<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating Websense with Cisco ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411197#M784348</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Websence, only traffic flow from higher to lower security is filtered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround : Configure another router on a DMZ interface of the ASA and loop the&lt;BR /&gt;remote traffic back to the dmz interface of the ASA. This flow now would appear to come&lt;BR /&gt;from higher to lower security (dmz ---&amp;gt;outside) and then to the internet. Websense can&lt;BR /&gt;hence filter this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Dec 2009 06:22:21 GMT</pubDate>
    <dc:creator>Parminder Sian</dc:creator>
    <dc:date>2009-12-18T06:22:21Z</dc:date>
    <item>
      <title>Integrating Websense with Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411195#M784332</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;We have a Cisco ASA firewall in our office. This firewall is used to isolate consultants working for us on a project for us in a seperate network. They bring their own laptop and connect it to consultant subnet. These consultants are only allowed to access internet (http/https traffic) or vpn etc. The firewall rules are implemented on outside interface. To access internet they have to go through our Inside interface &amp;amp; eventually through our Enterprise firewall (seperate from this).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;The outside interface (security 0) of Cisco ASA is connected to consultants subnet &amp;amp; inside interface (security 100) is connected to out Production netowrk. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;We are trying to implement WebSense integration with Cisco ASA 5510. I have followed instructions from Cisco configuration guide to configure filter rules &amp;amp; specifing url server. But it is not working. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;After troubleshooting the problems I found out that HTTP request that originate from a high security level interface destined for a lower security level will trigger the URL filtering. But a HTTP request that originates on a lower security level interface destined for a higher security level interface will skip the URL filtering. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;I suspect that the issue lies somewhere with interface security levels and URL filtering. Security levels of the ASA interface are as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;Inside interface security level: 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;Outside interface security level 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: &amp;amp;quot; "&gt;So before I go messing with security levels, I wanted to get a 2nd opinion on this issue. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:49:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411195#M784332</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2019-03-11T16:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Websense with Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411196#M784338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell what are the commands that you have applied on the ASA related to the URL filtering?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please attach the show run url-server and the show run filter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe that you are missing the filter command on the lower security interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Dec 2009 22:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411196#M784338</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2009-12-17T22:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Websense with Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411197#M784348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Websence, only traffic flow from higher to lower security is filtered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround : Configure another router on a DMZ interface of the ASA and loop the&lt;BR /&gt;remote traffic back to the dmz interface of the ASA. This flow now would appear to come&lt;BR /&gt;from higher to lower security (dmz ---&amp;gt;outside) and then to the internet. Websense can&lt;BR /&gt;hence filter this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 06:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411197#M784348</guid>
      <dc:creator>Parminder Sian</dc:creator>
      <dc:date>2009-12-18T06:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating Websense with Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411198#M784361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Parminder,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you also agree that traffic from Higher to lower security is filtered but not the other way round. I did not find any references where Cisco have mentioned about that fact. Do you think I should open a TAC case with Cisco or should I just go with the work around suggested by you. Or is it from Cisco. Let me know....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also let me know what implications I will have if I change the security number of Outside to 100 &amp;amp; inside to 0.As the traffic is still controlled by access-list applied on inside interface &amp;amp; outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Ds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Dec 2009 17:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-websense-with-cisco-asa/m-p/1411198#M784361</guid>
      <dc:creator>dharmendra2shah</dc:creator>
      <dc:date>2009-12-22T17:07:15Z</dc:date>
    </item>
  </channel>
</rss>

