ProxySG & Advanced Secure Gateway

 View Only
Expand all | Collapse all

traffic interface0:1 no able to make users access internet , although 0:0 able to do that

  • 1.  traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 07:19 AM
    Hi , 

    I have proxy deployed explicate with two interfaces , one 0:0 for management with ip address 10.20.173.80 and proxy have default gateway 10.20.173.1
    and interface 0:1 for internal traffic with ip 10.20.170.23 ,  users have reachability for the both ip's by using ping , when we enter the ip management in browser proxy setting was able to access internet browsing , but when enter the ip address in proxy browser setting for traffic interface the users not able to reach internet, although both ip's in the same policy in FW , and FW not see any traffic from internal interface of proxy (0:1) , can anyone help me ?

    Deployment topology 

    proxy using two interface 0:0 and 0:1 
    0:0 ip address 10.20.173.80
    0:1 ip address 10.20.170.23
    proxy GW 10.20.173.1
    Proxy >>>switch >>FW


  • 2.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 07:22 AM
    we need to make 0:1 forward traffic to internet by using it's ip in browser proxy setting , or how troubleshooting that


  • 3.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 07:44 AM
    Hello,

    You would need to run a packet capture on the proxysg to work out what is happening to requests when both coming into, and leaving the 0:1 interface. At the same time, you should also run a policy trace based on the client IP address making the requests. Also, you should disable any bridge mode settings for the 0:0 and 0:1 interfaces if there are any.

    Regards
    Paul


  • 4.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:01 AM
    Is there any command for ping 0:1 as source to Internet for example or how make tracert from specific interface in proxy . 

    Thanks & Best Regards,
    Mohamed Mohsen
    +966 56175 6647






  • 5.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:21 AM
    Unfortunately not, it will just go out the interface which is on the same subnet as the default gateway and you can't specify the source interface.

    Regards
    Paul


  • 6.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:26 AM
    Thanks, 
    I think that the users subnet not defined in static route in proxy is the reason that the 0:1 ip address not access able the internet , do you think that's right ?






  • 7.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:30 AM
    Well it depends if you have "return to sender" enabled, in which case it wouldn't matter as the return traffic would just go back the same way it came in. Also, you already stated that the users are able to ping the proxy on the IP address of interface 0:1.

    Paul


  • 8.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:35 AM
    yes , the users able to ping the 0:1 ip address , so should  i  enable "return to sender "  , right ?

    Thanks & Regards,

    Original Message:
    Sent: 9/24/2021 8:30:00 AM
    From: Paul Riddington
    Subject: RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Well it depends if you have "return to sender" enabled, in which case it wouldn't matter as the return traffic would just go back the same way it came in. Also, you already stated that the users are able to ping the proxy on the IP address of interface 0:1.

    Paul


  • 9.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:42 AM
    As I say, it probably already is enabled if your users can ping the 0:1 interface.

    Paul


  • 10.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:47 AM
    so , could you help me ? 
    what should i do, if it's already enabled  ?

    Thanks & Regards,






  • 11.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 08:53 AM
    or should enable "return to sender " for both inbound and outbound ?


  • 12.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 24, 2021 11:25 AM
    I've already suggested what you need to do next in my first reply.

    Regards
    Paul


  • 13.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 30, 2021 01:42 PM
    In my experience, you need to enable inbound return-to-sender  (enabled by default on new installations) but also overwrite-static-route (not enabled by default).


  • 14.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 27, 2021 07:46 AM

    I have almost the same configuration on my environtmen  we use  3 interfaces, 0:0  for management  1:0 internet  and 2:0  Intranet the only difference is as follows, maybe you could check on your side, irect on the network adapters configuration. 

    there are many options, and you could see  When receiving packets on this interface:

    i have this configuration 
    0:0  and 2:0

    Allow  transparent interceptoin

    but in  the interface with internet  

    i have :
    Firewall incoming Traffic.

    maybe this is your solution.

    Regards

    Fermin






  • 15.  RE: traffic interface0:1 no able to make users access internet , although 0:0 able to do that

    Posted Sep 27, 2021 08:46 AM
    That is the standard/default setup for a proxysg, as you would not normally initiate traffic from behind the WAN interface unless it was a reverse proxy, or managed on that interface.

    Regards
    Paul