Cisco Cisco Web Security Appliance S670 Guida Utente

Pagina di 494
2-11
AsyncOS 9.1.1 for Cisco Web Security Appliances User Guide
 
Chapter 2      Connect, Install, and Configure
  System Setup Wizard
Network / Routes for Management and Data Traffic
Note
If you enable “Use M1 port for management only”, this section will have separate sections for 
management and data traffic; otherwise one joint section will be shown.
Network / Transparent Connection Settings
Note
By default, the Cloud Connector is deployed in transparent mode. which requires a connection 
to a Layer-4 switch, or a version 2 WCCP router.
Property
Description
Default Gateway
The default gateway IP address to use for the traffic through the Management and 
Data interfaces.
Static Routes 
Table
Optional static routes for management and data traffic. Multiple routes can be added. 
Name – A name used to identify the static route.
Internal Network – The IPv4 address for this route’s destination on the network.
Internal Gateway – The gateway IPv4 address for this route. A route gateway 
must reside on the same subnet as the Management or Data interface on which 
it is configured.
Property
Description
Layer-4 Switch or 
No Device
Specifies that the Web Security appliance is connected to a layer 4 switch for 
transparent redirection, or that no transparent redirection device is used and clients 
will explicitly forward requests to the appliance.
WCCP v2 Router
Specifies that the Web Security appliance is connected to a version 2 
WCCP-capable router.
If you connect the appliance to a version 2 WCCP router, you must create at 
least one WCCP service. You can enable the standard service on this screen, or 
after the System Setup Wizard is finished, where you can also create multiple 
dynamic services.
When you enable the standard service, you can also enable router security and 
enter a passphrase. The passphrase used here must be used all appliances and 
WCCP routers within the same service group. 
A standard service type (also known as the “web-cache” service) is assigned a 
fixed ID of zero, a fixed redirection method (by destination port), and a fixed 
destination port of 80.
A dynamic service type allows you to define a custom ID, port numbers, and 
redirection and load balancing options.