Quantcast
Channel: Forcepoint Community
Viewing all articles
Browse latest Browse all 2011

Default Policy is being explicitly enforced

$
0
0

Hello all,

Admittedly, I have been a forum troll for answers, however, find myself not finding solutions to any of my issues,

* My First post (Question) - please help

ENVIRNMENT:

MS Windows 2012 R2 - WSGA 7.8.4 TRITON

Red Hat Enterprise Linux Server release 6.5 (Santiago) - WSGA 7.8.4 WCG (HF01 Multi Fix / HF03 Multi Fix / HF03 - UserService Anonymous Bind Fail / HF 04 Multi Fix)

ISSUE:

TRITON > Policy Management > Clients

We have 5 AD groups (L01 to L05)

L01 - Controlled Internet Access

L02 - Basic Internet Access

L03 - General Internet Access

L04 - General Internet Access plus additional protocols 

L05 - Unrestricted Internet Access

Each AD groups is assigned an Internet policy and Protocol Filter

We also make use of an Limited Access Filter for a list of approved sites (whitelist) clients are allowed to go to which ties to the WCG > Configure > Security > Access Control List and is assigned to the Default Policy.

PROBLEM:

With each group assigned their policy, everything works as designed, restrictions are applied, block pages .etc, however, when we activate, the default policy and assigned it the limited access filter (save and deploy), all groups explicitly enforce the Default Policy and only certain HTTPS sites open (ties to access filter), where, opening https://www.google.com is presented with page cannot be displayed message.

ANOMALY:

This is our QA environments and our production environment is set up the exact same way, however ever using WSGA 7.8.6 and everything is working as designed

INSTALLATION:

Fresh install, no policy imports

MAIN QUESTION:

Why is the Default Policy is being explicitly enforced

MY POLICY ASSIGNMENT:

L05 - Unrestricted Internet Access

TESTLOG SERVER:

Log Source= Protocol Log 

Client Hostname= 10.217.32.23

SourceIp= 10.217.32.23

DestinationIp= 91.225.248.129

server= 10.217.219.140

time= Mon Dec 01 08:59:22 2014   version= 6

disposition= 1031 - Blocked By Limited Access Filter

URL= https://www.linkedin.com

protocol= 11 - https  port= 443  networkDirection= Outbound

method= CONNECT

contentType = 

category= 1527 - Social Web Controls - LinkedIn

categoryReason= 1 - Master Database: URL

bytes sent= 0  bytes received= 0

file name= 

True File Type= 0 - None

roleId= 8

user= 

duration= 20 ms

scan duration= 14 ms

policyName= Super Administrator**Default

SIEM Results

   protocol version= 0

   server status code= 0

   proxy status code= 403

   client source port=56156

   client destination port= 8080

   proxy source=10.217.219.140

   proxy source port= 0

   user agent= Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.1.25 (KHTML, like Gecko) Version/8.0 Safari/600.1.25

   X-Forward For=


Viewing all articles
Browse latest Browse all 2011

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>