Configuring a proxy policy
A proxy policy enables proxying of traffic.
To create or edit a proxy policy:
- Go to Policy.
- With the appropriate device selected, select Proxy Policy in the Policy type dropdown list.
- Click Create or select a policy and click Edit.
- In the form, enter the following information:
Settings
Guidelines
Name
Enter a name for the policy.
Explicit Proxy Type
Select one the following options:
Explicit Web: Proxy HTTP and HTTPS traffic.
Transparent Web: Transparently proxy HTTP and HTTPS traffic.
FTP: Proxy FTP traffic.
WAN Optimize: Optimize WAN traffic through a proxy.
Incoming Interface
Select the incoming interfaces.
This option is only available when Explicit Proxy Type is set to Transparent Web.
Outgoing Interface
Select the outgoing interfaces.
IPv4 Source Address
Select the IPv4 source addresses.
This option is only available when Source Internet Service is disabled.
IPv6 Source Address
Select the IPv6 source addresses.
This option is only available when Source Internet Service is disabled.
Source User
Select source users.
Source User Group
Select source user groups.
Negate
Enable or disable negation of the source.
Destination Internet Service
Enable or disable the destination internet service, then select services.
IPv4 Destination Address
Select to add one or more address objects.
This option is only available when Destination Internet Service is disabled.
IPv6 Destination Address
Select to add one or more address objects.
This option is only available when Destination Internet Service is disabled.
Negate Destintion
Enable or disable negation of the destination.
Service
Select services and service groups.
This option is not available when Explicit Proxy Type is set to FTP.
When Explicit Proxy Type is set to Explicit Web or Transparent Web, the only available service is webproxy.
Schedule
Select one entry from the dropdown.
Action
Select whether to Deny, Accept, or Redirect matching traffic.
Redirect is only available when Explicit Proxy Type is set to Explicit Web or Transparent Web.
Log Allowed Traffic
Select from the following options:
No Log
Log Security Events
Log All Sessions
This option is only available when Action is set to Accept.
Generate Logs when Session Starts
Enable to generate logs when the session starts.
This option is only available when Action is set to Accept.
Log Violation Traffic
Enable or disable logging of denied traffic.
This option is only available when Action is set to Deny.
Display Disclaimer
Enable or disable disclaimer for this type of traffic.
This option is only available when Action is set to Accept.
Customize Message
From the dropdown, select a customized message.
This option is only available if Display Disclaimer is enabled.
This option is only available when Action is set to Accept.
Security Profiles Options
Enable or disable security profiles.
If Use Standard Security Profiles is enabled, select the appropriate profiles.
If Use Security Profile Group is enabled, select the appropriate profile group.
This option is only available when Action is set to Accept.
Protocol Options
Select from the available protocol options group, as configured by your service provider.
This option is only available when Action is set to Accept.
SSL/SSH Inspection
Select the SSL/SSH inspection profile to use for this policy.
This option is only available when Action is set to Accept.
Redirect URL
Enter the URL where matching traffic will be redirected.
This option is only available when Action is set to Redirect.
Web Proxy Forwarding Server
Select the forwarding server to use.
This option is only available when Explicit Proxy Type is set to Transparent Web.
Comments
Optionally, enter a comment for the policy.
- Click Save.