300-320 · Question #417
Which ASA to action with Web traffic to treat both HTTP and HTTPS for local internet proxy?
The correct answer is A. Redirect traffic HTTP & HTTPS to WSA using wccp. To transparently redirect both HTTP and HTTPS web traffic to a local Cisco Web Security Appliance (WSA) acting as an internet proxy, the ASA should use WCCP (Web Cache Communication Protocol). WCCP allows the ASA to intercept and redirect HTTP (port 80) and HTTPS (port 443)…
Question
Which ASA to action with Web traffic to treat both HTTP and HTTPS for local internet proxy?
Options
- ARedirect traffic HTTP & HTTPS to WSA using wccp
- BSend traffic for inspection to CWS
- CSend traffic to a different port for http & https monitoring to WSA using L2TP.
- DUse IPS module in ASA for inspection
How the community answered
(21 responses)- A81% (17)
- B10% (2)
- C5% (1)
- D5% (1)
Explanation
To transparently redirect both HTTP and HTTPS web traffic to a local Cisco Web Security Appliance (WSA) acting as an internet proxy, the ASA should use WCCP (Web Cache Communication Protocol). WCCP allows the ASA to intercept and redirect HTTP (port 80) and HTTPS (port 443) traffic to the WSA without requiring any configuration changes on end-user devices - the redirection is transparent. The WSA then performs URL filtering, malware scanning, and policy enforcement before forwarding allowed traffic to the internet. Option B (CWS - Cloud Web Security) sends traffic to Cisco's cloud-based inspection service, not a local on-premises WSA. Option C (L2TP) is a VPN tunneling protocol not designed for web traffic redirection to a proxy. Option D (IPS module) performs inline threat inspection but does not function as an HTTP/HTTPS proxy and cannot perform the URL filtering and content control that a WSA provides.
Topics
Community Discussion
No community discussion yet for this question.