07-15-2012 09:48 PM
Hi,
I'm having trouble with accessing www.linkedin.com
The symptoms are that the page is not displaying correctly. Only links appear on the left hand side of the page. I remember facebook having issues rendering pages incorrectly a while ago.
Because this is in the category of Social Networking, I should instead be receiving a blocked page message. If I add the site manually to this category however, I do get the blocked page.
I do want everyone to be able to access this site (but only allow facebook and other social networking sites via allow rules via this category). To do this, I have added the site to the whitelist but still have issues rendering the website correctly. I have also tried adding the site to the proxy bypass list and still receive the same symptoms.
Can anyone assist please?
The ironport device is s370 with version 7.1.4
I have attached to show what the website looks like.
Solved! Go to Solution.
07-17-2012 11:21 PM
We faced bit similar issue . Linkedin pictures were not displaying while going thorugh proxy because linked is allowed through custom url catagory and social networking is blocked for the user's.
It works after allowing
[a-z|0-9].licdn.com/*
07-18-2012 05:56 AM
The first step in trouble shooting any URL issue is to grep for the access logs.
To grep the access logs for an entry, SSH into the WSA and run the following command from the CLI:
1. Grep
2. Enter the number of the log you wish to grep.
[]> 1
3. Enter the regular expression to grep.
[]> IP of the PC that the issue is being re produced on.
4. Do you want this search to be case insensitive? [Y]>
5. Do you want to search for non-matching lines? [N]>
6. Do you want to tail the logs? [N]> Yes
7. Do you want to paginate the output? [N]>
Once you have the grep output please paste it in this discussion.
Sincerely,
Erik Kaiser
Cisco WSA Forums Moderator
07-18-2012 10:16 PM
Hi Shaun,
Yes you would add .licdn.com & licdn.com to a custom URL category which you would then add to the Default Access Policy. Leave the action on that custom category to Monitor. This will allow linkedin to work correctly.
Sincerely,
Erik Kaiser
WSA Cisco Forums Moderator
07-17-2012 04:25 PM
Bumping this one. No ideas anyone?
07-17-2012 11:21 PM
We faced bit similar issue . Linkedin pictures were not displaying while going thorugh proxy because linked is allowed through custom url catagory and social networking is blocked for the user's.
It works after allowing
[a-z|0-9].licdn.com/*
07-18-2012 09:29 PM
Thank You ndc.cisco. I actually just added .licdn.com to our whitelist and no more problems exist.
This is now resolved.
I will Grep first next time - thanks Erik
07-18-2012 05:56 AM
The first step in trouble shooting any URL issue is to grep for the access logs.
To grep the access logs for an entry, SSH into the WSA and run the following command from the CLI:
1. Grep
2. Enter the number of the log you wish to grep.
[]> 1
3. Enter the regular expression to grep.
[]> IP of the PC that the issue is being re produced on.
4. Do you want this search to be case insensitive? [Y]>
5. Do you want to search for non-matching lines? [N]>
6. Do you want to tail the logs? [N]> Yes
7. Do you want to paginate the output? [N]>
Once you have the grep output please paste it in this discussion.
Sincerely,
Erik Kaiser
Cisco WSA Forums Moderator
07-18-2012 06:35 PM
Hi Erik,
Thanks. I have performed the appropriate grep as requested. Here is the output:
1342660798.284 249 10.33.170.56 TCP_MISS/200 8396 GET
"domain\username@domain" DIRECT/www.linkedin.com text/html MONITOR_CUSTOMCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-DefaultGroup
1342660798.306 0 10.33.170.56 TCP_DENIED/407 1723 GET
http://s3.licdn.com/scds/concat/common/css?h=14ei741up8a35oqzaaqbo2zar&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.307 0 10.33.170.56 TCP_DENIED/407 1723 GET
http://s4.licdn.com/scds/concat/common/css?h=33tdivxzq9w7ezjxsor11kjw5&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.307 0 10.33.170.56 TCP_DENIED/407 1723 GET
http://s3.licdn.com/scds/concat/common/js?h=7te4p95pipb5icveef284kps-6fpgvxfmet1dgazyby9ub4rnk&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.308 1 10.33.170.56 TCP_DENIED/407 1723 GET
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",13784.00,0,-,"-","-"> - -
1342660798.310 0 10.33.170.56 TCP_DENIED/407 531 GET
http://s3.licdn.com/scds/concat/common/js?h=7te4p95pipb5icveef284kps-6fpgvxfmet1dgazyby9ub4rnk&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.310 0 10.33.170.56 TCP_DENIED/407 531 GET
