Websense not filtering entire IP range

rated by 0 users
Not Answered This post has 0 verified answers | 3 Replies | 2 Followers

Top 500 Contributor
9 Posts
Fusion-Tech posted on 23 Aug 2011 11:37 AM

I am running Websense 7.6 in standalone mode. All services are installed on one machine. My subnet is a /23 and our IP range is 10.10.30.1-10.10.31.254. I recently found out that websense isn't blocking any computers on the .31.xxx but is blocking on the .30.xxx.

I've verified the range is correct in the manager. i've even gone as far as entering it in different ways to see if it helps (tried 10.10.30.1-10.10.31.254 ; 10.0.0.0-10.255.255.255 ; 10.10.30.1-254 and 10.10.31.1-254) but they all result the same.

I also ran the testlogserver on a computer sitting on a .31 address and I am able to see the traffic however everything is coming back as "allowed". Ran the same testing on a computer on a .30 address and traffic is blocked. Specifically I am testing youtube.com.

Any help you guys can offer would be appreciated.

|

All Replies

Top 10 Contributor
986 Posts
Trusted Users (MVP)

If testlogserver shows the traffic as being allowed then it's an issue with how you've applied a policy to that IP range (or users).  Testlogserver should have included all information about the host, so make sure the username isn't in a group/OU/domain you have a policy to, or that there's a conflicting IP based policy applied.

|
Top 500 Contributor
8 Posts

Thanks for the reply.  Since the policy was applied to an IP I was thinking that maybe order of precedence was the issue.  I thought IP would take precedence over the user but maybe I had that wrong.  To be sure assigned the User directly to the same policy and ran testlogserver agiain.

time= Tue Aug 30 14:18:01 2011   version= 5
server= 10.20.161.xx  source= 10.20.xx
URL= www.flalottery.com
protocol= 1 - http  port= 80  networkDirection= Inbound
method=
contentType =
category= 13 - GAMBLING
categoryReason= 0 - CatNone
disposition= 1027 - Custom URL - Category Blocked
roleId= 0
user= LDAP://xxx OU=xxx,OU=xxx,OU=xxx,DC=xxx,DC=xxx,DC=xxx,DC=xxx,DC=xxx/testuser
bytes sent= 538  bytes received= 199
  duration= 0 ms   scan duration= 0 ms
policyName=

Network direction inbound?  that is interesting.

I also see that there is no policyname but the category is blocked as is expected. It was blocked in previous testlog server using ip too.

Thanks

|
Top 10 Contributor
986 Posts
Trusted Users (MVP)

I thought you said it was the 10.10.30.xxx range that wasn't being filtered?  your example is 10.20.xxx

|
Page 1 of 1 (4 items)