Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Not sure if this was overlooked, but after July most browsers will start having errors on SHA2 certificates. Noticed that there is no option to present a SHA2 Cert for the HTTPS Proxy just a SHA1.
If this on the roadmap for a future patch?
I was wondering if WSA has any file analysis capabilities beyond anti-malware detection. Something we could setup a simple filter for similar to a content filter in an ESA appliance. We have had a number of malicious files getting through the WSA, an...
Something new I have been running against are e-mails that typo our domain to get past spoofing. So I applied a similar rule to fight this along with a dictionary that I would for Spoofing.
First step generate typosquatting domains from your legit d...
Is there a method to report malicious URLs to Cisco? I see this is not done via categorization so wanted to see what is available when missed malicious sites are caught after the fact (infection).
So it has been about a month or 2 since I finally got my AMP license installed. Today a few of my users are starting to get[Warning: Attachement Unscanned] on the Subjects of their incoming e-mails. I have a feeling there is something misconfigured o...
The following is adapted from deployment information from another cache solution. It begins to explain some of the limitations of Cisco's implementation of WCCP on the ASA's the first one also applies to ISRs. I was not able to find the same informat...
So this is the one thing I have struggled with the WSA/ASA WCCP pair for a while. I recently found out that in the ASA WCCP implementation HTTPS DNS traffic is not forwarded to the WSA. Without the DNS information redirected the WSA is unable to filt...
For those running into this issue and want to know how to configure in exchange for the ESA:
Here is how to setup in exchange 2013 a proper receive connector for Cisco ESA
https://technet.microsoft.com/en-us/library/jj657467(v=exchg.150).aspx
Here ...
I also recommend doing a Quarantine-Duplicate just before you strip the attachments, just incase you get a one off legitimate important document you need to recover.
You can still add a disclaimer text, and strip the attachment.
Yes, next to the Drop there is a ? bubble and when you click on it:
No end-user notification will be provided for dropped HTTPS connections. Use this setting with caution.
I took this as, don't use this option unless you have a special case as the ...