http://s3.licdn.com/scds/concat/common/css?h=14ei741up8a35oqzaaqbo2zar&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.310 0 10.33.170.56 TCP_DENIED/407 531 GET
http://s4.licdn.com/scds/concat/common/css?h=33tdivxzq9w7ezjxsor11kjw5&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.316 0 10.33.170.56 TCP_DENIED/407 531 GET
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.317 12 10.33.170.56 TCP_DENIED/403 7483 GET
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.325 13 10.33.170.56 TCP_DENIED/403 4207 GET
http://s4.licdn.com/scds/concat/common/css?h=33tdivxzq9w7ezjxsor11kjw5&fc=1
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.336 24 10.33.170.56 TCP_DENIED/403 4207 GET
http://s3.licdn.com/scds/concat/common/css?h=14ei741up8a35oqzaaqbo2zar&fc=1
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.347 36 10.33.170.56 TCP_DENIED/403 4375 GET
http://s3.licdn.com/scds/concat/common/js?h=7te4p95pipb5icveef284kps-6fpgvxfmet1dgazyby9ub4rnk&fc=1
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.360 43 10.33.170.56 TCP_DENIED/403 9289 GET
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.626 0 10.33.170.56 TCP_DENIED/403 4131 GET
http://s4.licdn.com/scds/common/u/img/tracker.gif?id=sct--174041236
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.029 0 10.33.170.56 TCP_DENIED/407 1723 GET
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.033 0 10.33.170.56 TCP_DENIED/407 531 GET
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.284 249 10.33.170.56 TCP_MISS/200 8396 GET
"domain\username@domain" DIRECT/www.linkedin.com text/html MONITOR_CUSTOMCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-DefaultGroup
1342660798.306 0 10.33.170.56 TCP_DENIED/407 1723 GET
http://s3.licdn.com/scds/concat/common/css?h=14ei741up8a35oqzaaqbo2zar&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.307 0 10.33.170.56 TCP_DENIED/407 1723 GET
http://s4.licdn.com/scds/concat/common/css?h=33tdivxzq9w7ezjxsor11kjw5&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.307 0 10.33.170.56 TCP_DENIED/407 1723 GET
http://s3.licdn.com/scds/concat/common/js?h=7te4p95pipb5icveef284kps-6fpgvxfmet1dgazyby9ub4rnk&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.308 1 10.33.170.56 TCP_DENIED/407 1723 GET
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",13784.00,0,-,"-","-"> - -
1342660798.310 0 10.33.170.56 TCP_DENIED/407 531 GET
http://s3.licdn.com/scds/concat/common/js?h=7te4p95pipb5icveef284kps-6fpgvxfmet1dgazyby9ub4rnk&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.310 0 10.33.170.56 TCP_DENIED/407 531 GET
http://s3.licdn.com/scds/concat/common/css?h=14ei741up8a35oqzaaqbo2zar&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.310 0 10.33.170.56 TCP_DENIED/407 531 GET
http://s4.licdn.com/scds/concat/common/css?h=33tdivxzq9w7ezjxsor11kjw5&fc=1
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.316 0 10.33.170.56 TCP_DENIED/407 531 GET
- NONE/- - OTHER-NONE-domain_Identity-NONE-NONE-NONE-NONE <-,-,"-","-",-,-,-,"-","-",-,-,-,"-","-",-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-"> - -
1342660798.317 12 10.33.170.56 TCP_DENIED/403 7483 GET
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.325 13 10.33.170.56 TCP_DENIED/403 4207 GET
http://s4.licdn.com/scds/concat/common/css?h=33tdivxzq9w7ezjxsor11kjw5&fc=1
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.336 24 10.33.170.56 TCP_DENIED/403 4207 GET
http://s3.licdn.com/scds/concat/common/css?h=14ei741up8a35oqzaaqbo2zar&fc=1
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.347 36 10.33.170.56 TCP_DENIED/403 4375 GET
http://s3.licdn.com/scds/concat/common/js?h=7te4p95pipb5icveef284kps-6fpgvxfmet1dgazyby9ub4rnk&fc=1
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.360 43 10.33.170.56 TCP_DENIED/403 9289 GET
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
1342660798.626 0 10.33.170.56 TCP_DENIED/403 4131 GET
http://s4.licdn.com/scds/common/u/img/tracker.gif?id=sct--174041236
"domain\username@domain" NONE/- - BLOCK_WEBCAT_11-DefaultGroup-domain_Identity-NONE-NONE-NONE-NONE
So looking at this, do I allow ".licdn.com"?
07-18-2012 10:16 PM
Hi Shaun,
Yes you would add .licdn.com & licdn.com to a custom URL category which you would then add to the Default Access Policy. Leave the action on that custom category to Monitor. This will allow linkedin to work correctly.
Sincerely,
Erik Kaiser
WSA Cisco Forums Moderator
05-29-2013 05:45 AM
Hello
I am also facing the same issue.
