Hi
I am using Wingate 7
I am using the WGIC on user PCs to prevent any unauthorized programs from gaining HTTP access, which is great.
I am also using the new Puresight and the WWW proxy service is enabled and intercepting port 80 so that the Winsock Redirector service can pass HTTP traffic from a WGIC connected PC through to Puresight.
All of the above works great, except for one thing: Port 80 on the Wingate PC is now open on the same internal ethernet adapter that is used to connect to the WGIC PC. This means a PC user can quit the WGIC application and then surf through port 80 of the proxy on the Wingate PC.
I tried changing the proxy port to 8888 so I can block it with a Policy on the adapter but I still had to intercept port 80 for puresight to work, and then the proxy is open on port 80 on the adapter again.
I have tried various policies checking the source port of the connecting client hoping I could find port 2080 of the Winsock redir service so I can allow those connects through to the WWW proxy and dump the rest ( coming from outside on the LAN ).
How can I create a policy that can determine if a client connects via the local Winsock redirector service or from the internal adapter ( from the LAN ) ?
If I know how to do this, I can block clients connecting to the WWW proxy without using the WGIC.
Please help, I really need to get this working!
Thanks
Deon.