<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WSA will authenticate again in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882612#M323</link>
    <description>&lt;P&gt;WSA will authenticate again if surrogate times out. But it should still be transparent to end user as it needs to re-authenticate the end user. &amp;nbsp;The end user will only receive prompt if authentication is failed.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2016 23:27:52 GMT</pubDate>
    <dc:creator>Tao Yang</dc:creator>
    <dc:date>2016-03-07T23:27:52Z</dc:date>
    <item>
      <title>WSA question</title>
      <link>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882607#M318</link>
      <description>&lt;P&gt;Hi , all&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Nowaday, I meet some questionlike this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;WSA has surrogate type: IP address, &amp;nbsp;Persistent Cookie, &amp;nbsp;Session Cookie.&lt;/P&gt;
&lt;P&gt;I want to know which scenario are they&amp;nbsp;used ?&lt;/P&gt;
&lt;P&gt;If I change "IP Address" to "Session cookie", it will make my origin policy invalidate? It will make which different from "IP Address"?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882607#M318</guid>
      <dc:creator>cunfa xu</dc:creator>
      <dc:date>2019-03-09T01:38:50Z</dc:date>
    </item>
    <item>
      <title>Hello Cunfa,</title>
      <link>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882608#M319</link>
      <description>&lt;P&gt;Hello Cunfa,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In simple, cookie surrogate is used in shared IP scenario, for example terminal server, kiosk server as it is a multiple sessions with same IP. For all other situation, you can use IP surrogate. &amp;nbsp;Here are the details from WSA user guide.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;DIV class="page" title="Page 265"&gt;
&lt;DIV class="section"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;Determines which method the Web Proxy uses to track the user: &lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;• &lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;IP Address. &lt;/SPAN&gt;&lt;SPAN&gt;The Web Proxy allows the user at that IP address to use any web browser or non-browser HTTP process to access the web once the user clicks the link on the end-user acknowledgment page. Tracking the user by IP address allows the user to access the web until the Web Proxy displays a new end-user acknowledgment page due to inactivity or the configured time interval for new acknowledgments. Unlike tracking by a session cookie, tracking by IP address allows the user to open up multiple web browser applications and not have to agree to the end-user acknowledgment unless the configured time interval has expired. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When IP address is configured and the user is authenticated, the Web Proxy tracks users by username instead of IP address. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Session Cookie. &lt;/SPAN&gt;&lt;SPAN&gt;The Web Proxy sends the user’s web browser a cookie when the user clicks the link on the end-user acknowledgment page and uses the cookie to track their session. Users can continue to access the web using their web browser until the Time Between Acknowledgments value expires, they have been inactive longer than the allotted time, or they close their web browser. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the user using a non-browser HTTP client application, they must be able to click the link on the end-user acknowledgment page to access the web. If the user opens a second web browser application, the user must go through the end-user acknowledgment process again in order for the Web Proxy to send a session cookie to the second web browser. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Using a session cookie to track users when the client accesses HTTPS sites or FTP servers using FTP over HTTP is not supported. &lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 07 Mar 2016 03:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882608#M319</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-03-07T03:39:28Z</dc:date>
    </item>
    <item>
      <title>Em....</title>
      <link>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882609#M320</link>
      <description>&lt;P&gt;Em....&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If I change "IP Address" to "Session cookie", will it&amp;nbsp;&amp;nbsp;make my origin policy invalidate?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 05:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882609#M320</guid>
      <dc:creator>cunfa xu</dc:creator>
      <dc:date>2016-03-07T05:30:23Z</dc:date>
    </item>
    <item>
      <title>Surrogate for authentication</title>
      <link>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882610#M321</link>
      <description>&lt;P&gt;Surrogate for authentication will not impact your policy configuration. However it may cause end user being applied the incorrect policy.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 05:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882610#M321</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-03-07T05:35:17Z</dc:date>
    </item>
    <item>
      <title>Dear Tao</title>
      <link>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882611#M322</link>
      <description>&lt;P&gt;Dear Tao&lt;/P&gt;
&lt;P&gt;Em。。。&lt;/P&gt;
&lt;P&gt;So, If I change "IP Address" to "Session cookie" , It may lead to end user policy invalidate. Right?&lt;/P&gt;
&lt;P&gt;And another question&lt;/P&gt;
&lt;P&gt;If "Session cookie/IP Address/persistent cookie" time out, will it pop authentication windows?Thanks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sincerely Yours&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 05:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882611#M322</guid>
      <dc:creator>cunfa xu</dc:creator>
      <dc:date>2016-03-07T05:55:38Z</dc:date>
    </item>
    <item>
      <title>WSA will authenticate again</title>
      <link>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882612#M323</link>
      <description>&lt;P&gt;WSA will authenticate again if surrogate times out. But it should still be transparent to end user as it needs to re-authenticate the end user. &amp;nbsp;The end user will only receive prompt if authentication is failed.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 23:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/wsa-question/m-p/2882612#M323</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-03-07T23:27:52Z</dc:date>
    </item>
  </channel>
</rss>