Requirement: Allow only linked in and block all social networking sites
Changes made: Added custom category for linkedin and the same allowed in access and decryption policies and blocked social networking category.
custom category sites added
[a-z|0-9].licdn.com/*
23.32.0.0/11, 23.64.0.0/14, 118.214.0.0/15
Still the linkedin site is not working properly and the same is working when i enabled the default category of social networking.
Please check and help to resolve the issue.
Thanks
Siva
Below is the grep logs.
1369819812.940 375
1369819813.579 637
1369819813.598 655
1369819828.599 70510
1369819868.600 110511
1369820001.516 479
1369820001.527 494
1369820001.527 490
1369820001.541 508
1369820001.556 520
1369820001.557 522
1369820002.253 720
1369820002.261 718
1369820002.281 723
1369820002.285 755
1369820002.285 725
1369820002.285 766
1369820003.037 782
1369820003.040 757
1369820003.040 775
1369820003.041 752
1369820003.048 757
1369820003.077 787
1369820003.667 616
1369820003.688 641
1369820003.688 633
1369820003.693 651
1369820003.703 623
1369820003.703 654
1369820003.704 658
1369820003.704 661
1369820003.711 673
1369820004.342 651
1369820004.354 662
1369820004.354 647
1369820004.815 455
1369820005.419 601
1369820005.823 2114
1369820006.011 2299
1369820006.240 2532
1369820006.270 445
1369820006.442 2736
1369820006.460 446
1369820006.644 371
1369820006.662 420
1369820007.015 3307
1369820007.025 581
1369820007.316 652
1369820007.667 650
1369820007.719 700
1369820008.387 665
1369820008.490 769
1369820008.492 767
1369820009.356 861
1369820009.405 909
1369820010.235 827
1369820010.276 869
1369820010.906 626
1369820010.941 662
1369820060.942 62537
1369820065.943 67538
05-29-2013 06:43 AM
Looking at your grep add 118.215.177.244 and you should be fine.
Thanks
Chris
05-29-2013 07:46 AM
The ip network 118.214.0.0/15-----[118.214.0.1-118.215.255.254] already added in the custom category. But it still denied by using web cat instead of cust cat.
1369820010.941 662
Regards,
Siva
05-29-2013 08:04 AM
Not sure then, checking our rule to allow linked in we have custom:
linkedin.com, .linkedin.com, licdn.com, .licdn.com
Thanks
Chris
05-29-2013 10:30 AM
Whoah for a minute - if you put 23.32.0.0/11 into the allow custom cat, you are explicitly allowing access to 2,097,152 IPs, irrespective of their contents. /14 and /15 are marginally better - allowing 262,144 and 131,072 hosts, respectively. I would strongly urge you to reconsider allowing such a vast swath of IP space to be granted explicit access.
custom category sites added
[a-z|0-9].licdn.com/* - the same thing is accomplished by having .licdn.com, licdn.com in the whitelist. The asterisk does not work as a wildcard here, as far as I know. You can use regular expressions to restrict/allow access to certain sites following the / part of the web address, but that's not what you are trying to accomplish here.
23.32.0.0/11, 23.64.0.0/14, 118.214.0.0/15 - where did you get these IP ranges? 118.215.177.244 in a browser takes you to UPS.com, and resolves to: a118-215.177-244.deploy.akamaitechnologies.com - LinkedIn uses their own proprietary content delivery network for content.
In short, if you take Chris' advice above, and just add linkedin.com, .linkedin.com, licdn.com, .licdn.com, to your whitelist, it will should work, and make administration far, far easier for you.
05-29-2013 10:39 AM
Or, you could upgrade to the latest build of 7.5.1 and use Application Visiblity Controls to allow access to LinkedIn and not the other social sites...
01-28-2024 06:45 AM - edited 11-11-2024 10:30 AM
The IP network 118.214.0.0/15, within the range 118.214.0.1-118.215.255.254, is already included in the custom category. However, despite this, it is being denied when using web cat instead of cust cat. The log indicates a TCP_DENIED/403 error for a connection attempt to 118.215.177.244:443.
Regards, udit
02-18-2024 01:52 PM
Hello @uditbarma20
here are some points which I would like to highlight:
[1] Custom Categories are top-to down ( make sure there are no other categories above the one which are expecting to hit)
[2] In Explicit Mode the name resolution is done from WSA but in transparent mode from Client,
[3] check the Accesslogs or Web Tracking report and:
[3-1] Make sure you are hitting correct Custome Category
[3-2] You are hitting correct Policy ( Decryption & Access )
[4] Please be advised, if the traffic is HTTPs and the URL is set to pass through (could be due to WBRS score) then it will never hit access policy, so it is best to Block the Custom Cat in both Decryption and Access policy
Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide