ASA with Websense filtering traffic on DMZ not working
I have a Cisco ASA firewall that is setup with an inside interface and a DMZ interface. I also have a Websense content filter that is currently filtering traffic succesfully on the inside interface.
I setup a DMZ port for our guest wireless network and traffic is flowing just fine over this interface and out to the internet. I want to be able to filter this traffic just like I filter the internal traffic.
I configured the ASA for the WCCP redirect for the DMZ interface and when I do then no traffic is allowed out to the internet and I am not getting any response from the Websense.
Here is the config before any changes to the WCCP config from the ASA:
wccp 0 redirect-list WCCP group-list PROXY-WS
wccp 70 redirect-list WCCP group-list PROXY-WS
wccp interface inside 0 redirect in
wccp interface inside 70 redirect in
I added the following lines to the ASA and after I did this traffic over the DMZ port stopped. Internal traffic continued to work fine and is filtered.
wccp interface DMZ 0 redirect in
wccp interface DMZ 70 redirect in
Here is the PROXY-WS command
access-list PROXY-WS extended permit ip host 126.96.36.199 any
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...