4
Plan the Installation
Decide how you are going to configure the Cisco S170 Web
Security Appliance within your network.
The Cisco S170 appliance is typically installed as an additional
layer in the network between clients and the Internet.
Depending on how you deploy the appliance, you may or may
not need a Layer 4 (L4) switch or a WCCP router to direct client
traffic to the appliance.
Deployment options include:
• Transparent Proxy—Web proxy with an L4 switch
• Transparent Proxy—Web proxy with a WCCP router
• Explicit Forward Proxy—Connection to a network switch
• L4 Traffic Monitor—Ethernet tap (simplex or duplex)
Simplex Mode: Port T1 receives all outgoing traffic,
–
and port T2 receives all incoming traffic.
Duplex Mode: Port T1 receives all incoming and
–
outgoing traffic.
Management PC
CONSOLE
Clients
MGMT
P1
L4 Switch/
Ethernet tap
WCCP
Router
P2
T1
T2
Firewall
Simplex/
Duplex
Internet
7