Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Websense content filter exception

Status
Not open for further replies.

jayoungf9

Technical User
Jun 10, 2001
3
GB
Dear Forum members,

I wonder if you could help me with the following problem please.

We use websense for traffic filtering however, it's a bit slow on returning the web page.
If it's switched off network traffic is fine. However, I'm looking for a balance between the two.
I want my users to still go through websense to get to stuff like but for
some intranet based web servers I want to make an exception and not use websense to avoid the excessive wait.

The PIX is a 515E running 6.2(2)

Here's the current config;

url-server (outside) vendor websense host 80.192.56.1 timeout 5 protocol TCP version 1
url-cache dst 128KB
filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url 8080 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url except 0.0.0.0 195.168.10.1 255.255.255.255

(80.192.56.1) is the IP address of the websense server. Note, that the websense server is outside.
(195.168.10.1) is a host http server on our intranet
e0 address is 86.194.122.12
e1 address is 11.0.0.1

when I run a sh filter I get

filter url except 0.0.0.0 195.168.10.1 255.255.255.255
filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url 8080 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow

I would have expected to get

filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url 8080 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
filter url except 0.0.0.0 195.168.10.1 255.255.255.255

But, accessing 195.168.10.1 is still slow. When I turn off websense, it's fine.

Please note that the IP addresses are for illustration purposes only.
Any help would be appreciated.

Sincerely,

James
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top