<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ironport incorrectly blocking &amp;quot;shopping&amp;quot; from IT Admin in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899884#M2205</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that.&amp;nbsp; I really like the grep and tail the logs.&amp;nbsp; It's like an instant way to see what's going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I did this and today the site is not blocked!!&amp;nbsp; Weird how it would be blocked one day but not the next. Oh well, at least I got the nifty grep command out of it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess what took me back is that I'm in the IT identity group which does not block much at all.&amp;nbsp; Shopping is especially not blocked as we make online purchases for various busness needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Mar 2012 14:44:07 GMT</pubDate>
    <dc:creator>keithsauer507</dc:creator>
    <dc:date>2012-03-07T14:44:07Z</dc:date>
    <item>
      <title>Ironport incorrectly blocking "shopping" from IT Admin</title>
      <link>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899882#M2203</link>
      <description>&lt;P&gt;I'm trying to order a laptop locker from a website for busness purposes.&amp;nbsp; Sure I can go into the IronPort and whitelist the site, but I want to know why the IronPort is so flaky like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error I'm getting is this (sanitised domain name and username):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P align="center" style="color: #000000; font-family: sans-serif; font-size: large;"&gt;&lt;STRONG&gt;The website you are trying to access is blocked.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #000000; font-family: 'Times New Roman'; text-align: -webkit-auto; font-size: medium;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #000000; font-family: 'Times New Roman'; text-align: -webkit-auto; font-size: medium;" /&gt;&lt;/P&gt;&lt;TABLE style="font-family: 'Times New Roman';"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;Blocked Site:&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;&lt;STRONG&gt;www.schoollockers.com&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;Blocked Category:&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;&lt;STRONG&gt;Shopping&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;User:&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;&lt;STRONG&gt;DOMAINNAME\username@Windows&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;User Group:&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;&lt;STRONG&gt;BLOCK_WBRS_11-Information_Technology-Authenticated_Users-NONE-NONE-NONE-NONE&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;Reauth_URL:&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: white; border-color: gray; border-style: none; padding: 1px;"&gt;&lt;P&gt;&lt;STRONG&gt;-&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt; &lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; text-align: -webkit-auto; font-size: medium;"&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;Base64Decode&lt;/SPAN&gt; &lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;error '800a0001'&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; text-align: -webkit-auto; font-size: medium;"&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;Bad Base64 string.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: 'Times New Roman'; text-align: -webkit-auto; font-size: medium;"&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;/ironport/blocked.asp&lt;/SPAN&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;, line 78&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now why would the blocked category be Shopping, but yet in another tab I am at &lt;A href="https://community.cisco.com/www.walmart.com" target="_blank"&gt;www.walmart.com&lt;/A&gt; and that loads fine?&amp;nbsp; In fact other sites like Newegg, PCMall, BestBuy, Staples, Officemax, etc... all shopping sites - work great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me the best way to diagnose this problem rather than bypass the webfilter or maintain long lists of one off exceptions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S160 running v7.1.3-014 for Web&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 15:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899882#M2203</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2012-03-06T15:40:09Z</dc:date>
    </item>
    <item>
      <title>Ironport incorrectly blocking "shopping" from IT Admin</title>
      <link>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899883#M2204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Simplest way to diagnose is to use the Policy Trace feature under System Administration, this will show all the policies that the account is hitting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More detailed logs can be found from SSHing to the box and running a grep on the accesslogs, how is best depends on your setup.&amp;nbsp; But basically:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Grep&lt;/P&gt;&lt;P&gt;1&lt;/P&gt;&lt;P&gt;regular expression: username&lt;/P&gt;&lt;P&gt;Tail the logs: yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then do the actions which are getting allowed/denied and use them to find out the reason - AVC is application controls, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2012 07:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899883#M2204</guid>
      <dc:creator>Chris Illsley</dc:creator>
      <dc:date>2012-03-07T07:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Ironport incorrectly blocking "shopping" from IT Admin</title>
      <link>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899884#M2205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that.&amp;nbsp; I really like the grep and tail the logs.&amp;nbsp; It's like an instant way to see what's going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I did this and today the site is not blocked!!&amp;nbsp; Weird how it would be blocked one day but not the next. Oh well, at least I got the nifty grep command out of it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess what took me back is that I'm in the IT identity group which does not block much at all.&amp;nbsp; Shopping is especially not blocked as we make online purchases for various busness needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2012 14:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899884#M2205</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2012-03-07T14:44:07Z</dc:date>
    </item>
    <item>
      <title>Ironport incorrectly blocking "shopping" from IT Admin</title>
      <link>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899885#M2206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; A note on grep.. I typically use the IP address instead of username... that way you'll see things, even if the user isn't authenticated yet... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2012 14:59:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899885#M2206</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2012-03-07T14:59:42Z</dc:date>
    </item>
    <item>
      <title>Ironport incorrectly blocking "shopping" from IT Admin</title>
      <link>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899886#M2207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That "&lt;STRONG style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: 'Times New Roman';"&gt;BLOCK_WBRS_11&lt;/STRONG&gt;" means that the particular site was blocked due to a low web reputation score, rather than due to the category of the content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further along in the access log line for that connection will be the score itself. Here's one of ours:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BLOCK_WBRS_11-All_Access-CC_AD_Identity-NONE-NONE-NONE-NONE &lt;IW_ADV&gt; -&lt;/IW_ADV&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The -6.4 is the negative reputation score that caused this transaction to be blocked. Cisco has a public site where you can look up the reputation scores: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://senderbase.org"&gt;http://senderbase.org&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the upper right corner, just under the "Look up your network" box, click on the Reputation Look Up link.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2012 18:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ironport-incorrectly-blocking-quot-shopping-quot-from-it-admin/m-p/1899886#M2207</guid>
      <dc:creator>Stafford Rau</dc:creator>
      <dc:date>2012-03-14T18:11:22Z</dc:date>
    </item>
  </channel>
</rss>

