CVE-2024-3400: PAN-OS Command Injection Vulnerability in GlobalProtect Gateway. Learn More

CVE-2024-3400: PAN-OS Command Injection Vulnerability in GlobalProtect Gateway. Learn More

Services
Capture
Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

twi-managed-portal-color
Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

twi-briefcase-color-svg
Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

tw-laptop-data
Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

twi-database-color-svg
Database Security

Prevent unauthorized access and exceed compliance requirements.

twi-email-color-svg
Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

tw-officer
Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

tw-network
Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Partners
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats
Loading...
Loading...

PRB: Issues when a NAT router or load balancer is used between browsing users and WebMarshal

Expand / Collapse


This article applies to:

  • WebMarshal

Question

Why are users seeing a large number of abort pages?

Information:

This problem can occur when another proxy device within the local network is configured to use a single credential to forward requests through WebMarshal or when IP authentication is used in a NAT (network address translation) router or load balancer between WebMarshal and the browsing users. The traffic will be treated as being for a unique computer user. The single user will be used when applying browsing rules, evaluating quotas, or showing any file abort notifications triggered by the content analysis rules. This means it is not possible to do reporting on individual usage.

All traffic from the user will appear to come from the IP address of the NAT router or load balancer. By default, WebMarshal can only see that IP address and cannot tell that there are multiple computers. All of these computers will be seen by WebMarshal as a single computer user and browsing rules will be applied accordingly. Quotas will apply to all computers, not just a single computer. File abort notifications will be shown on all computers until acknowledged by any user. All reporting data is logged against a single computer user and therefore it is not possible to do reporting on individual usage.

If a NAT router or load balancer is be used two options are available.

  • In a NAT environment, configure user based authentication. The credentials passed through will be used to identify users.
  • In a load balancing environment, use the X-Forwarded-For based IP authentication ability present in WebMarshal 7.5.0 and above. See the related article linked below.

Notes:

  • If neither user-based authentication nor X-Forwarded-For authentication is available with NAT or load balanced environments, WebMarshal cannot perform any user-based logging or control of browsing activity.
  • If the proxy server or NAT router is able to forward the original user authentication account with requests then the problem should not occur.
  • See the WebMarshal User Guide for supported installation scenarios.

To contact Trustwave about this article or to request support:


Rate this Article:
     
Tags:

Related Articles



Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.