
transparent - Manage the transparent web proxy
[1] transparent [raz | (add (internal | auxiliary | vpnipsec) <ip> [<network-mask> [<qos%>]]) | (del (internal | auxiliary | vpnipsec) <ip> <network-mask>)]
When transparent mode is activated, the system transparently intercepts incoming web traffic and processes it in the same way as traffic destined for the system’s web proxy (in web mode). The intercepted traffic includes clear http traffic as well as encrypted https traffic, which can be processed at the TLS/SNI (Server Name Indication) level only. When SSL mediation is activated in transparent mode, https traffic is fully decrypted and processed in the same way as http traffic.
This command is used to limit the transparent mode to specified web traffic only. If no transparent traffic is defined, the system acts as a transparent web gateway (web proxy) for all web traffic incoming from the internal (web in vlan mode), auxiliary and vpnipsec interfaces. If at least one transparent web traffic is defined, the system acts as a transparent web gateway only for specified web traffic. A transparent web traffic is identified by two parameters: the network interface via which it enters into the system and its source IP address.
Traffic bandwidths can also be customised for transparent networks by setting the optional <qos%> parameter. The <qos%> value is a percentage of the ingress or egress bandwidth allocated to tweb (transparent web) traffic and should be an integer between 1 and 100. Ingress and egress bandwidth values to which the percentage is applied are as follows:
• For web traffic exchanged via the native internal network interface or the 802.1q pseudo network interface called web (in vlan mode), the ingress and egress bandwidths to consider are defined with the command usage form qos shape tweb internal.
• For web traffic exchanged via the auxiliary network interface, the ingress and egress bandwidths to consider are defined with the command usage form qos shape tweb auxiliary.
If no <qos%> value is specified, a default value of 100% is used. If a <qos%> value is specified for the vpnipsec interface, it is ignored, as IPsec VPN traffic flows through encrypted tunnels and therefore cannot be identified for the purpose of applying traffic shaping.
access(1), apply(1), cache(1), guard(1), mode(1), qos(1), sslmediate(1), tweb(1), vlan(1)
CacheGuard Technologies <www.cacheguard.com>
Send bug reports or comments to the above author.
Copyright (C) 2009-2026 CacheGuard Technologies - All rights reserved