6.5.6. Configuring nontransparent rules with inband destination selection

When using inband destination selection, Application-level Gateway extracts the address of the destination server from the traffic. Note the following points:

  • For HTTP connections, create a firewall rule that uses a nontransparent HTTP proxy and inband destination selection. Also, set the web browsers of the clients to use Application-level Gateway as a web proxy.

  • If the clients use a caching web proxy for HTTP traffic, for example, Squid, and Application-level Gateway is located between the clients and the web proxy, then:

    • Create a firewall rule that uses a nontransparent HTTP proxy.

    • Set the parent_proxy and parent_proxy_port attributes of the proxy to the address of the caching proxy.

    • Use a DirectedRouter in the service to redirect the connections to the caching proxy, or use inband destination selection.