SWG Deployment Methodologies en
SWG Deployment Methodologies en
WHITEPAPER
DEPLOYMENT METHODOLOGIES
In today’s complex network architectures it seems there are limitless ways to deploy networking equipment.
This may be the case for some networking gear, but for web gateways there are only a few proven deployment
methodologies that are effective and provide complete security.
In this article, we’ll talk about the four most common types of web gateway network deployments. Sometimes
referred to as forward proxies, these devices are used to secure web access for an organization’s internal end-
users. The four commonly used deployment scenarios for web gateways are inline, explicit, transparent and SPAN
port. Each one of these deployments has its advantages and disadvantages.
Transparent Deployment
Secure Web Gateway
Transparent deployment allows a web gateway to be deployed in
any network location that has connectivity, similarly to explicit mode
Figure 2 - Explicit Deployment
Client has an explicitly defined proxy in its settings for the web browser
deployment (Figure 3), reducing the need for a configuration change
to the network to implement. In addition, there is no administrative
When using explicit deployment it is extremely important to have the overhead to configure end-user systems, since the routing of HTTP
firewall properly configured to prevent users from bypassing the proxy. and HTTPS traffic is typically done by the router or other network
The firewall needs to be configured to allow only the proxy to talk device. Transparent deployment is often used when an organization is
through the firewall using HTTP and HTTPS. All other hosts/IP addresses too large for an inline deployment and does not want the added work
should be denied. In addition, all other ports need to be locked down to and overhead needed for an explicit deployment. Most transparent
prevent end-users from setting up their own proxy internally that tries to deployments rely on web Caching Communications Protocol (WCCP), a
access the Internet via HTTP on a port other than the commonly used protocol supported by many network devices. Alternatively transparent
ones (80 and 443). deployment can be achieved using Policy Based Routing (PBR).
include narrowing the amount of traffic processed by the web gateway Clients Switch
or Router
(you can limit traffic to only HTTP based traffic), and the ability to more
easily implement redundancy for web gateways in your environment.
Explicit mode deployment for an environment without an existing web Secure Web Gateway
gateway is also less disruptive to the network. The web gateway can be
SECURE WEB GATEWAY placed anywhere in the network that is accessible by all end-users as
Figure 3 - Transparent Deployment
Router and SWG use WCCP for communications
DEPLOYMENT METHODOLOGIES long as the web gateway is able to reach the Internet.
©
BLUE COAT SYSTEMS, INC
2
WHITEPAPER
Transparent Deployment Advantages SPAN Port Advantages
The main advantages of deploying a web gateway in transparent mode SPAN port deployments are advantageous for large scale deployments
include narrowing the amount of traffic processed by the proxy, and because the monitoring mode typically uses fewer resources than
the ability to more easily implement redundancy of the web gateway. In inline, explicit or transparent, which all must actively process traffic. A
addition, transparent deployment does not require changes to end-user SPAN port deployment is useful if you think your hardware might be
systems. undersized for your needs. Finally, port monitoring to passively detect
call home attempts on most ports and network traffic is available with
this deployment method.
Transparent Deployment Disadvantages
Transparent deployment does depend on the availability of either
SPAN Port Disadvantages
WCCP or PBR, and support for these by the web gateway, typically
available only on more sophisticated web gateways. Configuration can A SPAN port deployment on a switch does not see all the traffic.
be trickier as there needs to be compatibility of supported versions of Corrupt network packets, packets below minimum size, and layer 1
WCCP between the router and the web gateway. More in-depth network and 2 errors are usually dropped by the switch. In addition, it’s possible
expertise is required to implement and deploy a transparent mode a SPAN port can introduce network delays. The software architecture
deployment, which may not be a problem in larger organizations but of low-end switches introduces delay by copying the spanned packets.
could be an issue for smaller organizations. Also, if the data is being aggregated through a gigabit fiber optic
port, a delay is introduced as the signal is converted from electrical to
optical. Any network delay can be critical since TCP resets are used to
SPAN Port Deployment
implement policy.
The last deployment methodology is the SPAN (Switched Port
SPAN ports also have an issue when there is an overload of traffic.
Analyzer) port deployment. Sometimes this method is called TCP Reset
Typically the port will drop packets and result in some data loss. In a
deployment, as it relies on TCP resets to implement the policy of the
high network load situation most web gateways connected to a SPAN
web gateway. A web gateway is deployed by attaching it to a SPAN
port will not be able to respond quickly enough to keep malware from
port on a switch (Figure 4). Unlike the other three deployment methods,
spreading across a corporate network.
which process the web traffic and implement policies based on the
network response the web gateway issues, a web gateway deployed
on a SPAN port implements policies by issuing a TCP reset to the client
system to prevent completing a download of offending content.
Switch
TAP
EMEA Headquarters
Hampshire, UK
+44.1252.554600
APAC Headquarters
Singapore
+65.6826.7000
5