We have a PIX facing the Internet and recently introduced Websense for URL filtering. The method we use to send the traffic to websense is using a SPAN port on the core switch's interface that the INSIDE interface of the firewall connects to. This works very well for all users on the INSIDE network.
However we also have RA VPN users that also require to access the Internet and we are unsure how to force their traffic to Websense given they are coming from the OUTSIDE interface.
One thing we do know that there is a feature on the firewall to send http, https, ftp, java and active-x to websense regardless of which interface the traffic is coming from.