Configure Transparent SSL forward proxy with authentication
book
Article ID: 166473
calendar_today
Updated On:
Products
Advanced Secure Gateway Software - ASG
ProxySG Software - SGOS
Resolution
Follow the high-level steps below to set up SSL forward proxy in a transparent deployment. For step-by-step instructions, see the attached document.
- Create a keyring and define a certificate.
- Use VPM to create SSL policy:
- Add an SSL Intercept Layer, specify an SSL Forward Proxy Action, and select the keyring created in step 1
- Add an SSL Access Layer, set the Action to Disable Server Certificate Validation
- Install the policy
- Import the certificate on all computers.
- Define a virtual IP on the ProxySG.
- Create an HTTPS reverse proxy service port with the virtual IP on port 4433 or any unused port. Tie the keyring created in step 1 into the service.
- Create an SSL service that listens on all IP addresses on port 443. This service will be used to intercept connections to HTTPS sites.
- Create a realm for the authentication protocol.
- Define the virtual URL as the HTTPS reverse proxy
- Define this same virtual URL for the transparent proxy
- Use VPM to create Web Authentication policy:
- Add a Web Authentication LayerOrigin cookie redirect or Origin IP redirect
- Enforce authentication by creating an Authenticate/Force Authenticate Action. Mode=Origin cookie redirect or Origin IP redirect
- Install policy
- Import the ProxySG self-signed certificate into IE
Attachments
SSL Forward Proxy with Authentication.pd
get_app
Feedback
thumb_up
Yes
thumb_down
No