<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ironport Initial Setup in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/ironport-initial-setup/m-p/2136366#M3003</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just setup an ironport S160 appliance on my network. The applaince shows to be up but it does not seem to be capturing users activities. the following are the configuration details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mode: Transparent&lt;/P&gt;&lt;P&gt;data interface: P1 only&lt;/P&gt;&lt;P&gt;mngt int: management only&lt;/P&gt;&lt;P&gt;filter mode:monitor only&lt;/P&gt;&lt;P&gt;Layer 4 switch mode enabled&lt;/P&gt;&lt;P&gt;WCCP:disabled&lt;/P&gt;&lt;P&gt;Licenses: up and valid.&lt;/P&gt;&lt;P&gt;Reporting: Enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed that web categories that are enabled by default are up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No reports are being generated at the moment. What do i have to configure on the core switch to redirect all traffic to the Ironport appliance? according to the S160 documentation, once Layer4 is chosen over WCCP nothing more is required which doesnt make much sense to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a schema showing my network diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Justice&lt;/P&gt;</description>
    <pubDate>Fri, 23 Nov 2012 07:41:18 GMT</pubDate>
    <dc:creator>Justice Nsude</dc:creator>
    <dc:date>2012-11-23T07:41:18Z</dc:date>
    <item>
      <title>Ironport Initial Setup</title>
      <link>https://community.cisco.com/t5/web-security/ironport-initial-setup/m-p/2136366#M3003</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just setup an ironport S160 appliance on my network. The applaince shows to be up but it does not seem to be capturing users activities. the following are the configuration details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mode: Transparent&lt;/P&gt;&lt;P&gt;data interface: P1 only&lt;/P&gt;&lt;P&gt;mngt int: management only&lt;/P&gt;&lt;P&gt;filter mode:monitor only&lt;/P&gt;&lt;P&gt;Layer 4 switch mode enabled&lt;/P&gt;&lt;P&gt;WCCP:disabled&lt;/P&gt;&lt;P&gt;Licenses: up and valid.&lt;/P&gt;&lt;P&gt;Reporting: Enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed that web categories that are enabled by default are up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No reports are being generated at the moment. What do i have to configure on the core switch to redirect all traffic to the Ironport appliance? according to the S160 documentation, once Layer4 is chosen over WCCP nothing more is required which doesnt make much sense to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a schema showing my network diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Justice&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2012 07:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ironport-initial-setup/m-p/2136366#M3003</guid>
      <dc:creator>Justice Nsude</dc:creator>
      <dc:date>2012-11-23T07:41:18Z</dc:date>
    </item>
    <item>
      <title>Ironport Initial Setup</title>
      <link>https://community.cisco.com/t5/web-security/ironport-initial-setup/m-p/2136367#M3004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Justice,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;L4TM is not used for redirecting traffic for the purpose of web traffic inspection to Web Proxy on WSA. You will need to setup WCCP either on your 6505 or the ASA so that any outgoing traffic with dstn TCP port 80. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check details here: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/solutions/SBA/August2012/Cisco_SBA_BN_WebSecurityUsingWSADeploymentGuide-Aug2012.pdf"&gt;http://www.cisco.com/en/US/docs/solutions/SBA/August2012/Cisco_SBA_BN_WebSecurityUsingWSADeploymentGuide-Aug2012.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-629052.html"&gt;http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-629052.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that WSA supports explicit proxy even when configured in transparent mode. To ensure that your web proxy service is applying policies correctly, you can point your browser on test client to explicitely use WSA IP addr as a proxy. Then you can test the same with your traffic being redirected over WCCP. Also, please check the access logs on WSA to make sure if any traffic was seen on WSA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chetan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 01:02:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ironport-initial-setup/m-p/2136367#M3004</guid>
      <dc:creator>Chetankumar Phulpagare</dc:creator>
      <dc:date>2012-11-27T01:02:30Z</dc:date>
    </item>
  </channel>
</rss>

