Manage Proxy Chaining
You can deploy proxy-chaining in your environment for easier migration or proxy transparency. Cisco Secure Access supports proxy-chain traffic on Registered Networks only. Since the Forwarded-For (XFF) HTTP header is not available on traffic for network tunnels, we recommend that you do not send proxy-chain traffic through tunnels.
The Cisco Secure Access secure web gateway (SWG) leverages FQDN anycast routing to forward web traffic to the best possible data center. If the Secure Access DNS resolvers are used, and an on-premises proxy can use an FQDN-based URL to define the upstream proxy, then FQDN anycast should be used.