Inline proxy deployment requires two network port pairs. This can be accomplished using a Network Security appliance with two port pairs, or one port pair from each of two Network Security appliances.
For details about inline proxy deployment, refer to the Hardware Administration Guide for your appliance model.
Note
Starting with version 7.1.0, the Network Security appliances bypass packets larger than 1650 bytes rather than dropping them.
Operator or Admin access
Configuring inline proxy mode with one Network Security appliance
Use the Policy Settings page for inline proxy mode to configure a deployment with one Network Security appliance with two network port pairs. Interface A connects the LAN-facing switch or router (A1) to the proxy server (A2). Interface B connects the LAN-facing switch or router (B1) to the Internet-facing switch or router (B2).

Operational modes for inline deployment are described in the following table.
Mode | Description |
|---|---|
Block | Blocks malicious traffic (recommended).
|
Monitor | Monitors the traffic and generates alerts on malicious events. |
Bypass | Forced bypass wherein the Network Security appliance neither blocks nor analyzes traffic. |
Use the Settings: Interfaces - Whitelists page for inline whitelists to configure interface A2 to allow incoming traffic from the proxy server to pass through unblocked.

Click the Settings tab.
Click Inline Operational Modes on the sidebar.
Select a blocking option for pair A and pair B. (Inline Block FS Open is recommended).
Click Update: Operational Modes.
Select Inline Whitelists on the sidebar. Enter the information for the proxy server and then click Add Whitelist.
Configuring inline proxy mode with two Network Security appliances
Use the Policy Settings page for inline proxy mode to configure a deployment with two Network Security appliances with one network port pair each. NX Appliance1 connects to the proxy offline, and NX Appliance2 is between a LAN-facing switch or router and an Internet-facing switch or router.

Operational modes for inline deployment are described in the following table.
Mode | Description |
|---|---|
Block | Blocks malicious traffic (recommended).
|
Monitor | Monitors the traffic and generates alerts on malicious events. |
Bypass | Forced bypass wherein the Network Security appliance neither blocks nor analyzes traffic. |
Use the Policy Settings page for inline whitelists to configure interface A2 to allow incoming traffic from the proxy server to pass through unblocked.

Click the Settings tab.
Click Inline Operational Modes on the sidebar.
Select a blocking option for pair A. (Inline Block FS Open is recommended).
Click Update: Operational Modes.
Select Inline Whitelists on the sidebar. Enter the information for the proxy server and then click Add Whitelist.
Click the Settings tab.
Click Inline Operational Modes on the sidebar.
Select a blocking option for pair A. (Inline Block FS Open is recommended).
Click Update: Operational Modes.