04-07-2013 07:50 AM
We have an ASA configured for WCCP, forwarding to a WSA in Transparent mode. HTTP traffic is blocked correctly per our policies. However, even though HTTPS Proxy is enabled with a root cert and Decryption Policy is set for global to Decrypt, the HTTPS traffic is not blocked and doesn't even show up in the reports. If we set the web browser manually to use the Ironport for proxy, it works. I thought the whole point of WCCP and transparent mode was to not have to define the proxy at the browser level?
04-08-2013 01:23 PM
Did you add the https ports on the Network/Transparent Redirection page?
Does the ACL that you have on the ASA have any ports on it? the service should be "ip"
04-09-2013 06:20 AM
"Standard Service" was changed to Dynamic (90) and ports configured to 80,443. Firewall is set to ip as you mention (i.e. no specific ports.)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide