04-21-2017 02:15 AM
hi,
We are having problem accessing to two of our webs. Doing a packet capture in the client machine we see the error 504, and doing pcap in the WSA we see the error 404. If we bypass the proxy both webs are working. We dont see any drops in FWs.
Where could it be the cause for this problem???
Product: Cisco S170 Web Security Appliance
Model: S170
Version: 10.1.0-204
04-21-2017 05:31 AM
Please see the below troubleshooting urls for WSA for gateway timeout.
http://www.cisco.com/c/en/us/support/docs/security/web-security-appliance/118079-troubleshoot-wsa-00.html
http://www.cisco.com/c/en/us/support/docs/security/web-security-appliance/118217-troubleshoot-wsa-00.html
04-21-2017 05:55 AM
I saw all these notes and i opened a TAC case. TAC closed ticket because in the pcaps the error was 504 so the problem is in another intermmediate device. But after this, we bypass the WSA and its working fine. Three-way handshake is done properly between WSA and server, but when WSA sends GET we dont see any respond. So its seems like its not a connectivity problem.
Where could it be the cause for this problem???
04-21-2017 10:08 PM
Typically when troubleshooting an issue like this a network diagram that shows MAC & IP addresses is needed in order to understand what is being seen in the PCAP.
trying to ping the
04-24-2017 12:11 AM
ping is not allowed in this server but running a GET from WSA i get response. I checked Layer 4 Traffic Monitor and its disabled.
04-24-2017 07:45 AM
The URL Category or Web Reputation Score in Access Policies / HTTPS Descryption Policy could be flagging the website you are accessing to be blocked. You could try creating a whitelist in the URL Category and applying it to the access policy to allow or pass through in HTTPS Descryption Policy.
04-25-2017 01:14 AM
We dont have any Decrypt policy. We tried that with no success :(
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide