<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
  <head runat="server">
    <!-- PageID 382 - published by RedDot 7.5 - 7.5.1.69 - 22111 -->
    <META name="PublicArticle" content="True" />
    <META http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <META name="keywords" />
    <META name="summary" />
    <META name="product" content="fp_web" />
    <META name="version" content="v85" />
    <META name="book" content="Content Gateway Manager Help, v8.5.x" />
    <title>Content Gateway IP spoofing</title>
    <!--Loading the 2016 fonts.-->
    <script type="text/javascript" src="//fast.fonts.net/jsapi/c504d579-e135-4f75-8335-4906f6c6ce67.js"></script>
    <!--Library content styles.-->
    <link rel="StyleSheet" href="https://help.forcepoint.com/docs/ni/assets/css/help2016.css" type="text/css" media="all" />
    <!--2016 font support -->
    <link type="text/css" rel="stylesheet" href="//fast.fonts.net/cssapi/c504d579-e135-4f75-8335-4906f6c6ce67.css" />
  </head>
  <body>
    <!--googleoff: all-->
    <a href="https://www.forcepoint.com">
      <img class="logo" alt="Forcepoint logo" src="https://help.forcepoint.com/docs/ni/assets/logo1.png" />
    </a>
    <div class="extLinksContainer">
      <a class="extLinks" href="//support.forcepoint.com/documentation">Documentation</a> | <a class="extLinks" href="//support.forcepoint.com">Support</a></div>
    <!--
		<wsApp:UserAccess ID="useraccess1" runat="server" IsSecure="False" />
		-->
    <div class="spacer1"></div>
    <br />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="additional_proxy.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="configure_ip_spoofing.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="wcg_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="additional_proxy.aspx">Additional Proxy Configuration</a> &gt; Content Gateway IP spoofing</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <!--googleon: all-->
    <div>
      <div class="N1H-Heading1"><a name="598550">Content Gateway IP spoofing</a></div>
      <div class="IN-TopicInfo"><a name="603849">Help | Content Gateway | v8.5.x</a></div>
      <div class="B-Body"><a name="603858">IP spoofing is sometimes used to support upstream activities that require the client IP address or a specific IP address. It also results in origin servers seeing the client or specified IP address instead of the proxy IP address (although the proxy IP address can be a specified IP address; more below).</a></div>
      <div class="B-Body"><a name="598074">Content Gateway IP spoofing support has the following features and restrictions:</a></div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598076">IP spoofing is supported for HTTP and HTTPS traffic only.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598077">When IP spoofing is enabled, it is applied to both HTTP and HTTPS. It cannot be configured for only one protocol.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598078">HTTPS traffic is spoofed whether SSL support is enabled or not.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598079">IP spoofing relies on the ARM.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="602186">In transparent proxy deployments using WCCP and IP spoofing, with GRE or L2 mode negotiation, neither HASH nor MASK are supported on the source port or source port/source IP address.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598080">IP spoofing is </a><span class="B-Bold">not</span> supported with edge devices such as a Cisco ASA or PIX firewall. When this is attempted, requests made by Content Gateway using the client IP address are looped back to Content Gateway.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="600960">IP spoofing requires all IP addresses in the same routing path use the same format. That is, all IP addresses must be either IPv6 or IPv4. A combination of IPv6 and IPv4 addresses is not supported.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="F-Frame"><a name="598090">&nbsp;</a></div>
      <table class="ImpTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="WI-WarnIcon">
              <img src="caution_icon.gif" alt="*" border="0" width="38" height="34" /><a name="598085">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="W-Warning">Warning<a name="598087">&nbsp;</a></div>
            <div class="NT-NoteText"><span class="B-Bold"><a name="598088">Deploying IP spoofing requires precise control of the routing paths on your network, overriding the normal routing process for traffic running on TCP port 80 and 443. When configured with either transparent or explicit proxy, return traffic must be routed back to the proxy.</a></span></div>
            <div class="NT-NoteText"><a name="601177">For assistance, please contact your network equipment vendor or Technical Support.</a></div>
            <div class="NT-NoteText"><a name="598089">With IP spoofing enabled, traditional debugging tools such as </a><span class="B-Bold">traceroute</span> and <span class="B-Bold">ping</span> have limited utility.</div>
          </td>
        </tr>
      </table>
      <div class="F-Frame"><a name="598098">&nbsp;</a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="II-ImpIcon">
              <img src="important.gif" alt="*" border="0" width="30" height="34" /><a name="598093">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="IMP-Important">
