cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2762
Views
0
Helpful
6
Replies

WSA problem accessing two webs

hi,

We are having problem accessing to two of our webs. Doing a packet capture in the client machine we see the error 504, and doing pcap in the WSA we see the error 404. If we bypass the proxy both webs are working. We dont see any drops in FWs.

Where could it be the cause for this problem??? 


Product: Cisco S170 Web Security Appliance
Model: S170
Version: 10.1.0-204

6 Replies 6

syeda3
Level 1
Level 1

Please see the below troubleshooting urls for WSA for gateway timeout.

http://www.cisco.com/c/en/us/support/docs/security/web-security-appliance/118079-troubleshoot-wsa-00.html

http://www.cisco.com/c/en/us/support/docs/security/web-security-appliance/118217-troubleshoot-wsa-00.html

I saw all these notes and i opened a TAC case. TAC closed ticket because in the pcaps the error was 504 so the problem is in another intermmediate device. But after this, we bypass the WSA and its working fine. Three-way handshake is done properly between WSA and server, but when WSA sends GET we dont see any respond. So its seems like its not a connectivity problem.

Where could it be the cause for this problem??? 

Typically when troubleshooting an issue like this a network diagram that shows MAC & IP addresses is needed in order to understand what is being seen in the PCAP.

trying to ping the web site,  if your WSA is replying to the PING request the Layer 4 Traffic Monitor may be blocking the website,  not the URL filter.   

ping is not allowed in this server but running a GET from WSA i get response.  I checked  Layer 4 Traffic Monitor and its disabled.

Sriram Subramanian
Cisco Employee
Cisco Employee

The URL Category or Web Reputation Score in Access Policies / HTTPS Descryption Policy could be flagging the website you are accessing to be blocked. You could try creating a whitelist in the URL Category and applying it to the access policy to allow or pass through in HTTPS Descryption Policy.

We dont have any Decrypt policy. We tried that with no success :(