Solved

How do I get Websense to display PC name instead of IP address

Posted on 2009-04-10
10
1,949 Views
Last Modified: 2013-11-08
We have Websense 6.3.2 running on a Windows 2003 server, using port mirroring with a Cisco ASA 5510.  Filtering is working the way we want it.  However, when we try to run a report using the reporting tools, the activity is listed by IP address instead of by user or by machine name.  Our DHCP server winds up giving people new IP addresses every few days, so this is not very effective for us.  

I checked the eimserver.ini file, and found DNSlookup was set to "AUTO".  I changed it to "ON", but that had no effect.  Where do I go to change this?
0
Comment
Question by:natjbrown
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 11

Expert Comment

by:billwharton
ID: 24117502
Try these steps and tell me if it works

# For Websense Explorer issues, verify that Hide User Names in Reports is not selected in Websense Manager for your Delegated Administrator. This is a frequent cause of the problem.
# Verify that directory objects can be added without error messages appearing.

How do you know if you receive error messages when you add directory objects?

Open the file websense.log and review any errors listed for User Service. Possible errors include cannot connect to LDAP server and invalid credentials.

    * If you see the error cannot connect to LDAP server:
         1. Verify that User Service is started. If you are running in mixed mode, you might have to run User Service as a domain\admin account.
         2. Verify that the port used to connect to your Directory Service is open and listening (netstat, telnet).
         3. Verify that the settings for the Directory Service are correct in Websense Manager > Server > Settings > Directory Service.

    * If you see the error invalid credentials:
         1. Re-enter the password for the Directory Service in Websense Manager > Server > Settings > Directory Service.
         2. If User Service is running as a domain\admin account, re-enter the password for User Service.
         3. Add a root context for the Directory Service. See KB article 2862.


# Verify that Filtering Service is able to retrieve the user-to-IP mapping from your Transparent Identification Agent (such as DC Agent or Logon Agent). To check this, run the ConsoleClient utility against port 15869.  See KB article 3349.
# If the user-to-IP mapping has no names in it, check the settings for your Transparent ID Agent in Websense Manager. Make sure that Enable Authentication is enabled for the desired Agent.
0
 
LVL 11

Expert Comment

by:billwharton
ID: 24117529
btw, have you installed the user identification agent as explained in this url?

Go to http://kb.websense.com and search for 2684 and you'll see the article i'm talking about
0
 
LVL 1

Author Comment

by:natjbrown
ID: 24117806
We are using a DC agent to direct who is able to access different groups of websites.  It appears to be working fine, and I can add a new directory object without error.

Where do I verify that Hide User Names in Reports is not selected in Websense Manager for my Delegated Administrator?
0
Defend Your Organization from The Greatest Threats

Looking to fill the gaps in your security? Bring together information from the network, endpoint and threat intelligence feeds to really see what's happening in your organization. Join the WatchGuardians in their adventures fighting cyber crime!

 
LVL 1

Author Comment

by:natjbrown
ID: 24118812
I tried to verify that Filtering Service is able to retrieve the user-to-IP mapping from my Transparent Identification Agent (DC Agent) by running the ConsoleClient utility against port 15869.  

I got:
========================================
XID User Map PrintSelf
Snapshot time: 04-10-2009 14:03:41.226461
Number of entries in map is : 0
========================================

So obviously something isn't right there.
0
 
LVL 1

Author Comment

by:natjbrown
ID: 24119687
Where do I do this?
"# If the user-to-IP mapping has no names in it, check the settings for your Transparent ID Agent in Websense Manager. Make sure that Enable Authentication is enabled for the desired Agent."
0
 
LVL 14

Expert Comment

by:Ehab Salem
ID: 24248807
Open RealTimeAnalyzer and see first if it logs usernames or IPs.
If it logs IPs, then you have a problem in identifying users.
0
 
LVL 1

Author Comment

by:natjbrown
ID: 24359534
It appears to log IPs.  I have three ethernet ports on this sever, and it appears that some services are trying to use a port that they shouldn't.  I now have disabled one of the ports, and now the RealTimeAnalyzer does not show any traffic.  I am going to get someone else in to take a look at this mess.
0
 
LVL 8

Expert Comment

by:pgolding00
ID: 24810903
Would not DC agent, radius agent or one of the other transparent user agents do the trick? Check page 231 of this doc http://kb.websense.com/article.aspx?article=3133&p=12
0
 

Accepted Solution

by:
ee_auto earned 0 total points
ID: 26016266
Question PAQ'd, 500 points not refunded, and stored in the solution database.
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Wireless Access Controller 3 47
WLC and radius 4 46
SonicPoint N2 will not provision on SonicWall NSA220 4 53
CTIOS error on Windows 10 3 58
In this article we have discussed the manual scenarios to recover data from Windows 10 through some backup and recovery tools which are offered by it.
I previously wrote an article addressing the use of UBCD4WIN and SARDU. All are great, but I have always been an advocate of SARDU. Recently it was suggested that I go back and take a look at Easy2Boot in comparison.
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question