              <span class="Bold">Important</span><a name="598095">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="598096">For a discussion of how the proxy kernel routing table impacts transparent proxy deployment, see the Solution Center article titled, </a><span class="URL-URL"><a href="https://help.forcepoint.com/support/article/t-kbarticle/Web-sites-in-the-Static-or-Dynamic-bypass-list-fail-to-connect-1258048533319" target="external_window">Web sites in the Static or Dynamic bypass list fail to connect</a></span>.</div>
          </td>
        </tr>
      </table>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="598100">Range-based IP spoofing</a></div>
      <div class="B-Body"><a name="598101">Range-based IP spoofing supports groupings of clients (IP addresses and IP address ranges) that are mapped to specified IP addresses.</a></div>
      <div class="B-Body"><a name="598102">Among other uses, range-based IP spoofing facilitates:</a></div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598103">The delivery of web-hosted services when the identification is by source IP address. For example, to receive a web-hosted service, an organization might be required to identify membership to the service via a known IP address.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598104">IP address-based authentication with an external service when a unique IP address represents a group of users.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><a name="598105">A way to configure traditional IP spoofing for some clients (source IP addresses that don't match any group are spoofed with their own IP address), range-based IP spoofing for some clients, and standard proxy IP address substitution for some clients. The latter is done by creating a group that specifies the proxy IP address. </a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="F-Frame"><a name="598113">&nbsp;</a></div>
      <table class="ImpTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="II-ImpIcon">
              <img src="important.gif" alt="*" border="0" width="30" height="34" /><a name="598108">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="IMP-Important">
              <span class="Bold">Important</span><a name="598110">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="598111">Range-based IP Spoofing is not supported on many older versions of Cisco IOS firmware. To avoid problems, update your Cisco device to the latest firmware.</a></div>
            <div class="NT-NoteText"><a name="599359">IP Spoofing is supported for IPv6. However, range-based IP Spoofing is not supported for IPv6.</a></div>
          </td>
        </tr>
      </table>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="598114">IP spoofing and the flow of traffic</a></div>
      <div class="B-Body"><a name="598115">When IP spoofing is used with WCCP, HTTP and HTTPS traffic flows as follows. The numbers in the diagram correspond to the actions described in the numbered list. (Note that policy-based routing can be implemented to achieve the same results.)</a></div>
      <div class="F-Frame"><a name="598119"><img class="Default" src="images/IP_Spoofing.gif" width="197" height="326" style="display: block; left: 0.0; top: 0.0" alt="" /></a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="598120">A client request arrives at a routed port or Switched Virtual Interface (SVI) looking for traffic with a destination port of HTTP (80) or HTTPS (443).</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="598121">The switch redirects the client request to Content Gateway. </a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="598122">If needed, the proxy creates a connection to the origin server using the client IP address or specified IP address (range-based IP spoofing). </a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">3.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="598123">The request is sent to the origin server through the switch, NAT and/or firewall.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">4.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="598124">When the origin server response is returned, the IP packet has the substituted IP address as the destination (client or specified IP address).</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">5.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="598125">The origin server response arrives at a routed port or Switched Virtual Interface (SVI) looking for traffic with a source port of HTTP&nbsp;(80) or HTTPS (443). See the note below.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">6.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="598126">The switch redirects the origin server response to the proxy, completing the proxy-to-origin server TCP connection.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">7.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="598127">A proxy response to the client is generated and returned to the client on the proxy-to-client TCP connection.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="F-Frame"><a name="598134">&nbsp;</a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="NI-NoteIcon">
              <img src="note.gif" alt="*" border="0" width="33" height="33" /><a name="598130">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="N-Note">Note<a name="598132">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="598133">When IP spoofing is enabled, the proxy advertises a reverse service group for each enabled WCCP service. The reverse service group must be applied along the return path of the proxy.</a></div>
          </td>
        </tr>
      </table>
