<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When decrypt for in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879367#M6579</link>
    <description>&lt;P&gt;When decrypt for authentication and WCCP is used together, this should be ok. However please note there is limitation in the proxy for 3 conditions below:&lt;/P&gt;
&lt;P&gt;1. WCCP/transparent mode&lt;/P&gt;
&lt;P&gt;2. HTTPS traffic&lt;/P&gt;
&lt;P&gt;3. Authentication&lt;/P&gt;
&lt;P&gt;And depends on the authentication surrogate used there is certain limitation on this (consult the user guide)&lt;/P&gt;
&lt;P&gt;Would recommend to open a TAC case for the engineer to dig deep on to this based on the network environment and also possible defect (such as if you are using CDA or AD agent as your authentication).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Apr 2016 04:40:27 GMT</pubDate>
    <dc:creator>Handy Putra</dc:creator>
    <dc:date>2016-04-23T04:40:27Z</dc:date>
    <item>
      <title>HTTPs sites randomly not working on WSA 170</title>
      <link>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879364#M6576</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTTPs sites randomly not working on WSA 170 seeing following in access logs when it happens. what does&amp;nbsp;&lt;SPAN&gt;DENY_ADMIN_2 mean here?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What could be possible cause? the other times it works fine. 3 out 10 times it gives this error message.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1461173910.696 104 10.36.198.77 TCP_DENIED/403 0 TCP_CONNECT 142.103.59.207:443 - DIRECT/ubc.ca - DENY_ADMIN_2-NONE-HAC_AD-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_edu,1.5,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,IW_edu,-,"-","-","Unknown","Unknown","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; -&lt;BR /&gt;1461173911.010 154 10.36.198.77 TCP_DENIED/403 0 TCP_CONNECT 142.103.59.207:443 - DIRECT/ubc.ca - DENY_ADMIN_2-NONE-HAC_AD-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_edu,1.5,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,IW_edu,-,"-","-","Unknown","Unknown","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; -&lt;BR /&gt;1461173911.115 103 10.36.198.77 TCP_DENIED/403 0 TCP_CONNECT 142.103.59.207:443 - DIRECT/ubc.ca - DENY_ADMIN_2-NONE-HAC_AD-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_edu,1.5,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,IW_edu,-,"-","-","Unknown","Unknown","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; -&lt;BR /&gt;1461173911.452 334 10.36.198.77 TCP_DENIED/403 0 TCP_CONNECT 142.103.59.207:443 - DIRECT/142.103.59.207 - DENY_ADMIN_2-NONE-HAC_AD-NONE-NONE-NONE-DefaultGroup &amp;lt;IW_edu,1.5,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,IW_edu,-,"-","-","Unknown","Unknown","-","-",0.00,0,-,"-","-",-,"-",-,-,"-"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;chrome displays following message when it happens:&lt;/P&gt;
&lt;H1 jsselect="heading" jsvalues=".innerHTML:msg" jstcache="8"&gt;This site can’t be reached&lt;/H1&gt;
&lt;P jsselect="summary" jsvalues=".innerHTML:msg" jstcache="9"&gt;&lt;STRONG jscontent="hostName" jstcache="20"&gt;ubc.ca&lt;/STRONG&gt; unexpectedly closed the connection.&lt;/P&gt;
&lt;DIV class="error-code" jscontent="errorCode" jstcache="10"&gt;ERR_CONNECTION_CLOSED&lt;/DIV&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 17:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879364#M6576</guid>
      <dc:creator>sarabsin</dc:creator>
      <dc:date>2016-04-20T17:44:50Z</dc:date>
    </item>
    <item>
      <title>It looks you are running WSA</title>
      <link>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879365#M6577</link>
      <description>&lt;P&gt;It looks you are running WSA in transparent mode with WCCP enabled and in the meantime, "&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Decrypt for Authentication:&lt;/SPAN&gt;" option in HTTPs Proxy is also enabled for proxy authentication.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 23:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879365#M6577</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-04-20T23:30:38Z</dc:date>
    </item>
    <item>
      <title>Hi Tao. What does this mean?</title>
      <link>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879366#M6578</link>
      <description>&lt;P&gt;Hi Tao. What does this mean? Should you not run these two things together? I have this issue as well.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 08:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879366#M6578</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2016-04-22T08:13:34Z</dc:date>
    </item>
    <item>
      <title>When decrypt for</title>
      <link>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879367#M6579</link>
      <description>&lt;P&gt;When decrypt for authentication and WCCP is used together, this should be ok. However please note there is limitation in the proxy for 3 conditions below:&lt;/P&gt;
&lt;P&gt;1. WCCP/transparent mode&lt;/P&gt;
&lt;P&gt;2. HTTPS traffic&lt;/P&gt;
&lt;P&gt;3. Authentication&lt;/P&gt;
&lt;P&gt;And depends on the authentication surrogate used there is certain limitation on this (consult the user guide)&lt;/P&gt;
&lt;P&gt;Would recommend to open a TAC case for the engineer to dig deep on to this based on the network environment and also possible defect (such as if you are using CDA or AD agent as your authentication).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Apr 2016 04:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879367#M6579</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-04-23T04:40:27Z</dc:date>
    </item>
    <item>
      <title>The DENY_ADMIN_2 might</title>
      <link>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879368#M6580</link>
      <description>&lt;P&gt;The DENY_ADMIN_2 might indicating there is combination issues between https traffic with WCCP/transparent mode and authentication surrogate used (for example IP address surrogate).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Would recommend open TAC case to investigate in details and to explore possible defect as well (such as if you are using TUI as authentication using CDA or AD agent)&lt;/P&gt;</description>
      <pubDate>Sat, 23 Apr 2016 04:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/https-sites-randomly-not-working-on-wsa-170/m-p/2879368#M6580</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-04-23T04:42:48Z</dc:date>
    </item>
  </channel>
</rss>

