We're looking for possible new content/URL filter solution to replace our aging, crappy SmartFilter.
It's a long story, but quick, high-level requirements are:
-Inline (no IFP, or WCCP redirection)
-Citrix Integration
All connections are sourced from XenApp servers.
Any solution can tell which sessions are from which users?
-QoS Marking
We'd like to mark different URL categories w/ different DHCP markings, so that downstream WAN routers can do WRED based on them.
-AD Integration
Every vendor's solution can do it, but question is how well?
BYOD users don't login to the domain to gain access.
Is there anyway to identify their uname/group, w/o explicit captive portal?
Can any vendor's solution do federated SSO w/ our RADIUS server (Cisco ACS 5.4), so that users don't have to login multiple times? (once for network wired/wifi, and second time for content filter)
========================
We're looking at Cisco's CX, and Palo Alto Networks PA-5000.
CX is preferred, since we can just stick an extra module into our ASA's, but it's relatively new, and not as mature as PAN.
If anyone could provide some recommendations I'd really appreciate it.
It's a long story, but quick, high-level requirements are:
-Inline (no IFP, or WCCP redirection)
-Citrix Integration
All connections are sourced from XenApp servers.
Any solution can tell which sessions are from which users?
-QoS Marking
We'd like to mark different URL categories w/ different DHCP markings, so that downstream WAN routers can do WRED based on them.
-AD Integration
Every vendor's solution can do it, but question is how well?
BYOD users don't login to the domain to gain access.
Is there anyway to identify their uname/group, w/o explicit captive portal?
Can any vendor's solution do federated SSO w/ our RADIUS server (Cisco ACS 5.4), so that users don't have to login multiple times? (once for network wired/wifi, and second time for content filter)
========================
We're looking at Cisco's CX, and Palo Alto Networks PA-5000.
CX is preferred, since we can just stick an extra module into our ASA's, but it's relatively new, and not as mature as PAN.
If anyone could provide some recommendations I'd really appreciate it.
Last edited: