<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filtered URLs in ASA Still Sent to Websense? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238328#M349874</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got it.. Can you post the entire ASA config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 May 2013 18:36:56 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-05-15T18:36:56Z</dc:date>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238327#M349873</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a ASA5510 running version 8.2(5).&amp;nbsp; My predecesor configured it to send traffic to our Websense server for filtering, which is successful.&amp;nbsp; Because we're running low on Websense licenses, and because we don't have a need to have our servers filtered, I added exceptions yesterday as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;filter url except 10.1.1.15 255.255.255.255 0.0.0.0 0.0.0.0 allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure enough, when I try to access previously forbidden sites on that server, the traffic is allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However - and this is my question - the Websense box still "sees" the IP and accordingly counts it against licenses.&amp;nbsp; If the ASA is configured to ignore the IP with the above command, why is it still sending it to the Websense server, especially even if it continues to allow traffic?&amp;nbsp; (I have restarted all the websense services in the order their support site suggests between attempts as well).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;DS&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238327#M349873</guid>
      <dc:creator>dsstaoist</dc:creator>
      <dc:date>2019-03-12T01:43:48Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238328#M349874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got it.. Can you post the entire ASA config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 18:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238328#M349874</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-15T18:36:56Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238329#M349875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, no.&amp;nbsp; We have pretty strict confidentiality controls due to the work we do here.&amp;nbsp; I can verify/check particular items though if you'd like.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 18:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238329#M349875</guid>
      <dc:creator>dsstaoist</dc:creator>
      <dc:date>2013-05-15T18:55:07Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238330#M349876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What a shame..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then do captures on the asa interface connecting to the websense and provide me what you see on the 5 and 6th bit of the payload&amp;nbsp; on the packets sent to the websense appliance, also the message type&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 18:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238330#M349876</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-15T18:57:19Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238331#M349877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, I know &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp; How would I do what you're asking on the capture part?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 19:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238331#M349877</guid>
      <dc:creator>dsstaoist</dc:creator>
      <dc:date>2013-05-15T19:05:21Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238332#M349878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On wireshark, no way I can send you the steps or photos of how to do it as I do not have any websense to play with,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could do the captures and sent them privately to me but I would say its not an option based on the security policy of your company&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 19:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238332#M349878</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-15T19:07:50Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238333#M349879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can send the firewall config privately if you're a Cisco employee, which based on your email address it seems you are.&amp;nbsp; Shall I?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 19:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238333#M349879</guid>
      <dc:creator>dsstaoist</dc:creator>
      <dc:date>2013-05-15T19:12:18Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238334#M349882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure, go ahead&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 19:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238334#M349882</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-15T19:15:16Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238335#M349883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 19:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238335#M349883</guid>
      <dc:creator>dsstaoist</dc:creator>
      <dc:date>2013-05-15T19:25:28Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238336#M349885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I believe I found the root cause and the fix seems to work.&amp;nbsp; Simply, if HTTPS filtering is turned on, and you exclude an IP using "filter url..." you also need to exclude it using "filter https...".&amp;nbsp; Even if the machine behind a particular IP is only sending HTTP requests (presumably) for sites like cnn.com or msn.com, the ASA seems to forward the IP to Websense anyway to check for HTTPS filter policies/etc.&amp;nbsp; Excluding this as mentioned, from both http and https, seems to do the trick after a websense service restart and license report generation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 15:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238336#M349885</guid>
      <dc:creator>dsstaoist</dc:creator>
      <dc:date>2013-05-17T15:52:34Z</dc:date>
    </item>
    <item>
      <title>Filtered URLs in ASA Still Sent to Websense?</title>
      <link>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238337#M349886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting enough,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to know everything is working now&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 16:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/filtered-urls-in-asa-still-sent-to-websense/m-p/2238337#M349886</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-17T16:34:51Z</dc:date>
    </item>
  </channel>
</rss>

