Solved

web usage reports after PAT to external scansafe web proxy service

Posted on 2012-12-23
1
1,082 Views
Last Modified: 2013-01-22
Hi We recently put a  NAT /PAT  inside to outside interface (on ASA firewall) and port 80/http to 8080 port forward -direct to Cisco's scansafe proxy servers IP address on the web.
We  have some "exceptions" for http sites we dont want filtered - these are ok and also listed in the ASA firewall

We did this to solve a number of problems

1. Apple IPAD's - wifi - avoid manual proxy in browser
2 avoid manual proxy entry for all different types of browser
basically now proxy config is all in the ASA firewall.

Problem is now that due to the ASA NAT the scansafe reports show only the "outside" IP as the no1 user - basically the only user. - so now i cant get meaningful web usage reports.

Before with proxy ticked in users client browser - THe reports showed individual usage.
I want to keep what we have done on the ASA - I dont want to do a PAC file etc.

Does anyone know how I can go about getting the Scansafe to show individual web usage again? - something i can do on ASA?
  Thanks
0
Comment
Question by:philb19
1 Comment
 
LVL 61

Accepted Solution

by:
btan earned 500 total points
ID: 38718405
looks similar to this issue raised

using syslog and do manual mapping  - doesnt seems operationally friendly
https://supportforums.cisco.com/message/194755#194755

"Another way might be to add an access-list on the inside interface and add logging to " ip any any " which would be logged to the syslog server. But this might cause a lot of traffic for the syslog server."

also saw in  scansafe help doc stating below
https://scancenter.scansafe.com/portal/static/help/ScanCenterHelp/WSAAP3.html

(in case you need) online help - https://scancenter.scansafe.com/portal/static/help/ScanCenterHelp/

"Cisco ASA 5500 Series Adaptive Security Appliances with version 8.3 or later of the operating system can be configured to enable user names, internal IPs, and domain groups to be sent via PIM to Cisco Cloud Web Security without needing to make end-user changes. There are several ways to achieve this but Cisco recommends using explicit proxy, PAC file or WPAD."
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now