Skip to main content

LevelBlue Named Official Cybersecurity Advisor of the PGA of America. Learn more

LevelBlue Named Official Cybersecurity Advisor of the PGA of America. Learn more

Services
Cyber Advisory
Managed Cloud Security
Data Security
Managed Detection & Response
Email Security
Managed Network Infrastructure Security
Exposure Management
Security Operations Platforms
Incident Readiness & Response
SpiderLabs Threat Intelligence
Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Operational Technology
End-to-end OT security
Microsoft
Unlock the full power of Microsoft Security
Securing the IoT Landscape
Test, monitor and secure network objects
Why LevelBlue
About Us
Awards and Accolades
LevelBlue SpiderLabs
PGA of America Partnership
Secure What's Next
LevelBlue Security Operations Platforms
Security Colony
Partners
Microsoft
Unlock the full power of Microsoft Security
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Loading...
Loading...

HOWTO: Allow MSC to find nearest on-premise proxy

Expand / Collapse


This article applies to:

  • Mobile Security Client (MSC)
  • Secure Web Gateway
  • MS Windows

Problem Description:

  • When there is more than one internal (on-premise) SWG proxy, the MSC is unable to work out which one is closest. This can lead to inefficient routing of web traffic and consequently poor browsing performance.
  • For example, a company has two ‘main’ offices – one in NY and the other one in London. They have SWG scanners installed in both locations. They would like roaming users to use the local scanners when they are on premise. A few more ‘facts’:
    • NY scanners load balancer IP – 10.0.0.2
    • London scanners load balancer IP – 192.168.120.5
    • Each site has its own DNS server

Prerequisits:

Separate DNS servers covering each site are needed. If only one DNS server is used this solution will not work.

Procedure:

How to make this work:

  1. Define the following mapping in the DNS servers on both sites, so that the MSC software can detect that it is on premise:
    • Hostname ON-PREMISE-HOST > 1.1.1.1
  2. Define in NY DNS server the following mapping:
    • Hostname SWG-SCANNING > 10.0.0.2
  3. Define in London DNS server the following mapping:
    • Hostname SWG-SCANNING > 192.168.120.5
  4. In the SWG Policy Server GUI, on the Proxies (On-premise) do the following:
    • Add the following line in the On-premise Proxy Details:
      • SWG-SCANNING              8080       8443
    • In the Corporate Hostname enter ON-PREMISE-HOST
    • In the Internal Hostname IP enter 1.1.1.1 (or click the ‘Resolve IP’ button)
  5. Commit the SWG policy update.
  6. Boot up the PC and allow the MSC run for a few minutes to identify and pull down its new configuration information.


Notes:

V0_1    2012-Aug-23


To contact LevelBlue about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.