cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
573
Views
10
Helpful
4
Replies

ASA websense, check primary server, then secondary

wilson_1234_2
Level 3
Level 3

We have websense for our url filtering,

Can ASA 5510 be set up to check a primary server, then if that is not available, to check the secondary.

Will the ASA check from top down?

url-server (inside) vendor websense host Websense timeout 10 protocol UDP version 4

url-server (inside) vendor websense2 host Websense timeout 10 protocol UDP version 4

filter url except 10.250.0.0 255.255.0.0 0.0.0.0 0.0.0.0 allow

filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow

filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow

4 Replies 4

suschoud
Cisco Employee
Cisco Employee

Yes,

You can identify up to four filtering servers per context. The security appliance uses the servers in order until a server responds. You can only configure a single type of server (Websense or Secure Computing SmartFilter ) in your configuration.

ASA-5510-8x(config)# url-server (inside) vendor websense host 1.1.1.1

ASA-5510-8x(config)# url-server (inside) vendor websense host 1.1.1.2

Do rate helpful posts.

Regards,

Sushil

Thanks for the reply,

Oops, I had it incorrect, it should be like this right?:

name 10.1.1.1 Websense

name 10.1.1.2 Websense2

url-server (inside) vendor websense host Websense timeout 10 protocol UDP version 4

url-server (inside) vendor websense host Websense2 timeout 10 protocol UDP version 4

filter url except 10.250.0.0 255.255.0.0 0.0.0.0 0.0.0.0 allow

filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow

filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow

Correct.

Glad to help.

Regards,

Sushil

Since implementing this I am getting the "url server not responding" every five seconds.

Can I adjust this to something like having the ASA check every two minutes?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: