<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA, ISE, with HTTPS in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643866#M10169</link>
    <description>&lt;PRE&gt;WSA S170&lt;/PRE&gt;
&lt;P&gt;This is the end of life last year, I do not believe anything broken cisco can support&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;(Async 9),&lt;/PRE&gt;
&lt;P&gt;stable release and TAC support were 13. X or 14. is the latest, so you need to look at some features that may be not work as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WSA can use ISE for user authentication - but there is some minimum requirements to be in place :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for reference check the below guide :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/guide-c07-741637.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/guide-c07-741637.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 06:39:05 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-07-05T06:39:05Z</dc:date>
    <item>
      <title>WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643796#M10168</link>
      <description>&lt;P class=""&gt;I have an WSA S170 (Async 9), ISE (v2.0), Active Directory, WCCP router, no CDA server&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;With HTTP traffic, I believe it is doable for transparent authentication (WSA &amp;gt; ISE)&lt;/P&gt;&lt;P class=""&gt;However for HTTPS traffic, whereby the WSA should have a browser prompt for user login after enabling HTTPS Proxy, does the WSA also contact the ISE to authenticate users? Or does it need to have integration with AD by itself, directly?&lt;/P&gt;&lt;P class=""&gt;I am trying to avoid the case of WSA contacting AD as it uses SMBv1&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 04:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643796#M10168</guid>
      <dc:creator>irissen</dc:creator>
      <dc:date>2022-07-05T04:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643866#M10169</link>
      <description>&lt;PRE&gt;WSA S170&lt;/PRE&gt;
&lt;P&gt;This is the end of life last year, I do not believe anything broken cisco can support&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;(Async 9),&lt;/PRE&gt;
&lt;P&gt;stable release and TAC support were 13. X or 14. is the latest, so you need to look at some features that may be not work as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WSA can use ISE for user authentication - but there is some minimum requirements to be in place :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for reference check the below guide :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/guide-c07-741637.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/guide-c07-741637.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 06:39:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643866#M10169</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-07-05T06:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643868#M10170</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1374775"&gt;@irissen&lt;/a&gt; if WSA and ISE are integrated using pxGrid, then the WSA has the user information (user/ip binding) to authenticate the users without prompting.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 06:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643868#M10170</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-05T06:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643875#M10171</link>
      <description>&lt;P&gt;thanks, does this mean WSA can run solely off the integration with ISE, without the need to create any realms for AD?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 07:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643875#M10171</guid>
      <dc:creator>irissen</dc:creator>
      <dc:date>2022-07-05T07:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643880#M10172</link>
      <description>&lt;P&gt;thanks, sorry the versions are quite old and out of support.&lt;/P&gt;&lt;P&gt;when you say some features may not work as expected, is there an experience or issue that was known?&lt;/P&gt;&lt;P&gt;also concerned that with the old versions, is it feasible at all?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 07:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643880#M10172</guid>
      <dc:creator>irissen</dc:creator>
      <dc:date>2022-07-05T07:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643943#M10173</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1374775"&gt;@irissen&lt;/a&gt; as per the guide below, WSA obtains ISE (user/IP mappings) and AD group information for authenticated users from ISE using ERS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/guide-c07-741637.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/guide-c07-741637.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 810px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/155182i777F4A1D1B07F1D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 09:09:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643943#M10173</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-05T09:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643951#M10174</link>
      <description>&lt;P&gt;its been Long time worked on WSA aysnc 9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check the configuration guide : (its possible for radius authentication)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/wsa/wsa9-0/WSA_9-0-0_UserGuide.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/wsa/wsa9-0/WSA_9-0-0_UserGuide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 09:30:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643951#M10174</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-07-05T09:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643961#M10175</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1374775"&gt;@irissen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am referring form userguide 14.0 but that could be the same&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly notice that&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa_14-0/User-Guide/b_WSA_UserGuide_14_0.pdf" target="_blank"&gt;User Guide for AsyncOS 14.0 for Cisco Web Security Appliances - GD (General Deployment)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;page 88&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;under section : Identifying Users Transparently&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[1]&amp;nbsp;When you configure an Identification Profile to transparently identify users, the authentication surrogate must be&lt;STRONG&gt; IP address&lt;/STRONG&gt;. You cannot select a different surrogate type.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[2] From identification profile on the policies which are sets to authenticate users please select “Transparently identify users with authentication realms”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the latest version of ISE and WSA compatibility Matrix, maybe it help you to decide clearly regarding the upgrade plan&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/wsa/ise-matrix/ise-compatability-matrix-for-swa.html" target="_blank"&gt;ISE Compatibility Matrix for Secure Web Appliance - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;++++ &amp;nbsp; If you find this answer helpful, please rate it as such&amp;nbsp;&amp;nbsp;++++&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 09:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4643961#M10175</guid>
      <dc:creator>amojarra</dc:creator>
      <dc:date>2022-07-05T09:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4646401#M10176</link>
      <description>&lt;P&gt;okay thanks&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 01:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4646401#M10176</guid>
      <dc:creator>irissen</dc:creator>
      <dc:date>2022-07-08T01:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4646402#M10177</link>
      <description>&lt;P&gt;thanks Rob&lt;/P&gt;&lt;P&gt;if directly reading from the diagram, WSA should purely rely on ISE for identifying user-IP mappings.&lt;/P&gt;&lt;P&gt;I guess the next question would be.. does the ISE also use SMBv1 to connect with AD?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 01:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4646402#M10177</guid>
      <dc:creator>irissen</dc:creator>
      <dc:date>2022-07-08T01:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4646405#M10178</link>
      <description>&lt;P&gt;hi amojarra,&lt;/P&gt;&lt;P&gt;i think my version does not have this option.. for authentication realms are given as Kerberos and LDAP only. ISE is a separate section by itself. Asked my question specifically for Async 9.0, as I am in a situation with no possible means to upgrade &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 01:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4646405#M10178</guid>
      <dc:creator>irissen</dc:creator>
      <dc:date>2022-07-08T01:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: WSA, ISE, with HTTPS</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4647439#M10179</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1374775"&gt;@irissen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is so sad that you can not upgrade at this moment, hope things gets well soon &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;According to the user guide :&amp;nbsp;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/wsa/wsa9-0/WSA_9-0-0_UserGuide.pdf" target="_blank"&gt;User Guide for AsyncOS 9.0 for Cisco Web Security Appliances - LD (Limited Deployment)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;page 132 E-Book, there is an option :&amp;nbsp; &lt;STRONG&gt;Fallback to Authentication Realm or Guest Privileges&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have another Realm with AD and this option is configured to use that realm, then WSA will try connect to AD if Auth failed with ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For ISE V2.0, what I can see in&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_2x.html#reference_94BE6ABB85BC47C8AEC29EF8D286E6E4" target="_blank"&gt;Active Directory Integration with Cisco ISE 2.x - Cisco&lt;/A&gt; under section "&lt;STRONG&gt;Network Ports That Must Be Open for Communication"&amp;nbsp;&lt;/STRONG&gt;ISE is using MSRPC instead of SMB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from release note :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/admin_guide/b_ise_admin_guide_20.pdf" target="_blank"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.0&lt;/A&gt;&amp;nbsp;page 225 E-book :&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Cisco ISE 1.3 and above support SMB 2.0.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;++++ &amp;nbsp; If you find this answer helpful, please rate it as such&amp;nbsp;&amp;nbsp;++++&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 23:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ise-with-https/m-p/4647439#M10179</guid>
      <dc:creator>amojarra</dc:creator>
      <dc:date>2022-07-08T23:13:44Z</dc:date>
    </item>
  </channel>
</rss>

