<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Proxy setup - bypass in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114248#M15979</link>
    <description>&lt;P&gt;Why precisely are you trying to proxy and not just use NAT to achieve what you're after?&lt;/P&gt;</description>
    <pubDate>Mon, 22 Mar 2021 14:00:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-22T14:00:10Z</dc:date>
    <item>
      <title>HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114218#M15969</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've setup the Security Gateway as HTTP Proxy in Transparent Mode on all internal Interfaces.&lt;/P&gt;&lt;P&gt;Now I want to set it up that the Clients (coming from Interface 2) do not use Proxy when doing HTTP to Interface 1 (LAN), but to Interface 3 (external). Unfortunatly I don't understand how I could configure this one.&lt;BR /&gt;Can i configure this per Interface or is there a Proxy bypass List I can use?&lt;BR /&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;Many thanks and best regards&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 11:16:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114218#M15969</guid>
      <dc:creator>Frank_Fausch_sr</dc:creator>
      <dc:date>2021-03-22T11:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114225#M15970</link>
      <description>&lt;P&gt;You can configure which interfaces on the client side will be proxied by not on the destination side.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114225#M15970</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-03-22T12:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114229#M15972</link>
      <description>&lt;P&gt;Hello Val,&lt;BR /&gt;many thanks for your reply, but exactly this is what is not clear to me.&lt;BR /&gt;I want to have it Proxied comming from Client (eth2) to Internet (eth3) but not to LAN (eth1).&lt;/P&gt;&lt;P&gt;Means from eth2 to eth1 it should not be proxyfied.&lt;BR /&gt;But from eth2 to eth3 it should be.&lt;BR /&gt;So it's both times the Client is on eth2, but the outgoing interface is different.&lt;BR /&gt;So which one Interface I have to specify here?&lt;/P&gt;&lt;P&gt;I'm sorry for the stupied question - this is just not clear for me&lt;/P&gt;&lt;P&gt;Many thanks and best regards&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114229#M15972</guid>
      <dc:creator>Frank_Fausch_sr</dc:creator>
      <dc:date>2021-03-22T12:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114234#M15973</link>
      <description>&lt;P&gt;This setting is for client side. If you have clients coming from several internal interfaces, you can configure just some of them being proxied. This is not want you are trying to achieve, if I understand correctly. In your case, you want the same clients to be proxied when going to internet, and having direct connections to your DMZ servers. If that is your goal, my answer above stands&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:51:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114234#M15973</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-03-22T12:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114237#M15975</link>
      <description>&lt;P&gt;Hi Val,&lt;BR /&gt;Many thankks for your fast relpy.&lt;BR /&gt;So if I understand you corrently, what I'm trying to do (YES --&amp;gt;&amp;nbsp;&lt;SPAN&gt;same clients to be proxied when going to internet, and having direct connections to your DMZ servers) is not possible. Is that correct?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:07:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114237#M15975</guid>
      <dc:creator>Frank_Fausch_sr</dc:creator>
      <dc:date>2021-03-22T13:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114247#M15978</link>
      <description>&lt;P&gt;not with the transparent proxy, afaik&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:54:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114247#M15978</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-03-22T13:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114248#M15979</link>
      <description>&lt;P&gt;Why precisely are you trying to proxy and not just use NAT to achieve what you're after?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 14:00:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114248#M15979</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-22T14:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114249#M15980</link>
      <description>&lt;P&gt;Would it be possible in explicit Proxy mode?&lt;BR /&gt;and if yes, how?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 14:00:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114249#M15980</guid>
      <dc:creator>Frank_Fausch_sr</dc:creator>
      <dc:date>2021-03-22T14:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114255#M15981</link>
      <description>&lt;P&gt;we're using NAT for all what is going to Internet, of course.&lt;BR /&gt;the Point is, that from CISO point of view we have to proxify traffic going to Internet and not just URL filtering.&lt;BR /&gt;That's why I'm trying to find a way to use Proxy if it comes to Client -&amp;gt; Internte Traffic, but not if it comes to Client-&amp;gt;LAN traffic.&lt;BR /&gt;Trying to do that without external Services like proxy Pac file on another web server.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 14:25:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114255#M15981</guid>
      <dc:creator>Frank_Fausch_sr</dc:creator>
      <dc:date>2021-03-22T14:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Proxy setup - bypass</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114262#M15982</link>
      <description>&lt;P&gt;Transparent proxy applies to all web traffic passing through the gateway based on the origin interface.&lt;BR /&gt;There is, to my knowledge, no way to configure this based on destination interface.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;What you're asking for is likely an RFE.&lt;/P&gt;
&lt;P&gt;That said, what you're asking for can easily be achieved with NAT.&lt;BR /&gt;From a security perspective, I don't see a significant benefit to going with proxy mode (transparent or otherwise).&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 15:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTP-Proxy-setup-bypass/m-p/114262#M15982</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-22T15:16:26Z</dc:date>
    </item>
  </channel>
</rss>

