IronPort Web-Security and Cisco ASA 5500 series

2010.02.08

Some nuances I figured out while setting up an IronPort Web-Security appliance with a ASA firewalls.  The how-tos I’ve seen online were a bit lacking.

It’s easiest to use WCCP to hand-off traffic to the IronPort WSA.  WCCP requires basically three things to function:  Which ACLs you want to redirect, where you want to redirect them to, and which WCCP ‘service’ you want to use:

  1. In ASDM, the standard ACLs can be edited in Firewall | Advanced | ACL Manager
  2. Create an ACL of IPs you want to (or not) redirect to your WSA.  Redirect only the TCP/UDP services you want sent to the WSA.  If you configure ip/any in the ACL, then all packets will get sent over to the WSA.  This seems to break ICMP.  Do this through the GUI or from the CLI.  Some http-based apps don’t like this redirection so putting a ‘deny’ at the top of the ACL works.
  3. Create another ACL of your IronPort WSAs.  I think these need to be on the same subnet as the WCCP is happening (multicast and all).  i didn’t try putting the WSA on a separate interface than the ASA, nor did i try it with multicast routing enabled between them either.
  4. Third, we need to configure the redirection, and which interfaces the ASA listens to for WCCP.  In the GUI, Device Management | Advanced | WCCP.  Create a Service Redirection first.  This binds which IPs get to which WSAs.  Leave it on Web Cache for the simplest configuration.  I tried setting a password but that seemed to break WCCP.  (See notes below)


    The ‘redirection’ binds which interface the ASA listens for WCCP on.
  5. Lastly, don’t forget to set up ACLs so your WSAs can access the internet
  6. configuring the WSA-end of things is straight forward.  following the instructions from the help menu is about all you need.

Notes:

  • So far, I’ve only worked with the WSA 6.3.x code tree.
  • About policy matching:  Identity Polcy matches first.  Whether it’s IP or authentication based, first rule wins.  Take the matching Identity Policy that won and match it to the first Access Policy.  Then applications, URL categories, objects, etc.
  • As of ASA code 8.2.1, WCCP load balancing is only hash-based.  There’s no way to change it to (subnet) mask balancing.  if you need mask balancing, use an IOS-based device for now.
  • As of ASA code 8.2.1, any time you apply policy on the WSA (update access lists, identities, anything at all, really) you need to re-apply the service group (step 4); delete the policy, apply it.  create the policy and apply it.
  • The redirection password may be an issue with re-applying WSA policies.  We’re in production now so I haven’t taken it down to play.
  • If you use a ‘warning’ page for suspect URL categories (streaming media, social networking, etc) and you have hash-based load balancing, the users will get warned from each WSA you have load balanced
  • At this time, there’s no central management for multiple WSAs.  If you change policy on one WSA, you need to apply it to the other manually.
Categories : geek

choose

2010.02.01

I giggled.

Categories : fun  OMG DUDA WTF

math joke

2010.01.11

from a comment buried in a slashdot (people still read slashdot?) thread

As part of a psychological experiment, two single men, a physicist and mathematician, were placed in an otherwise empty room with a beautiful naked women at the far end.

They were instructed that they’d be allowed to close half the distance to the women every 10 minutes. Disgusted at the obvious subterfuge, the mathematician walked away in disgust. But the physicist stayed behind, occasionally glancing at his watch.

The experimenters looked puzzled, then asked the physicist, “You do realize, of course, that mathematically speaking, you can never actually reach the woman?”

“Naturally”, replied the physician, looking up. “But I can sure get close enough for all practical purposes!”

Categories : fun  geek

kulhanjian reunion

2010.01.10

mom wanted to put together four generations of kulhanjians in the same room.

there’s more over here.  for printing, high-resolution versions available upon request.

Categories : events  photography

catch-up

2010.01.10

725 posts?  wow.

oh folded paper, save me from the rain.  i think i found a new icon.  “300” effect.  bump 2 stops.  bump fill 2 stops.

our niece went to her first homecoming

The rest can be found here over here.

Categories : photography

Nick vs Pre

2009.12.04

Amanda and I migrated to Sprint over the weekend and picked up a couple of Palm Pre handsets.

Sprint’s service has been fine so far, we’ll see if there’s any billing or customer service fiascoes to deal with over time.

Good parts about the Pre:

  • Compact hardware
  • Slick OS
  • Screen
  • WiFi
  • Google integration (contacts, address book, mail, maps, chat, etc)
  • GPS
  • Synergy
  • Homebrew Community – there’s an active homebrew app/tweak development community with a few good repositories of such stuff.  I wonder how much of the official App Catalog‘s efforts are being thwarted by the increasingly popular homebrew stuff.  In all seriousness, is it that tough to get software approved for proper distribution?
  • ‘developer mode’ easter egg of searching for upupdowndownleftrightleftrightbastart
  • Browser – The Webkit browser is pretty quick at rendering webpages.  It handles zooming, panning, and scrolling nicely
  • Touchstone charger – although kinda pricey, inductive charging base is pretty sweet.

Bad Parts:

  • Battery life – some of this can be mitigated by changing data sync settings, screen timeout settings, and GPS settings
  • Select/Copy/Paste – Gestures for managing these are a bit cumbersome
  • it can be a bit slow.  for example, i have about 300 well-populated contacts.  the address book can take a few seconds to come up
  • Smallish keyboard takes some getting used to.  The ‘alt’ key is annoyingly close to the / key, which is the alternate for q (typing URLs is a pain.)

What I miss and might come later:

  • having both a ‘d-pad’ and touchscreen like previous Palm devices.  Makes it easier when you have to move one character over.  🙂
  • Screen brightness control – homebrew to the rescue for now though
  • on-screen keyboard – this one can be done with homebrew apps but nothing official yet
  • ability to remove some of the carrier-provided default applications

Essential Official Apps:

  • TweeFree – Twitter client that’s fast
  • Pandora – music genome project, 40 hours/month of free music
  • Facebook – Faster than the mobile site but less featured
  • Yelp – Location-based business reviews (restaurants, stores, etc).  I wish you could update/post from it though.

Essential Homebrew Apps:

  • Preware – Framework for installing homebrew apps
  • drPodder / PrePod – Podcast client which supports downloads for offline listening
  • Battery Icon and Percent
  • Brightness in Device Menu – saving battery
  • Calendar Month View Default
  • Call Duration in Call Log
  • Char Count in Messaging – Finding out when you’re close to 160 characters
  • GPS in Device Menu – Easier access to turning off the radio, saving battery
  • Just Charge by Default
Categories : geek  mobile  reviews

senator clay davis

2009.11.13

for my friends who watched the wire 🙂

thx tmbo

Categories : fun

Machinarium

2009.10.26

Amanda‘s been playing Machinarium.  The music is awesome and peaceful.  It has to be since it can be a pretty nerve racking puzzle game.  I played the free demo through steam though.

Turns out, all the music is MP3s and they’re in the game’s install folder!  There’s a sub-folder called 11 that has a bunch of .001 files.

They’re MP3s!  Copy them somewhere, rename them to mp3 and play them in your favorite MP3 player.  I’ve tried them in Winamp, WMP, and VLC.

Of course, you could support the artist.

Categories : fun  geek

Amanda’s Birthday

2009.08.22

Amanda turned… Old this month.  a bunch of her friends joined us to celebrate

Categories : events  fun

The 4th

2009.08.22

We spent the 4th with Joe, Christine, and others, followed by Clawson’s fireworks.

Categories : events  fun  geek