Installation guide

Deployment Primer
2-13
Simple transparency is not compatible with some older Web browsers when their
HTTP requests do not include information about the host.
HTTP requests for servers that use a port other than the HTTP default port 80 are
redirected to IWSVA. This means SSL (HTTPS) requests are typically fulfilled, but
the content is not scanned.
Do not use any source NAT (IP masquerade) downstream of IWSVA, because
IWSVA needs to know the IP address of the client to clean.
A DNS server is needed for DCS to resolve the client machine name from its IP
address in order to perform a cleanup.
A Layer 4 switch can be used to redirect HTTP traffic to IWSVA. The HTTP Scanning
Service must be enabled in the HTTP Proxy mode.
F
IGURE
2-6.
Using a Layer 4 Switch