported.  I will try with MS ISA server next week and see if it will work with
https.

Unless your proxy is capable of doing something smart with HTTPS traffic (like doing a man-in-the-middle attack and actually scan it) it is rather pointless to burden a proxy with tcp connects.

Hugo.

--
        hvdkooij AT vanderkooij DOT org http://hvdkooij.xs4all.nl/
            This message is using 100% recycled electrons.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>