<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix, WebSense not blocking https in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930450#M938682</link>
    <description>&lt;P&gt;I use WebSense 5.5 on windows 2000. I have a pix 515 running 6.3(3)&lt;/P&gt;&lt;P&gt;I am having trouble blocking https sites&lt;/P&gt;&lt;P&gt;The https protocol blocking is enabled on Websense.&lt;/P&gt;&lt;P&gt;I have this in my config:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;url-server (inside) vendor websense host 10.208.18.2 timeout 5 protocol TCP version 1&lt;/P&gt;&lt;P&gt;filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was recommended that I use "filter url https" instead of 443, but it automatically changes https to 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any solutions?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:36:49 GMT</pubDate>
    <dc:creator>daniel.ketchum</dc:creator>
    <dc:date>2019-03-11T12:36:49Z</dc:date>
    <item>
      <title>Pix, WebSense not blocking https</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930450#M938682</link>
      <description>&lt;P&gt;I use WebSense 5.5 on windows 2000. I have a pix 515 running 6.3(3)&lt;/P&gt;&lt;P&gt;I am having trouble blocking https sites&lt;/P&gt;&lt;P&gt;The https protocol blocking is enabled on Websense.&lt;/P&gt;&lt;P&gt;I have this in my config:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;url-server (inside) vendor websense host 10.208.18.2 timeout 5 protocol TCP version 1&lt;/P&gt;&lt;P&gt;filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was recommended that I use "filter url https" instead of 443, but it automatically changes https to 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any solutions?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930450#M938682</guid>
      <dc:creator>daniel.ketchum</dc:creator>
      <dc:date>2019-03-11T12:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Pix, WebSense not blocking https</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930451#M938683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In a PIX HTTPS protocol is disabled by default.check for the version of pix firewall as:&lt;/P&gt;&lt;P&gt;1)Websense Enterprise web filtering application is supported by PIX Firewall Version 5.3 or higher only.&lt;/P&gt;&lt;P&gt;2)PIX Firewall Version 6.3 or higher supports filtering of HTTPS and FTP sites when using the Websense filtering server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More information about enabling HTTPS protocol blocking using websense refer:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/app_ntwk_services/waas/acns/v55/configuration/central/guide/9136fltr.html#wp1042822" target="_blank"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/waas/acns/v55/configuration/central/guide/9136fltr.html#wp1042822&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 May 2008 18:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930451#M938683</guid>
      <dc:creator>smahbub</dc:creator>
      <dc:date>2008-05-02T18:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Pix, WebSense not blocking https</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930452#M938684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration should work as you have it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;filter url [http | port[-port] local_ip local_mask foreign_ip foreign_mask] [allow] [proxy-block] &lt;/P&gt;&lt;P&gt;[longurl-truncate | longurl-deny] [cgi-truncate]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you checked the statistics by issuing "show url-server statistics"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 May 2008 18:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930452#M938684</guid>
      <dc:creator>Matt Lang</dc:creator>
      <dc:date>2008-05-02T18:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Pix, WebSense not blocking https</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930453#M938685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Matt,&lt;/P&gt;&lt;P&gt;"show url-server statistics" returns a bad syntax response. "show url server statistics" returns "Ambiguous command. Please enter more characters."&lt;/P&gt;&lt;P&gt;What am I missing here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 May 2008 22:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930453#M938685</guid>
      <dc:creator>daniel.ketchum</dc:creator>
      <dc:date>2008-05-05T22:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Pix, WebSense not blocking https</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930454#M938686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My mistake.  It should be "show url-server stats".  That is the command for 6.3 code.  Here is the link....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/tz.html#wp1026449" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/tz.html#wp1026449&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show url-server statistics" is for 7.2 code.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 May 2008 23:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930454#M938686</guid>
      <dc:creator>Matt Lang</dc:creator>
      <dc:date>2008-05-05T23:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Pix, WebSense not blocking https</title>
      <link>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930455#M938687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice Matt, that worked. My stats look like the pix is not even seeing https requests:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL Server Statistics:&lt;/P&gt;&lt;P&gt;----------------------&lt;/P&gt;&lt;P&gt;Vendor                           websense&lt;/P&gt;&lt;P&gt;URLs total/allowed/denied        2611484/2578007/33477&lt;/P&gt;&lt;P&gt;HTTPSs total/allowed/denied      0/0/0&lt;/P&gt;&lt;P&gt;FTPs total/allowed/denied        0/0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL Server Status:&lt;/P&gt;&lt;P&gt;------------------&lt;/P&gt;&lt;P&gt;10.208.50.2		UP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL Packets Sent and Recieved Stats:&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;Message			Sent	Recieved&lt;/P&gt;&lt;P&gt;STATUS_REQUEST		80424	80353&lt;/P&gt;&lt;P&gt;LOOKUP_REQUEST		2658590	2657063&lt;/P&gt;&lt;P&gt;LOG_REQUEST		0	NA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2008 14:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-websense-not-blocking-https/m-p/930455#M938687</guid>
      <dc:creator>daniel.ketchum</dc:creator>
      <dc:date>2008-05-06T14:39:14Z</dc:date>
    </item>
  </channel>
</rss>

