<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disable http inspection in global_policy FWSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487410#M234285</link>
    <description>&lt;P&gt;I am running 4.0(7) and we are experiencing some issues with downloads - specifically http downloads. Anything with an https link works fine.&lt;/P&gt;&lt;P&gt;Looking into the config on the FWSM i see that under the global_policy we are inspecting http&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;&amp;nbsp; inspect http&lt;/P&gt;&lt;P&gt;I would like to remove inspect http as a test to see if this is causing our problems, but am unsure of the impact of doing this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it is strange as this option has been there for a long time and our download issues have only recently started to happen, it does seem to be only for http links though?&lt;/P&gt;&lt;P&gt;I don't really understand what the inspection engine does?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:08:33 GMT</pubDate>
    <dc:creator>roger perkin</dc:creator>
    <dc:date>2019-03-12T04:08:33Z</dc:date>
    <item>
      <title>Disable http inspection in global_policy FWSM</title>
      <link>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487410#M234285</link>
      <description>&lt;P&gt;I am running 4.0(7) and we are experiencing some issues with downloads - specifically http downloads. Anything with an https link works fine.&lt;/P&gt;&lt;P&gt;Looking into the config on the FWSM i see that under the global_policy we are inspecting http&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;&amp;nbsp; inspect http&lt;/P&gt;&lt;P&gt;I would like to remove inspect http as a test to see if this is causing our problems, but am unsure of the impact of doing this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it is strange as this option has been there for a long time and our download issues have only recently started to happen, it does seem to be only for http links though?&lt;/P&gt;&lt;P&gt;I don't really understand what the inspection engine does?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:08:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487410#M234285</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2019-03-12T04:08:33Z</dc:date>
    </item>
    <item>
      <title>If you don't have any config</title>
      <link>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487411#M234289</link>
      <description>&lt;P&gt;If you don't have any config that needs the enabled http-inspection, then it's very likely that your HTTP-inspection basically doesn't do anything. And based on your description I would assume that the problem should be somewhere outside the FWSM.&lt;/P&gt;&lt;P&gt;Do you see anything in the log regarding the problems?&lt;/P&gt;&lt;P&gt;If you really don't need the inspection (any "filter"-command on the FWSM?) then I would just remove the inspection:&lt;/P&gt;&lt;P&gt;&lt;KBD&gt;policy-map global_policy&lt;BR style="font-size: 14px;" /&gt;&amp;nbsp; class inspection_default&lt;BR style="font-size: 14px;" /&gt;&amp;nbsp; &amp;nbsp; no&amp;nbsp;inspect http&lt;/KBD&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 10:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487411#M234289</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2014-04-30T10:35:04Z</dc:date>
    </item>
    <item>
      <title>I agree with Karsten.Also</title>
      <link>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487412#M234292</link>
      <description>&lt;P&gt;I agree with Karsten.&lt;/P&gt;&lt;P&gt;Also verify that you don't have any http proxy or url-filter service configured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2014 15:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487412#M234292</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-01T15:33:37Z</dc:date>
    </item>
    <item>
      <title>Well,I removed the http</title>
      <link>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487413#M234295</link>
      <description>&lt;P&gt;Well,&lt;/P&gt;&lt;P&gt;I removed the http inspection and it broke all inbound and outbound web services!&lt;/P&gt;&lt;P&gt;Then I discover this&lt;/P&gt;&lt;P&gt;url-server (WEB-Sense) vendor websense host 10.*.*.* timeout 30 protocol TCP version 1 connections 5&lt;BR /&gt;&lt;BR /&gt;filter url except 10.0.0.0 255.0.0.0 10.0.0.0 255.0.0.0 allow&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This web-sense server is down and no longer used.&lt;/P&gt;&lt;P&gt;But am I correct to assume that the prescense of this config caused a problem as all http was trying to go via the Websense but with the http inspection enabled it is able to go out direct?&lt;/P&gt;&lt;P&gt;I am unclear as to exactly how the inspection and the url-server / filter url commands interact.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2014 15:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-http-inspection-in-global-policy-fwsm/m-p/2487413#M234295</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2014-05-01T15:33:38Z</dc:date>
    </item>
  </channel>
</rss>