      <div class="B-Body"><a name="598135">WCCP service group IDs are user defined and must be programmed on the WCCP devices and in Content Gateway (see </a><span class="LEM-LinkEmphasis"><a href="wccp_cnfg_serv_groups.aspx" title="Configuring service groups on the WCCP device">Configuring service groups on the WCCP device</a></span> and <span class="LEM-LinkEmphasis"><a href="wccp_wcg_service_groups.aspx" title="Configuring service groups in the Content Gateway manager">Configuring service groups in the Content Gateway manager</a></span>). </div>
      <div class="B-Body"><a name="598173">The following definitions are suggested.</a></div>
      <table class="BodyTable" style="text-align: left" summary="">
        <caption></caption>
        <tr>
          <td style="background-color: #666465; border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: 2px; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: 2px; border-top-color: #808080; border-top-style: solid; border-top-width: 2px; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CH-CellHeading"><a name="598144">Service ID</a></div>
          </td>
          <td style="background-color: #666465; border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: 2px; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: 2px; border-top-color: #808080; border-top-style: solid; border-top-width: 2px; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CH-CellHeading"><a name="598146">Port</a></div>
          </td>
          <td style="background-color: #666465; border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: 2px; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: 2px; border-top-color: #808080; border-top-style: solid; border-top-width: 2px; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CH-CellHeading"><a name="598148">Traffic Type</a></div>
          </td>
        </tr>
        <tr>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598150">0</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598152">destination port 80</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598154">HTTP</a></div>
          </td>
        </tr>
        <tr>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598156">20</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598158">source port 80</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598160">HTTP</a></div>
          </td>
        </tr>
        <tr>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598162">70</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598164">destination port 443</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598166">HTTPS (HTTPS support must be enabled)</a></div>
          </td>
        </tr>
        <tr>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598168">90</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598170">source port 443</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="598172">HTTPS</a></div>
          </td>
        </tr>
      </table>
      <div class="B-Body"><span class="B-Bold"><a name="598174">Policy-based routing</a></span> (PBR) uses access control lists (ACL) to identify and redirect flows. In a PBR deployment, all of the configuration is done on the router and there is no corresponding Content Gateway configuration. PBR deployments have to redirect traffic returning from origin servers from port 80 and 443 to Content Gateway.</div>
    </div>
    <!--googleoff: all-->
    <div class="library_search">
      <form class="support_search" action="/content/kb-search.aspx" method="get">
        <label></label>
        <label></label>
        <input type="text" name="q" value=" Search eSupport" onfocus="if (this.value == ' Search eSupport') {this.value = '';}" onblur="if (this.value == '') {this.value = ' Search eSupport';}"></input>
        <input type="submit" value=" "></input>
      </form>
    </div>
    <br class="clear" />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="additional_proxy.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="configure_ip_spoofing.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="wcg_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="additional_proxy.aspx">Additional Proxy Configuration</a> &gt; Content Gateway IP spoofing</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <div class="extFooterContainer">
      <div class="extFooter">
        <div align="center">Copyright 2023 Forcepoint. All rights reserved.</div>
      </div>
    </div>
    <SCRIPT>
   function getFileName() {
      //this gets the full url
      var url = document.location.href;
      //this removes the anchor at the end, if there is one
      url = url.substring(0, (url.indexOf("#") == -1) ? url.length : url.indexOf("#"));
      //this removes the query after the file name, if there is one
      url = url.substring(0, (url.indexOf("?") == -1) ? url.length : url.indexOf("?"));
      //this removes everything before the last slash in the path
      url = url.substring(url.lastIndexOf("/") + 1, url.length);
      //return
      return url;
   }

   var url = document.URL;
   var Docname = getFileName()
   s.pageName = "enu:support:technical library:v85xwcg_help:" + Docname;
   s.prop1 = "enu:support";
   s.prop2 = "enu:support:technical library";
   s.channel = "support";
   // <!--
   s.server = "<%= System.Environment.MachineName %>";
   //--></SCRIPT>
    <script language="javascript1.1" type="text/javascript">
   /********Do Not alter below this line ***********/
   var s_code = s.t(); if (s_code) document.write(s_code)
   //--&gt;</script>
  </body>
  <!--"GENERALQUARTERSALLHANDSMANYOURSTATIONS"-->
</html>