<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot block https proxies ... in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045707#M356</link>
    <description>&lt;P&gt;For some reason&lt;BR /&gt;&lt;BR /&gt;I checked the firewall to verify 443 traffic was still being sent to the WSA&lt;BR /&gt;The decryption policy was set to Monitor.&lt;BR /&gt;Changed this to Decrypt.&lt;BR /&gt;Verified that it is set to Block in the Access Policies.&lt;BR /&gt;&lt;BR /&gt;Policy Trace seems to not work for http ... everything comes back "Transaction permitted" with no webcat listed.&lt;BR /&gt;For https, testing a proxy site comes back:&lt;BR /&gt;URL Category: Proxies &amp;amp; Translators&lt;BR /&gt;Policy Match:&lt;BR /&gt;... (all global, which has Proxies set to Monitor now)&lt;BR /&gt;Request completed&lt;BR /&gt;Details: PASSTHRU_ADMIN&lt;BR /&gt;&lt;BR /&gt;Tailing the grep does no good ... it's only showing when I attempt https, not https, but https traffic is indeed being forwarded from the same place https is.&lt;BR /&gt;&lt;BR /&gt;Any help would be appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Dec 2008 05:32:07 GMT</pubDate>
    <dc:creator>Gawayne_ironport</dc:creator>
    <dc:date>2008-12-16T05:32:07Z</dc:date>
    <item>
      <title>Cannot block https proxies ...</title>
      <link>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045707#M356</link>
      <description>&lt;P&gt;For some reason&lt;BR /&gt;&lt;BR /&gt;I checked the firewall to verify 443 traffic was still being sent to the WSA&lt;BR /&gt;The decryption policy was set to Monitor.&lt;BR /&gt;Changed this to Decrypt.&lt;BR /&gt;Verified that it is set to Block in the Access Policies.&lt;BR /&gt;&lt;BR /&gt;Policy Trace seems to not work for http ... everything comes back "Transaction permitted" with no webcat listed.&lt;BR /&gt;For https, testing a proxy site comes back:&lt;BR /&gt;URL Category: Proxies &amp;amp; Translators&lt;BR /&gt;Policy Match:&lt;BR /&gt;... (all global, which has Proxies set to Monitor now)&lt;BR /&gt;Request completed&lt;BR /&gt;Details: PASSTHRU_ADMIN&lt;BR /&gt;&lt;BR /&gt;Tailing the grep does no good ... it's only showing when I attempt https, not https, but https traffic is indeed being forwarded from the same place https is.&lt;BR /&gt;&lt;BR /&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2008 05:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045707#M356</guid>
      <dc:creator>Gawayne_ironport</dc:creator>
      <dc:date>2008-12-16T05:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block https proxies ...</title>
      <link>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045708#M357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gawayne,&lt;BR /&gt;&lt;BR /&gt;What is the WBRS score of the site that you are attempting to access? If the WBRS score is 6+ or greater, the HTTPS action will be Pass Through.&lt;BR /&gt;&lt;BR /&gt;If the score is incorrectly high, we may need to report this to IronPort in order to have the score adjusted accordingly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Dec 2008 00:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045708#M357</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-12-17T00:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block https proxies ...</title>
      <link>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045709#M358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've scoured both your site and the WSA admin panel, but can't find anything referencing where to look up this information. I see where to look up the categorisation and Webroot score, but no WBRS ...&lt;BR /&gt;&lt;BR /&gt;Although ... how does allowing a blocked category make sense, no matter what the web reputation is, though?&lt;BR /&gt;&lt;BR /&gt;FYI: particular site in question is: &lt;A href="https://community.cisco.com/www.kproxy.com" target="_blank"&gt;www.kproxy.com&lt;/A&gt; (and it's sub servers -- server1. server2. server3. etc)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Dec 2008 02:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045709#M358</guid>
      <dc:creator>Gawayne_ironport</dc:creator>
      <dc:date>2008-12-17T02:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot block https proxies ...</title>
      <link>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045710#M359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gawayne,&lt;BR /&gt;&lt;BR /&gt;You can verify the WBRS score from the access logs. Here is a sample access log line:&lt;BR /&gt;&lt;BR /&gt;Thu Dec 11 10:42:02 2008 22 10.1.1.29 TCP_MISS/200 66187 GET &lt;A href="http://www.foxnews.com/" target="_blank"&gt;http://www.foxnews.com/&lt;/A&gt; DOMAIN\user@AD DIRECT/www.foxnews.com text/html ALLOW_WBRS-WhiteList-DefaultRouting &lt;NEWS&gt; -  News -&lt;BR /&gt;&lt;BR /&gt;I've checked the score and the score is -0.70&lt;BR /&gt;&lt;BR /&gt;The reason the WBRS score is relevant is that if an HTTPS site has a 6.0+ score it will be "passed through" the WSA. Any traffic that is passed through is essentially allowed through the WSA, since the stream will be encrypted between the client and the web server.&lt;BR /&gt;&lt;BR /&gt;This behavior can be changed via the HTTPS WBRS policies. &lt;BR /&gt;&lt;BR /&gt;I recommend opening up a support ticket, as this is probably going to require some further specific troubleshooting.&lt;/NEWS&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Dec 2008 00:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/cannot-block-https-proxies/m-p/1045710#M359</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-12-18T00:01:31Z</dc:date>
    </item>
  </channel>
</rss>

