<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web Security Appliance in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470726#M9705</link>
    <description>If you need DLP for web traffic you want a WSA&lt;BR /&gt;If you need application level control in web apps (e.g. you can read a site, but not post), you need a WSA&lt;BR /&gt;If you need any sort of precise URL control, where you parse out parts of the URL whether to block/or allow... you need a WSA.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 21 Sep 2021 13:31:10 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2021-09-21T13:31:10Z</dc:date>
    <item>
      <title>Web Security Appliance</title>
      <link>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470484#M9702</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;Good day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So guys I have been going through WSA and I was not sure why we need it if we have got a Cisco FTD/FMC, I mean FTD offers features like Web filtering and Deep packet inspection so why do we need Cisco WSA.&lt;/P&gt;&lt;P&gt;Can you guys please mention the features that differ WSA from FTD.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 06:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470484#M9702</guid>
      <dc:creator>Asfandyar70754</dc:creator>
      <dc:date>2021-09-21T06:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Web Security Appliance</title>
      <link>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470499#M9703</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1034099"&gt;@Asfandyar70754&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There is a big difference on how these devices are working. FTD is doing inline inspection, meaning that it is acting as man-in-the middle for your connections (in your IP header you have PC IP as a source and some IP as destination, usually public one, e.g. of cisco.com). This can often be very tricky, as PC is unaware that someone/something is messing with their connections and can report some issues. On the other hand, WSA is working as a proxy (explicit or a transparent one), meaning that connections are coming to WSA as destined to WSA (in your IP header you have PC IP as a source and WSA as destination, and inside the packet, you are asking your WSA to proxy you to some URL, like cisco.com). This also means that you are talking only to your WSA, while your WSA is talking to the Internet, protecting you directly from certain exploits that could potentially target your PC directly otherwise (in this case, they would be destined to WSA, which is a security device, and much harder to be targeted).&lt;/P&gt;&lt;P&gt;Again, due to its nature, some things are much easier to be achieved if you have explicit proxy (e.g. file analysis for malware). Let's not forget SSL/TLS decryption also, which is normally quite demanding for devices such as FTD and degrading performance significantly, which is not something you would want from an edge device which is susceptible to DoS attacks.&lt;/P&gt;&lt;P&gt;I'm of an opinion that URL filtering on FTD is convenient for some smaller customers, which are not very demanding and are looking into some basic functionality. For customers who are interested in doing full blown URL filtering, I'm always advising WSA as a separate system meant for this functionality (and from recently Umbrella SIG, as it can do cloud-based proxy).&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 07:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470499#M9703</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-09-21T07:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Web Security Appliance</title>
      <link>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470530#M9704</link>
      <description>&lt;P&gt;Thanks a lot Milos.&lt;/P&gt;&lt;P&gt;I have been studying this for a financial organization, your points will help me a lot in convincing them.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 08:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470530#M9704</guid>
      <dc:creator>Asfandyar70754</dc:creator>
      <dc:date>2021-09-21T08:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Web Security Appliance</title>
      <link>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470726#M9705</link>
      <description>If you need DLP for web traffic you want a WSA&lt;BR /&gt;If you need application level control in web apps (e.g. you can read a site, but not post), you need a WSA&lt;BR /&gt;If you need any sort of precise URL control, where you parse out parts of the URL whether to block/or allow... you need a WSA.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Sep 2021 13:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4470726#M9705</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2021-09-21T13:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Web Security Appliance</title>
      <link>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4693454#M10267</link>
      <description>&lt;P&gt;The Cisco "&lt;STRONG&gt;Web Security Appliance&lt;/STRONG&gt;" combines advanced malware protection, application visibility and control, acceptable use policies, insightful reporting, and secure mobility on a single platform,&amp;nbsp;helping to address the growing challenges of securing and controlling web traffic.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 04:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4693454#M10267</guid>
      <dc:creator>markanderson</dc:creator>
      <dc:date>2022-09-26T04:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Web Security Appliance</title>
      <link>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4694266#M10268</link>
      <description>&lt;P&gt;on the Other hand, if you need to have some policies related to UserName/UserGroups yo need to use WSA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A&lt;SPAN&gt;pplication visibility and control : As mentioned Earlier.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Powerful&lt;SPAN&gt;&amp;nbsp;Reporting&lt;BR /&gt;Also we have 3 scanning Engine except&amp;nbsp;AMP&amp;nbsp; : WebRoot, Sophos and McAfee.&lt;BR /&gt;Meanwhile&amp;nbsp; you can have time based or quota&amp;nbsp;based policy&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;the AsyncOS in WSA has been designed&amp;nbsp;to to handle large amount of HTTP/HTTPS traffic with Decryption/re-Encryption capability which they are really resource consumer, so in large scale Networks ( high amount of requests per seconds ) that might be an issue if you chose something other than WSA.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Regards,&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Amirhossein Mojarrad&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;++++ &amp;nbsp; If you find this answer helpful, please rate it as such&amp;nbsp;&amp;nbsp;++++&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 06:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/web-security-appliance/m-p/4694266#M10268</guid>
      <dc:creator>amojarra</dc:creator>
      <dc:date>2022-09-27T06:39:36Z</dc:date>
    </item>
  </channel>
</rss>

