Quote:
Originally Posted by RayPesek We also use it for Outlook Web Access publishing because ISA has SSL termination, something that I think is a major omission in FW-1. |
I'll second that one. There is a third party PCI card that will allow SSL termination & inspection on the gateway. Of course Check Point will tell you to buy a Connectra for this :)
There are deffinet pro and cons to proxy servers. I personally like them, epically when MS patches come out and during snow storms when everyone is hitting the same site. On the bad side, I don't have any logging or control at the firewall.
Now if someone was to write an OPSEC module for Squid that let me push policy to it and send log back to the SmartCenter it would make me happy.