I have a new websense install that's integrated with a Cisco ASA. I've excluded the servers from HTTTP/S filtering in the cisco:
filter https except 192.168.100.0 255.255.255.128 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.205 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.207 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.210 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.206 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.209 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.204 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.208 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.202 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.203 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.201 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter https except 192.168.100.170 255.255.255.255 0.0.0.0 0.0.0.0 allow
filter url except 192.168.100.202 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block longurl-truncate cgi-truncate
filter url except 192.168.100.208 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block cgi-truncate
filter url except 192.168.100.206 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block cgi-truncate
filter url except 192.168.100.207 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block cgi-truncate
filter url except 192.168.100.204 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block cgi-truncate
filter url except 192.168.100.209 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block cgi-truncate
filter url except 192.168.100.205 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block cgi-truncate
filter url except 192.168.100.203 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block longurl-truncate cgi-truncate
filter url except 192.168.100.201 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block longurl-truncate
filter url except 192.168.100.210 255.255.255.255 0.0.0.0 0.0.0.0 allow proxy-block cgi-truncate
filter url except 192.168.100.170 255.255.255.255 0.0.0.0 0.0.0.0 longurl-truncate
filter url http 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow proxy-block longurl-deny
filter https 443 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 allow
I've also excluded them in the Network Agent setup page, but when I look at the Subscription Tracker they're listed as consuming a license (edited to just show the problem servers):
----------------------------------------------------------------------
Subscription Tracker - PrintSelf - Level: 3
Time: Wed Oct 08 15:58:32.446 2014
----------------------------------------------------------------------
Subscription Map Contents:
... 192.168.100.170 192.168.100.202 192.168.100.203 192.168.100.205
192.168.100.214 ...
How do I correct this?