
6
Plan the Installation
Decide how you are going to configure the Cisco S190 Web Security Appliance
within your network.
The Cisco S190 appliance is typically installed as an additional layer in the
network between clients and the Internet. Depending on how you deploy the
appliance, you may or may not need a Layer 4 (L4) switch or a WCCP router to
direct client traffic to the appliance.
Deployment options include:
•
Transparent Proxy—Web proxy with an L4 switch
•
Transparent Proxy—Web proxy with a WCCP router
•
Explicit Forward Proxy—Connection to a network switch
•
L4 Traffic Monitor—Ethernet tap (simplex or duplex)
–
Simplex Mode: Port T1 receives all outgoing traffic, and port T2
receives all incoming traffic.
–
Duplex Mode: Port T1 receives all incoming and outgoing traffic.
Security Services
L4 Traffic Monitor:
•
Monitor only
•
Block
Acceptable Use Controls:
Enable
•
IronPort URL Filters
•
Cisco IronPort Web
Usage Controls
Web Reputation Filters:
Enable
Malware and Spyware Scanning:
•
Enable Webroot
•
Enable McAfee
•
Enable Sophos
Action for Detected Malware:
•
Monitor only
•
Block
IronPort Data Security Filtering:
Enable