<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa/m-p/4005376#M8922</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class="user-badges-list"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;A id="link_14" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/56479" target="_self"&gt;ccg-security&lt;/A&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;TCP 445 is used for SMB communication. check if the WSA is trying to communicate with&amp;nbsp;the AD. Is your AD on the outside?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Shikha Grover&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and select as validated answer if this answered your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jan 2020 01:43:34 GMT</pubDate>
    <dc:creator>shgrover</dc:creator>
    <dc:date>2020-01-02T01:43:34Z</dc:date>
    <item>
      <title>WSA</title>
      <link>https://community.cisco.com/t5/web-security/wsa/m-p/3946995#M8840</link>
      <description>&lt;P&gt;&lt;BR /&gt;We would like to know why is that our WSA is communicatiing in public using 445?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 14:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa/m-p/3946995#M8840</guid>
      <dc:creator>ccg-security</dc:creator>
      <dc:date>2019-10-24T14:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: WSA suspicious traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa/m-p/3947073#M8841</link>
      <description>&lt;P&gt;The IP provided belong to apple -&amp;nbsp;apple.parklogic.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So better look at console what device is try to communicated, Do you have any apple device in the network. ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here port information :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.apple.com/en-is/HT202944" target="_blank"&gt;https://support.apple.com/en-is/HT202944&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 07:33:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa/m-p/3947073#M8841</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-10-24T07:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: WSA suspicious traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa/m-p/3947316#M8843</link>
      <description>&lt;P&gt;Hello Balaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we&amp;nbsp;l&lt;SPAN&gt;ook at console what device is try to communicated?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 13:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa/m-p/3947316#M8843</guid>
      <dc:creator>ccg-security</dc:creator>
      <dc:date>2019-10-24T13:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: WSA suspicious traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa/m-p/3947368#M8845</link>
      <description>&lt;P&gt;Looging to WSA using SSH&lt;/P&gt;
&lt;P&gt;once you see below prompt follow same steps :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;gt; grep&lt;/P&gt;
&lt;P&gt;&amp;gt;1 (this is for access logs)&lt;/P&gt;
&lt;P&gt;&amp;gt;45.79.222.138&lt;/P&gt;
&lt;P&gt;&amp;gt; N&lt;/P&gt;
&lt;P&gt;&amp;gt; N&lt;/P&gt;
&lt;P&gt;&amp;gt; Y&lt;/P&gt;
&lt;P&gt;&amp;gt; N&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then you can see real-time which IP address contacting that server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or you can also do report on GUI destination type IP address - 45.79.222.138&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 14:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa/m-p/3947368#M8845</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-10-24T14:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: WSA</title>
      <link>https://community.cisco.com/t5/web-security/wsa/m-p/4005376#M8922</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class="user-badges-list"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;A id="link_14" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/56479" target="_self"&gt;ccg-security&lt;/A&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;TCP 445 is used for SMB communication. check if the WSA is trying to communicate with&amp;nbsp;the AD. Is your AD on the outside?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Shikha Grover&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and select as validated answer if this answered your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2020 01:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa/m-p/4005376#M8922</guid>
      <dc:creator>shgrover</dc:creator>
      <dc:date>2020-01-02T01:43:34Z</dc:date>
    </item>
  </channel>
</rss>

