Page 331 / 944 Scroll up to view Page 326 - 330
ZyWALL USG 50 User’s Guide
331
C
HAPTER
18
HTTP Redirect
18.1
Overview
HTTP redirect forwards the client’s HTTP request (except HTTP traffic destined for
the ZyWALL) to a web proxy server. In the following example, proxy server
A
is
connected to the
DMZ
interface. When a client connected to the
LAN1
zone wants
to open a web page, its HTTP request is redirected to proxy server
A
first. If proxy
server
A
cannot find the web page in its cache, a policy route allows it to access
the Internet to get them from a server. Proxy server
A
then forwards the response
to the client.
Figure 197
HTTP Redirect Example
18.1.1
What You Can Do in this Chapter
Use the
HTTP Redirect
screens (see
Section 18.2 on page 333
) to display and
edit the HTTP redirect rules.
LAN1
Page 332 / 944
Chapter 18 HTTP Redirect
ZyWALL USG 50 User’s Guide
332
18.1.2
What You Need to Know
Web Proxy Server
A proxy server helps client devices make indirect requests to access the Internet
or outside network resources/services. A proxy server can act as a firewall or an
ALG (application layer gateway) between the private network and the Internet or
other networks. It also keeps hackers from knowing internal IP addresses.
A client connects to a web proxy server each time he/she wants to access the
Internet. The web proxy provides caching service to allow quick access and reduce
network usage. The proxy checks its local cache for the requested web resource
first. If it is not found, the proxy gets it from the specified server and forwards the
response to the client.
HTTP Redirect, Firewall and Policy Route
With HTTP redirect, the relevant packet flow for HTTP traffic is:
1
Firewall
2
Application Patrol
3
HTTP Redirect
4
Policy Route
Even if you set a policy route to the same incoming interface and service as a
HTTP redirect rule, the ZyWALL checks the HTTP redirect rules first and forwards
HTTP traffic to a proxy server if matched. You need to make sure there is no
firewall rule(s) blocking the HTTP requests from the client to the proxy server.
You also need to manually configure a policy route to forward the HTTP traffic from
the proxy server to the Internet. To make the example in
Figure 197 on page 331
work, make sure you have the following settings.
For HTTP traffic between
lan1
and
dmz
:
a from LAN1 to WAN firewall rule (default) to allow HTTP requests from
lan1
to
dmz
. Responses to this request are allowed automatically.
a application patrol rule to allow HTTP traffic between
lan1
and
dmz
.
a HTTP redirect rule to forward HTTP traffic from
lan1
to proxy server
A
.
For HTTP traffic between
dmz
and
wan1
:
a from DMZ to WAN firewall rule (default) to allow HTTP requests from
dmz
to
wan1
. Responses to these requests are allowed automatically.
Page 333 / 944
Chapter 18 HTTP Redirect
ZyWALL USG 50 User’s Guide
333
a application patrol rule to allow HTTP traffic between
dmz
and
wan1
.
a policy route to forward HTTP traffic from proxy server
A
to the Internet.
Finding Out More
See
Section 6.5.11 on page 99
for related information on these screens.
18.2
The HTTP Redirect Screen
To configure redirection of a HTTP request to a proxy server, click
Configuration
> Network > HTTP Redirect
. This screen displays the summary of the HTTP
redirect rules.
Note: You can configure up to one HTTP redirect rule for each (incoming) interface.
Figure 198
Configuration > Network > HTTP Redirect
The following table describes the labels in this screen.
Table 94
Configuration > Network > HTTP Redirect
LABEL
DESCRIPTION
Add
Click this to create a new entry.
Edit
Double-click an entry or select it and click
Edit
to open a screen where
you can modify the entry’s settings.
Remove
To remove an entry, select it and click
Remove
. The ZyWALL confirms
you want to remove it before doing so.
Activate
To turn on an entry, select it and click
Activate
.
Inactivate
To turn off an entry, select it and click
Inactivate
.
#
This field is a sequential value, and it is not associated with a specific
entry.
Status
This icon is lit when the entry is active and dimmed when the entry is
inactive.
Name
This is the descriptive name of a rule.
Interface
This is the interface on which the request must be received.
Proxy Server
This is the IP address of the proxy server.
Page 334 / 944
Chapter 18 HTTP Redirect
ZyWALL USG 50 User’s Guide
334
18.2.1
The HTTP Redirect Edit Screen
Click
Network > HTTP Redirect
to open the
HTTP Redirect
screen. Then click
the
Add
or
Edit
icon to open the
HTTP Redirect Edit
screen where you can
configure the rule.
Figure 199
Network > HTTP Redirect > Edit
The following table describes the labels in this screen.
Port
This is the service port number used by the proxy server.
Apply
Click
Apply
to save your changes back to the ZyWALL.
Reset
Click
Reset
to return the screen to its last-saved settings.
Table 94
Configuration > Network > HTTP Redirect (continued)
LABEL
DESCRIPTION
Table 95
Network > HTTP Redirect > Edit
LABEL
DESCRIPTION
Enable
Use this option to turn the HTTP redirect rule on or off.
Name
Enter a name to identify this rule. You may use 1-31 alphanumeric
characters, underscores(
_
), or dashes (-), but the first character cannot
be a number. This value is case-sensitive.
Interface
Select the interface on which the HTTP request must be received for the
ZyWALL to forward it to the specified proxy server.
Proxy Server
Enter the IP address of the proxy server.
Port
Enter the port number that the proxy server uses.
OK
Click
OK
to save your changes back to the ZyWALL.
Cancel
Click
Cancel
to exit this screen without saving.
Page 335 / 944
ZyWALL USG 50 User’s Guide
335
C
HAPTER
19
ALG
19.1
ALG Overview
Application Layer Gateway (ALG) allows the following applications to operate
properly through the ZyWALL’s NAT.
SIP - Session Initiation Protocol (SIP) - An application-layer protocol that can be
used to create voice and multimedia sessions over Internet.
H.323 - A teleconferencing protocol suite that provides audio, data and video
conferencing.
FTP - File Transfer Protocol - an Internet file transfer service.
The following example shows SIP signaling (
1
) and audio (
2
) sessions between
SIP clients
A
and
B
and the SIP server.
Figure 200
SIP ALG Example
The ALG feature is only needed for traffic that goes through the ZyWALL’s NAT.
19.1.1
What You Can Do in this Chapter
Use the
ALG
screen (
Section 19.2 on page 339
) to set up SIP, H.323, and FTP ALG
settings.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top