
What is a reverse proxy?
The Blue Coat ProxySG provides the basis for a robust and flexible Web communications solution. In addition to Web policy management, content filtering, blocking, web content virusscanning and network protection, companies can implement what is known as a reverse proxy to front end their Web applications. Implementing a reverse proxy with a ProxySG has the following advantages:
- The ProxySG terminates the session with the client and establishes another session with the Web server
- The Web server only sees the IP address of the ProxySG
- An administrator can implement granular policies with authentication, authorization and logging
- A company can achieve higher performance benefits with caching
Implementing a reverse proxy solution with Blue Coat
Reverse proxy with the Blue Coat ProxySG provides flexibility to network administrators in defining scalable proxy hierarchy designs. The following key features can be implemented:
- Forwarding to an upstream Web Server
- Load balancing of multiple Web Servers
- L3, L4 and L7 health checks of the upstream Web Servers
- Configure Advanced Forwarding hosts
- Configure Advanced Forwarding rules
- Test the configuration
Step 1 – Configuring Advanced Forwarding Host
To install the advanced forwarding configuration, open the web GUI interface on the ProxySG.
Go to Configuration | Forwarding | Forwarding Hosts
Click on install for "Install Local File from: Text Editor"
Into the text editor, paste the configuration:
Fwd_host <webserveralias> <ip_address or hostname of the web server> http=<server port> server
Step 2 – Configure Advanced Forwarding rules
The advanced forwarding rules are implemented via the Visual Policy Manager.
Open the Visual Policy Manager
Create a Forwarding Layer called "forwarding"
Then, create a rule with the following attributes and shown in the following screens:
Source= any
Destination = url=www.foo.com (what users will type in their browsers ie url seen by users)
Service = any
Action = Select Forwarding
Time = any
Tracking = none
Click on OK.
Click OK twice.
Finally, click on Install Policy
In this example the local ProxySG is 195.149.44.49 and the web server www.server.com is 195.149.44.201.
All requests not in cache for www.foo.com will be forwarded to the web server at 195.149.44.201.
Step 3 – Test your configuration
To validate that Reverse Proxy is working, enable URL logging
Blue Coat Management GUI | Access Logging Category | Default Facility | check Main facility
Look at the Security Appliance’s current logs
Blue Coat Statistics GUI | Access Logging category | Log Facility tab | Select Main
Observe the last couple entries so you can recognize the fields
DEFAULT_PARENT/WebserverIPAddress

Copyright © 2007 Blue Coat Systems, Inc. All rights reserved worldwide. No part of this document may be reproduced by any means nor translated to any electronic medium without the written consent of Blue Coat Systems, Inc. Specifications are subject to change without notice. Information contained in this document is believed to be accurate and reliable, however, Blue Coat Systems, Inc. assumes no responsibility for its use, Blue Coat is a registered trademark of Blue Coat Systems, Inc. in the U.S. and worldwide. All other trademarks mentioned in this document are the property of their respective owners. v.TP-AAA-v1-1007
Blue Coat Systems, Inc. 1.866.30.BCOAT // 408.220.2200 Direct // 408.220.2250 Fax // www.bluecoat.com
