Quantcast
Channel: Forcepoint Community
Viewing all articles
Browse latest Browse all 2011

Policy is applied to client but not effective

$
0
0

Websense TRITON - Unified Security Center 7.6 build: 7.6.2.1449

I have multiple category-based policies being applied to AD users via AD security groups. I'm getting irregular and unpredictable results for the time it takes to 'refresh' and enforce policies for users. My users are being identified correctly on the client machines - checking the More Information frame shows the correctly identified user and correct policies.

For example:

1.       USER_A is added to an AD group: 'GROUP_StreamingMedia' which is attached to policy: POL_StreamingMedia. This policy allows the Streaming Media category.

2.       Within an hour, the User Service has done its job because I see the POL_StreamingMedia policy associated with the GROUP_StreamingMedia ‘client’ in the Check Policy tool. Shortly after this I see the refreshed results appear in the Test Filtering tool, suing a URL categorized as Streaming Media.

3.       USER_A is logged onto a Windows 7 domain client, and browses to the URL but gets the block page. They view More information and they see the correct LDAP path to their account and the correct policies applying.

Background:

·          ‘Use more restrictive blocking’ is inactive

·         Websense.ini modifications: [DirectoryService] CacheTimeout=60

·         Restarting the ‘Websense Filtering Service’ makes the changes take effect immediately, otherwise the change will take up to 5 hours to take effect

Could someone please point me to the correct debug/error log info to start troubleshooting?

Thanks and regards


Viewing all articles
Browse latest Browse all 2011

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>