cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
431
Views
2
Helpful
1
Replies

Cisco WSA (SWA) Capabilities: Confirmation of Features.

MSN
Level 1
Level 1

Our customer is considering purchasing Cisco WSA, and they would like to confirm if the following requirements are feasible with the solution before proceeding. Could someone please provide a quick response to the inquiries below?

  1. Is it possible to configure Cisco WSA to:

    • Alert on access to suspicious, dangerous, or blacklisted websites?
    • Generate alerts for exceeding bandwidth usage?
  2. Can the proxy be configured to control and limit bandwidth usage for individual users or IP addresses?

  3. Does Cisco WSA include sandboxing features that allow for blocking specific hash values or files?

  4. Is it possible to integrate Cisco WSA with our existing SIEM and monitoring systems, such as SolarWinds?

Thank you in advance for your guidance!

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

check my short answers.

1. yes it will be generated logs, you can generate report, if you have central logging send the logs and do the alerts based on alerts required.

2. check control bandwidth options :

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_010010.html

3. yes that is addon features you need to buy that.

guide lines :

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/215165-best-practice-guide-for-advanced-malware.html

4. You can do export the logs to SIEM from WSA Logs

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_010111.html

https://www.cisco.com/c/en/us/support/docs/security/web-security-appliance/118074-configure-wsa-00.html

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

1 Reply 1

balaji.bandi
Hall of Fame
Hall of Fame

check my short answers.

1. yes it will be generated logs, you can generate report, if you have central logging send the logs and do the alerts based on alerts required.

2. check control bandwidth options :

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_010010.html

3. yes that is addon features you need to buy that.

guide lines :

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/215165-best-practice-guide-for-advanced-malware.html

4. You can do export the logs to SIEM from WSA Logs

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_010111.html

https://www.cisco.com/c/en/us/support/docs/security/web-security-appliance/118074-configure-wsa-00.html

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help