Hello all,
Admittedly, I have been a forum troll for answers, however, find myself not finding solutions to any of my issues,
* My First post (Question) - please help
ENVIRNMENT:
MS Windows 2012 R2 - WSGA 7.8.4 TRITON
Red Hat Enterprise Linux Server release 6.5 (Santiago) - WSGA 7.8.4 WCG (HF01 Multi Fix / HF03 Multi Fix / HF03 - UserService Anonymous Bind Fail / HF 04 Multi Fix)
ISSUE:
TRITON > Policy Management > Clients
We have 5 AD groups (L01 to L05)
L01 - Controlled Internet Access
L02 - Basic Internet Access
L03 - General Internet Access
L04 - General Internet Access plus additional protocols
L05 - Unrestricted Internet Access
Each AD groups is assigned an Internet policy and Protocol Filter
We also make use of an Limited Access Filter for a list of approved sites (whitelist) clients are allowed to go to which ties to the WCG > Configure > Security > Access Control List and is assigned to the Default Policy.
PROBLEM:
With each group assigned their policy, everything works as designed, restrictions are applied, block pages .etc, however, when we activate, the default policy and assigned it the limited access filter (save and deploy), all groups explicitly enforce the Default Policy and only certain HTTPS sites open (ties to access filter), where, opening https://www.google.com is presented with page cannot be displayed message.
ANOMALY:
This is our QA environments and our production environment is set up the exact same way, however ever using WSGA 7.8.6 and everything is working as designed
INSTALLATION:
Fresh install, no policy imports
MAIN QUESTION:
Why is the Default Policy is being explicitly enforced
MY POLICY ASSIGNMENT:
L05 - Unrestricted Internet Access
TESTLOG SERVER:
Log Source= Protocol Log
Client Hostname= 10.217.32.23
SourceIp= 10.217.32.23
DestinationIp= 91.225.248.129
server= 10.217.219.140
time= Mon Dec 01 08:59:22 2014 version= 6
disposition= 1031 - Blocked By Limited Access Filter
URL= https://www.linkedin.com
protocol= 11 - https port= 443 networkDirection= Outbound
method= CONNECT
contentType =
category= 1527 - Social Web Controls - LinkedIn
categoryReason= 1 - Master Database: URL
bytes sent= 0 bytes received= 0
file name=
True File Type= 0 - None
roleId= 8
user=
duration= 20 ms
scan duration= 14 ms
policyName= Super Administrator**Default
SIEM Results
protocol version= 0
server status code= 0
proxy status code= 403
client source port=56156
client destination port= 8080
proxy source=10.217.219.140
proxy source port= 0
user agent= Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.1.25 (KHTML, like Gecko) Version/8.0 Safari/600.1.25
X-Forward For=