<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Steps to enable Web Proxy for https in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090891#M2869</link>
    <description>&lt;P&gt;I have an S160 WSA and want to enable the Web service for http and https. I am using transparent mode with WCCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; This is part of the router configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp 192.168.80.0 0.0.7.255 any eq 80 &lt;/P&gt;&lt;P&gt;access-list 120 permit tcp 192.168.80.0 0.0.7.255 any eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip wccp 97 redirect-list 110&lt;/P&gt;&lt;P&gt;ip wccp 98 redirect-list 120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0.380&lt;/P&gt;&lt;P&gt;ip wccp 97 redirect in&lt;/P&gt;&lt;P&gt;ip wccp 98 redirect in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is the same configuration for http and for https, but only http traffic is working. When I see the logs in the WSA, it looks like accepted connections for https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Security Services -&amp;gt; Web Proxy it is enabled, when I put the port 443, I get an https error in the end user laptop; when I dont, it keeps trying and I get a timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried enabling https proxy but some sites (as gmail), wont work with self-generated certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you please, list me the steps to enable Proxy services for https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sergio L.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Nov 2012 22:07:06 GMT</pubDate>
    <dc:creator>slizarraga</dc:creator>
    <dc:date>2012-11-16T22:07:06Z</dc:date>
    <item>
      <title>Steps to enable Web Proxy for https</title>
      <link>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090891#M2869</link>
      <description>&lt;P&gt;I have an S160 WSA and want to enable the Web service for http and https. I am using transparent mode with WCCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; This is part of the router configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 110 permit tcp 192.168.80.0 0.0.7.255 any eq 80 &lt;/P&gt;&lt;P&gt;access-list 120 permit tcp 192.168.80.0 0.0.7.255 any eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip wccp 97 redirect-list 110&lt;/P&gt;&lt;P&gt;ip wccp 98 redirect-list 120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0.380&lt;/P&gt;&lt;P&gt;ip wccp 97 redirect in&lt;/P&gt;&lt;P&gt;ip wccp 98 redirect in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is the same configuration for http and for https, but only http traffic is working. When I see the logs in the WSA, it looks like accepted connections for https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Security Services -&amp;gt; Web Proxy it is enabled, when I put the port 443, I get an https error in the end user laptop; when I dont, it keeps trying and I get a timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried enabling https proxy but some sites (as gmail), wont work with self-generated certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you please, list me the steps to enable Proxy services for https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sergio L.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2012 22:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090891#M2869</guid>
      <dc:creator>slizarraga</dc:creator>
      <dc:date>2012-11-16T22:07:06Z</dc:date>
    </item>
    <item>
      <title>Steps to enable Web Proxy for https</title>
      <link>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090892#M2870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sergio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When WSA is configured as transparent proxy, it also accepts explitcit connections. So in order to test HTTPS proxy, you can configure client browser to explicitly use WSA as proxy and see if it is working before testing in transparent mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When WSA is used as HTTPS proxy, it uses its self-generated certificate to encrypt the connection between itself and the client browser. Since this certificate is not trusted by browser, it'll throw SSL certificate error when connecting via WSA. In order to get rid of this error, download the self-generated certificate from WSA and install it in your browser as a trusted certificate. That should resolve SSL issue with gmail also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chetan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2012 06:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090892#M2870</guid>
      <dc:creator>Chetankumar Phulpagare</dc:creator>
      <dc:date>2012-11-17T06:49:23Z</dc:date>
    </item>
    <item>
      <title>Steps to enable Web Proxy for https</title>
      <link>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090893#M2871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you install your own certificate into the WSA?&amp;nbsp; Like one from our own enterprise root ca, then the domain policy to auto enroll workstations with these certificates would make the whole process transparent to the end users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just have to figure out non windows based devices (ios / android / linux / mac).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2012 21:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090893#M2871</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2012-12-14T21:08:34Z</dc:date>
    </item>
    <item>
      <title>Steps to enable Web Proxy for https</title>
      <link>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090894#M2872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can do your own certificate as under a corporate CA (the WSA needs a Subordinate CA certificate because it will be generating the individual site certificates on the fly). The WSA cannot generate the request for the SubCA cert (at least not in 7.1.3). There is a post with steps for creating the SubCA certificate request from a Windows server (2008+) on one of the Microsoft forums.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2012 23:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/steps-to-enable-web-proxy-for-https/m-p/2090894#M2872</guid>
      <dc:creator>Jeffrey Ness</dc:creator>
      <dc:date>2012-12-14T23:03:13Z</dc:date>
    </item>
  </channel>
</rss>

