Contents

Related Topics

About Proxy Actions

A proxy action is a specific group of settings, sources, or destinations for a type of proxy. Because your configuration can include several proxy policies of the same type, each proxy policy uses a different proxy action. Each proxy policy has predefined, or default, proxy actions for clients and servers. For example, you can use one proxy action for packets sent to a POP3 server protected by the Firebox, and a different proxy action to apply to email messages retrieved by POP3 clients. You can clone, edit, and delete proxy actions in your Firebox configuration.

Fireware proxy actions are divided into two categories: predefined proxy actions, and user-defined proxy actions. The predefined proxy actions are configured to balance the accessibility requirements of a typical company, with the need to protect your computer assets from attacks. You cannot change the settings of predefined proxy actions. Instead, you must clone (copy) the existing predefined proxy action definition and save it as a new, user-defined proxy action. For example, if you want to change a setting in the POP3-Client proxy action, you must save it with a different name, such as POP3-Client.Standard.1.

The predefined proxy actions that have "Standard" appended to the proxy action name are updated from previous defaults to reflect the latest Internet network traffic trends.

You can create many different proxy actions for either clients or servers, or for a specified type of proxy policy. However, you can assign only one proxy action to each proxy policy. For example, a POP3 policy is linked to a POP3-Client proxy action. If you want to create a POP3 proxy action for a POP3 server, or an additional proxy action for POP3 clients, you must add new POP3 proxy policies to Policy Manager that use those new proxy actions.

For an HTTP proxy policy, you can select a proxy action or a content action. For information about content actions, see About Content Actions.

Set the Proxy Action in a Proxy Policy

To set the proxy action for a proxy policy when you add a new policy, from Fireware Web UI.

  1. Select Firewall > Firewall Policies.
    The Firewall Policies page appears.
  2. Click Add Policy.
    The Select a policy type page appears.
  3. Select Proxies.
  4. From the Proxies drop-down lists, select the proxy policy and proxy action for this policy.
  5. Click Add Policy.

To change a proxy action for an existing proxy policy:

  1. Select Firewall > Firewall Policies.
    The Firewall Policies page appears.
  2. Select the proxy policy you want to change.
    The Edit page appears.
  3. Select the Proxy Action tab.
  4. From the Proxy Action drop-down list, select the proxy action to use with this policy.
  5. Click Save.

To set the proxy action for a proxy policy when you add a new policy, from Policy Manager.

  1. Add or edit a proxy policy.
    The New/Edit Policy Properties dialog box appears, with the Policy tab selected.
  2. From the Proxy action drop-down list, select the proxy action to use with this proxy policy.
  3. Click OK.

Clone, Edit, or Delete Proxy Actions

To manage the proxy actions for your Firebox, you can clone, edit, and delete proxy actions. You can clone, edit, or delete any user-defined proxy action. You cannot make changes to predefined proxy actions, or delete them. You also cannot delete user-defined proxy actions that are used by a policy.

If you want to change the settings in a predefined proxy action, you can clone it and create a new, user-defined proxy action with the same settings. You can then edit the cloned proxy action to modify the settings as necessary. If you choose to edit a predefined proxy action, you cannot save your changes. Instead, you are prompted to clone the changes you have made to a new, user-defined proxy action.

When you edit a proxy action, you can change the rules and rulesets, and the associated actions. Each proxy action includes proxy action rules, which are organized into categories. Some categories are further subdivided into subcategories of rules.

For more information on the available proxy action settings for each proxy, see the About topic for that proxy.

About the DNS-Proxy About the IMAP-Proxy
About the FTP-Proxy About the POP3-Proxy
About the FTP-Proxy About the SMTP-Proxy
About the H.323-ALG About the SIP-ALG
About the HTTP-Proxy About the TCP-UDP-Proxy
About the HTTPS-Proxy  

Clone or Edit a Proxy Action

You can clone both predefined and user-defined proxy actions. You cannot edit a predefined proxy action. Instead, you must clone the predefined proxy action and then edit the cloned proxy action. You can always edit a user-defined proxy action.

To clone or edit a proxy action, from Fireware Web UI:

  1. Select Firewall > Proxy Actions.
    The Proxy Actions page appears.

Screen shot of the Proxy Actions page

  1. Select the proxy action to clone or edit.
  2. Click Clone or Edit.

If you selected to clone a proxy action, the Clone Proxy Action page appears.

Screen shot of the Clone Proxy Action page

If you selected to edit a proxy action, the Edit Proxy Action page appears.

Screen shot of the Edit Proxy Action page

  1. Select a category tab to see the options for that category.
    If the category you selected includes subcategories, a drop-down list expands to show the available subcategories. Select a subcategory.
    The content for the selected category appears. .

Screen shot of the Edit Proxy Action HTTP Request settings for the HTTP-Client proxy action

  1. Edit the rules and settings for the proxy action for all the necessary categories.
  2. Save the settings.

You can also clone a proxy action when you edit the configuration of a proxy policy that uses a predefined proxy action.

  1. From the Edit page for a proxy, select the Proxy Action tab.
  2. From the Proxy Action drop-down list, select Clone the current proxy action.
    The proxy action settings appear.
  3. In the Name text box, type a new name for the proxy action.
  4. Configure the settings for the proxy action.
  5. Click Save.

To clone or edit a proxy action, from Policy Manager:

  1. Select Setup > Actions > Proxies.
    The Proxy Actions dialog box appears.

Screen shot of the Proxy Actions dialog box

  1. Select the proxy action to clone or edit.
  2. Click Clone or Edit.

If you selected to clone a proxy action, the Clone Proxy Action Configuration dialog box appears, with the available categories displayed in the Categories tree.

Screen shot of the Clone Proxy Action Configuration dialog box

If you selected to edit a proxy action, the Edit Proxy Action Configuration dialog box appears, with the available categories displayed in the Categories tree.

Screen shot of the Edit Proxy Action Configuration dialog box

  1. From the Categories tree, select a category.
    The page for the selected category appears.
  2. Edit the rules and settings for the proxy action for all the necessary categories.
  3. Save the settings.

Delete a Proxy Action

You cannot delete predefined proxy actions. You can only delete user-defined proxy actions that are not used by a policy.

To delete a proxy action, from Fireware Web UI:

  1. Select Firewall > Proxy Actions.
    The Proxy Actions page appears.

Screen shot of the Proxy Actions page

  1. Select the proxy action to delete.
  2. Click Remove.
    A confirmation dialog box appears.
  3. To delete the proxy action, click Yes.
    The proxy action is removed from your device configuration.

To delete a proxy action, from Policy Manager:

  1. Select Setup > Actions > Proxies.
    The Proxy Actions dialog box appears.

Screen shot of the Proxy Actions dialog box

  1. Select the proxy action to delete.
  2. Click Remove.
    A confirmation dialog box appears.
  3. To delete the proxy action, click Yes.
    The proxy action is removed from your device configuration.

Import or Export Proxy Actions

If you manage several Fireboxes and want to add the same proxy actions to each one, you can save time and use the proxy action import/export function. This enables you to define the proxy actions on one Firebox, export them to a text file, and then import the proxy actions on another Firebox.

For more information, see Import and Export User-Defined Proxy Actions.

See Also

About Proxy Policies and ALGs

Give Us Feedback     Get Support     All Product Documentation     Technical Search