cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3418
Views
0
Helpful
8
Replies

Web filter

1salvarez
Level 1
Level 1

We upgraded to ASA IOS 8.2.4 from 8.0.2. When the commands "filter https 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow" and "filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow" are added the we lose internet access. We're using WebSense and command "url-server (inside) vendor websense host 192.168.1.180 timeout 30 protocol TCP version 4 connections 5"

Thank you.

8 Replies 8

Is websense properly configured? What the asa sees? Do a show url-server statistics. If it is up then the allow will not permit traffic.

Sent from Cisco Technical Support iPhone App

"sh url-ser sta"

Server Statistics:
--------------------
192.168.1.180                     UP
  Vendor                          websense

I've tried shutting down the server and we're still not allowed online. Only after we remove the filter command are we allowed online.

once you shut down the server how long you waited? ASA has to be aware that the server is down.

"sh url-ser sta"

Server Statistics:
--------------------
192.168.1.180                     DOWN
  Vendor                          websense

Waited for up to 10 after it showed it down. Thinking it may be a bug in the IOS.

you are testing with HTTPS traffic right?

Both. This wasn't a problem for us on 8.0. Thinking I'm going to upgrade to 8.4 in hopes of it working.

Be aware that 8.4 has differences in NAT. Check the release notes before.

Turns out we had a bad ASA. Cisco replaced it.

Review Cisco Networking products for a $25 gift card