Configuration
1. Connect the Web Appliance’s LAN port to your organization’s LAN.
2. Connect the Web Appliance’s WAN port to your organization’s firewall.
3. In the Web Appliance’s administrative web interface, on the Configuration > Network >
Network Interface page, set the Deployment mode to Bridged, and click Configure to create
a list of IP addresses or IP ranges for internal web servers that are exempted from handling
by the Web Appliance.
Note: You are not required to configure users’ web browsers.
2.3.3.1 Switching from Bridged Mode to Explicit Mode
This page describes the steps required to convert your Web Appliance from a Bridged Deployment
to an Explicit Deployment.
To transition from a Bridged to an Explicit deployment:
1. Leave the Web Appliance’s LAN port connection to your organization’s LAN unchanged.
2. Remove the connection between the Web Appliance’s WAN port and your organization’s
firewall.
3. On the Configuration > Network > Network Interface page, change the Deployment mode
from Bridged to Explicit.
4. Configure each user’s web browser to use the Web Appliance via port 8080 as their web proxy
for HTTP, HTTPS, and FTP. (Ports 3128 and 8081 are also supported, but their use is only
suggested if the Web Appliance is replacing a previous proxy configuration that used one of
these ports.)
Note: To add support for HTTPS applications that use non-standard ports, see Add Local
Classification.
Note: Configuring all user’s browsers to use the Web Appliance as a web proxy can be done
centrally in Windows networks by using one of several methods. See the Sophos
Knowledgebase pages for instructions on how to do this by:
■
Creating, Testing, and Deploying a
■
■
2.3.4 Bypassing for Internal Servers
This option allows clients to access specific internal servers directly. You might choose this setup
if you want to let users access internal web pages without routing requests through the appliance.
When based on the Explicit Deployment, this option does the following:
■
Inspects HTTP, HTTPS, and FTP over HTTP traffic.
■
Supports individual user opt-outs.
■
Requires configuration for all clients.
Sophos Web Appliance | Getting Started | 33