Cisco Cisco Web Security Appliance S160 Installation Guide

Page of 22
7
 
4  
Plan the Installation
Decide how you are going to configure the Cisco S390 Web 
Security Appliance within your network.
The Cisco S390 is typically installed as an additional layer in the 
network between clients and the Internet. Depending on how 
you deploy the appliance, you may or may not need a Layer 4 
(L4) switch or a WCCP router to direct client traffic to the 
appliance. 
Deployment options include:
  •
Transparent Proxy – Web proxy with an L4 switch
  •
Transparent Proxy – Web proxy with a WCCP router
  •
Explicit Forward Proxy – Connection to a network switch
  •
L4 Traffic Monitor – Ethernet tap (simplex or duplex)
  –
Simplex Mode: Port T1 receives all outgoing traffic, 
and port T2 receives all incoming traffic.
  –
Duplex Mode: Port T1 receives all incoming and 
outgoing traffic.
Note
To monitor true client IP addresses, the L4 traffic 
monitor should always be configured inside the firewall 
and before NAT (Network Address Translation).