Professional Documents
Culture Documents
Overview
This article explains the different types of web proxy modes.
The following sections are covered:
Direct Proxy Mode: A browser must be configured to send all HTTP and HTTPS requests to the Sophos Firewall's
Proxy IP address on port 3128 (default).
This setting can is configured at Web > Advanced
https://community.sophos.com/kb/enus/122802 1/2
2017518 Sophos Firewall: Web Proxy operation modes Sophos Community
The firewall module validates if Web Proxy service is allowed in the source zone in System Administration >
Appliance Access and validates the request in Local firewall rules. Allowed traffic is sent to the web proxy.
Note: SFOS does not support running the Web Proxy on WAN interface.
Transparent Web Proxy Mode: A firewall rule redirects traffic passing through the firewall module with a
destination port of 80, 443 or a custom port to the Web Proxy module.
Custom ports can be configured from the console with the command: set serviceparam HTTP/HTTPS
Upstream Proxy Mode: When using a third party web proxy all web proxy requests for port 80 or 443 will be sent
to the configured proxy's IP using connect method.
To apply web filter and Antivirus policies on the traffic, the Sophos Firewall should know the IP and port of
upstream proxy. The administrator can configure this in Routing > Upstream Proxy.
Related information
Sophos Firewall: Web Filtering Basics
Sophos Firewall: How to configure a direct proxy
Sophos Firewall: How to configure a direct proxy when the XG is not the gateway device
https://community.sophos.com/kb/enus/122802 2/2