https://community.sophos.com/kb/en-us/115865
On the 'Advanced' tab:
Transparent:
- No changes are needed to the client browser settings.
- Only HTTP (and HTTPS if selected) is handled by the proxy; all other allowed traffic passes via Packet Filter (Firewall) rule.
- The 'Transparent mode skiplist' is used to determine for which devices (IP addresses) the proxy is skipped.
Standard:
- On the clients, you must change 'Internet Options' to use the proxy by indicating the address of the Astaro on port 8080.
- All of the 'Allowed target services' are handled by the proxy.
- The 'Transparent mode skiplist' does not apply. Skipping the Proxy is configured on the client in 'Internet Options'.
- Clients can be configured using the 'Proxy Auto Configuration' instead of making the changes in each. If you have an Active Directory server, you can use a Group Policy to configure each logged-in user's Internet Options.
Standard allows you to block https sites without scanning the content.