Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.400 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-03-2008, 08:58 PM
Senior Member
 
Join Date: Mar 2008
Location: France
Posts: 466
Default [NOTABUG] [7.360] HTTP proxy no more working ?

Hi,

I just reactivated HTTP Filtering with all default options + anti-virus scan + full transparent and I'm no more able to browse the web...

I needed to disable HTTP Filtering to be able to connect to the web again...

thx
  #2 (permalink)  
Old 12-04-2008, 08:10 AM
Senior Member
 
Join Date: Mar 2008
Location: France
Posts: 466
Default

Hi

attached is a screenshot for the proxy error... without proxy everything is working fine..

of course google should work !!

this is standard http filter config with anti-virus enabled... and proxy allowed for internal network

thx

edit1: for info using PPPOE connection.
edit2: and this is on an ASG 120 box
Attached Images
File Type: jpg webfilter_not_working.jpg (19.5 KB, 28 views)
  #3 (permalink)  
Old 12-04-2008, 01:05 PM
Member
 
Join Date: Oct 2006
Posts: 52
Default

I had the same error. After disabling full transparent mode, the problem stopped occurring.
  #4 (permalink)  
Old 12-04-2008, 05:12 PM
Senior Member
 
Join Date: Nov 2008
Posts: 174
Default

You guys need to understand what full transparent mode really does, first. Basically, the proxy rewrites the src-address of the requests it generates with the clients ip address. If your client uses an internal IP, you' re screwed because the webserver will never reach the client.

Believe me, you just want to stick to normal transparent mode.
  #5 (permalink)  
Old 12-04-2008, 05:24 PM
Senior Member
 
Join Date: Mar 2008
Location: France
Posts: 466
Default

Quote:
Originally Posted by trollvottel View Post
You guys need to understand what full transparent mode really does, first. Basically, the proxy rewrites the src-address of the requests it generates with the clients ip address. If your client uses an internal IP, you' re screwed because the webserver will never reach the client.

Believe me, you just want to stick to normal transparent mode.
so full transparent proxy was not working in 7.350 ! because I remember to used it and all was working fine !

thx
__________________
Running Astaro ASG 120 Appliance with home license (thx to Astaro team )
Running Astaro Software Version with HA License for High Availability Data Center
Running Astaro Software Version for Office
Running several ASG test VM for beta contests
  #6 (permalink)  
Old 12-05-2008, 08:52 AM
Junior Member
 
Join Date: Aug 2008
Posts: 8
Default

Yep, transparent mode was fine this way all (?) the versions before,
with 7.36 you have to change operation mode of http proxy to standard
what and why ever ...?

before, updates/downloads were buffered and scanned,
now they're passed online to calling application ...
I hope for my good sleep asg scans really really transparent ?
  #7 (permalink)  
Old 12-05-2008, 01:05 PM
Senior Member
 
Join Date: Nov 2008
Posts: 174
Default

Full transparent mode is a new feature of v7.400, so there weren' t older versions of full transparent mode for HTTP proxy available to the public.
  #8 (permalink)  
Old 12-05-2008, 01:10 PM
Senior Member
 
Join Date: Mar 2008
Location: France
Posts: 466
Default

Quote:
Originally Posted by trollvottel View Post
Full transparent mode is a new feature of v7.400, so there weren' t older versions of full transparent mode for HTTP proxy available to the public.
I was talking about 7.350 where I was able to connect to internet from internal when full transparent proxy was checked.. as I remember...
__________________
Running Astaro ASG 120 Appliance with home license (thx to Astaro team )
Running Astaro Software Version with HA License for High Availability Data Center
Running Astaro Software Version for Office
Running several ASG test VM for beta contests
  #9 (permalink)  
Old 12-05-2008, 08:57 PM
Wizard
 
Join Date: Oct 2005
Posts: 2,065
Default

Just curious... what is the difference between "standard" transparent mode and "full" transparent mode?
__________________
Convergent Information Security Solutions, LLC
Astaro Preferred Solution Partner
  #10 (permalink)  
Old 12-05-2008, 09:40 PM
Gert Hansen's Avatar
Wizard
 
Join Date: Nov 2000
Location: Karlsruhe, Germany
Posts: 1,185
Default

In transparent mode, the proxy intercepts outbound port 80 connections and processes it. it creates a new connection to the real server. this connection uses the external interface ip adress as the source ip of this connection.
this way the original ip address of the client can not be seen on the real server.

Full Transparent does exactly the same thing, but it replaces the external ip adress on the connection to the real server with the original ip address of the client.
this way the real server knows the original ip adress of the client.

But this feature only works properly in bridge mode, as the real server will try to send the response back to the original client ip and if this client ip is not routable, than it does not work.

If properly used in bridge mode, the full transparent proxy is nearly undetectable.

I hope this is understandable
regards
Gert
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:27 AM.

 

Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.