<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix &amp; Websense filtering in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543135#M498121</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NEED YOUR HELP for Intergarting PIX-Websense&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing problem in integratiing PIX525(1:1 Active-Stdby), IOS 6.34. I have followed the documentation provided by Websense to do that. Websense ver is 6.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have taken the ethreal cap to see the TCP handshake bet'n PIX and websense. But it is not able to filter anything. I am using websense for Intranet only so have created custom URLs based on IP addresses and hostnames. Also I have tried to connect the websense server on SPAN port also but Test visibility tool is unable to find any IP addresses for Network agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nitin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Aug 2006 04:01:38 GMT</pubDate>
    <dc:creator>nitinmathur</dc:creator>
    <dc:date>2006-08-29T04:01:38Z</dc:date>
    <item>
      <title>Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543132#M498115</link>
      <description>&lt;P&gt;I'm using a PIX 515 with IOS version 7.0(4) and a websense filtering server. Everything works fine until the server is taken offline for maintenance. When the server is replaced I have to re-create the url-filtering commands on the PIX in order for the server to start filtering again. Any ideas on why this must be done?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543132#M498115</guid>
      <dc:creator>cprice2k7</dc:creator>
      <dc:date>2020-02-21T09:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543133#M498117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Finally found the Cisco write up on this.&lt;/P&gt;&lt;P&gt; &lt;A class="jive-link-custom" href="http://www.ciscotaccc.com/kaidara-advisor/security/showcase?case=K65713155" target="_blank"&gt;http://www.ciscotaccc.com/kaidara-advisor/security/showcase?case=K65713155&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Aug 2006 18:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543133#M498117</guid>
      <dc:creator>cprice2k7</dc:creator>
      <dc:date>2006-08-23T18:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543134#M498119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had similar problems on multiple PIX/ASAs.  After I upgraded to v7.21, the problems ceased.  Good luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Aug 2006 19:19:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543134#M498119</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2006-08-23T19:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543135#M498121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NEED YOUR HELP for Intergarting PIX-Websense&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing problem in integratiing PIX525(1:1 Active-Stdby), IOS 6.34. I have followed the documentation provided by Websense to do that. Websense ver is 6.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have taken the ethreal cap to see the TCP handshake bet'n PIX and websense. But it is not able to filter anything. I am using websense for Intranet only so have created custom URLs based on IP addresses and hostnames. Also I have tried to connect the websense server on SPAN port also but Test visibility tool is unable to find any IP addresses for Network agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nitin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Aug 2006 04:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543135#M498121</guid>
      <dc:creator>nitinmathur</dc:creator>
      <dc:date>2006-08-29T04:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543136#M498124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; On our setup we have three interfaces for the websense device. For one interface (the non-filtering interface) I have a span seesion setup so the websense can see all traffic. The second interface is the one I have the url redirects going to. The third interface is for the websense database. &lt;/P&gt;&lt;P&gt; Is your intranet traffic traversing your firewall? Can you send your configuration for the websense filtering?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Aug 2006 15:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543136#M498124</guid>
      <dc:creator>cprice2k7</dc:creator>
      <dc:date>2006-08-29T15:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543137#M498129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;post your Websense config from the PIX please&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Aug 2006 16:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543137#M498129</guid>
      <dc:creator>jwjohansen</dc:creator>
      <dc:date>2006-08-29T16:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543138#M498133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your email.&lt;/P&gt;&lt;P&gt;The config from PIX is fine as now I am able to see logs on Test Log server. Now I am trying to use Websense for URL filtering of Intranet pages. Pls see the details below and suggest if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clients are identified based on IP addresses and a policy should be made to permit authorized access of web apps based on URLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest if Websense can be used for URL filtering of Intranet made of private IP addresses. The details regarding the setup is as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewalls: Two PIX525 in Active-Stdby FO mode. Inside IP 10.100.200.4/24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Websense &lt;/P&gt;&lt;P&gt;Mode : Intergarted Cisco PIX firewalls&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version: 6.1.1 with database downloaded (Aug28)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OS : Windows 2003 server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Physical Placement:   In the inside zone of firewall. The application servers are currently placed in the same zone. Some Intranet servers will be accessed through DMZ zone also later on through a WAN link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Physical Conenctivity: Server has 2 NIC. 1 NIC for Management (IP 10.100.200.6) &lt;/P&gt;&lt;P&gt;                                      NIC 2 is used for monitoring (IP address 192.168.0.197/24)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Websense is configured to send block information through NIC 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A policy is made that allows permitted category. In User defined two sub categories are created ?Allowed? and ?Blocked? and respective custom URLs are created in that.  Only ?Allowed? category is permitted and other one blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When respective pages are accessed the Test Log servers shows activity and the disposition comes as Blocked and Allowed URL but the URL that is blocked can also be accessed by user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regard &amp;amp; good Day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2006 06:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543138#M498133</guid>
      <dc:creator>nitinmathur</dc:creator>
      <dc:date>2006-08-31T06:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Pix &amp; Websense filtering</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543139#M498137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are the lines that are configured in PIX for websense. I am getting matches on the TestLogserver on websense. But websense is not able to block anything nor does the block-message from Websense appears. I am using it for Intranet URLS based on IP addresses and domains resolved by local dns only. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest i&lt;/P&gt;&lt;P&gt;pixfw1# sh run | incl url&lt;/P&gt;&lt;P&gt;url-server (inside) vendor websense host 10.100.200.7 timeout 5 protocol UDP ver&lt;/P&gt;&lt;P&gt;sion 4&lt;/P&gt;&lt;P&gt;url-cache dst 1KB&lt;/P&gt;&lt;P&gt;filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;url-block block 1&lt;/P&gt;&lt;P&gt;pixfw1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions are welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2006 07:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-filtering/m-p/543139#M498137</guid>
      <dc:creator>nitinmathur</dc:creator>
      <dc:date>2006-09-07T07:05:43Z</dc:date>
    </item>
  </channel>
</rss>

