Installation guide
Deployment Primer
2-13
• Simple transparency is not compatible with some older Web browsers when their
HTTP requests do not include information about the host.
• HTTP requests for servers that use a port other than the HTTP default port 80 are
redirected to IWSVA. This means SSL (HTTPS) requests are typically fulfilled, but
the content is not scanned.
• Do not use any source NAT (IP masquerade) downstream of IWSVA, because
IWSVA needs to know the IP address of the client to clean.
• A DNS server is needed for DCS to resolve the client machine name from its IP
address in order to perform a cleanup.
A Layer 4 switch can be used to redirect HTTP traffic to IWSVA. The HTTP Scanning
Service must be enabled in the HTTP Proxy mode.
F
IGURE
2-6.
Using a Layer 4 Switch