01-18-2011 05:21 AM - edited 03-11-2019 12:36 PM
Hello All,
I am wondering if I can NAT before websense to reduce the licensing cost. Websense licensing is based on IP address allocation. What if I NAT all my 500 hosts to one IP and send to websense? So websense thinks all requests are coming from 1 host and I save on licensing
Thanks,
Ram
01-18-2011 05:36 AM
Hi Ram,
All about economics :-)
I don't see why it won't work.
Websense will see all requests coming from one single IP, and the PAT device can differentiate the connections
based on source port.
Maybe I'm missing something because I'm not familiar how websense works in this sense, but it sounds right.
Federico.
01-18-2011 08:26 AM
As Federico suggested, that is good idea. You can do it.
Note that if you are using websense with ASA, the ASA will be asking websense using just one ip address, so it will not eat up many ips off of your license.
I hope it helps.
PK
01-18-2011 08:35 AM
Ram,
People pay big bucks ($21.00 per seat is what I remember from when I evaluated it a few years ago) for the outstandbing reporting capability it has. Now, if you make all the requests that look like one IP address, all browing would have been done by one person.
Upper management (when I evaluated, this when I was outside of Cisco) wanted reporting based on user names and IP addresses and the sites that they all visited and the hours that they spent. This wouldn't be possible but, you sure can save on the licensing .
edit:
Not to mention its feature to integrate with Active Directory so, you can allocate 20 min. of ebay shopping for one group, while letting another group 30 min of golf and chess online and unrestricted access to the other group. That wouldn't be possible if only one IP address.
-KS
01-18-2011 08:43 AM
Poonguzhali has a very good point!
Technically you can do it, but it will come at ease of management cost.
Federico.
01-18-2011 09:29 AM
Thanks for you valuable points guys. I am going to decide whether or not to go with NAT based on my customer's requirements.
Thanks a lot!!
Ram
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide