AsyncOS 5.6.0 for Web is now Generally Available

I am pleased to announce the "GA" release of 5.6.0. Code named "Maui" internally, this release is primarily focused on core proxy functionality. We have had great feedback from our beta testers and early adopters. I encourage customers to give 5.6.0 a try.
A few notes:
We have changed the way policies work and also added a new authentication layer called "identities". After upgrade we strongly recommend customers verify the post upgrade configuration to ensure policies and identities have been migrated appropriately to match your business needs.
If HTTPS was enabled and then is disabled at the time of upgrade, any archived decryption policies will not be maintained during the upgrade.
To enhance the security of the WSA, we explicitly prevent the WSA from proxying requests on the P2 interface. Customers who need this functionality may want to wait for the 5.6.2 release, which will support this configuration.
New Features in 5.6.0
* New Feature: Multi-core scanning (for improved performance)
* New Feature: Time-based policies for URL filtering
* New Feature: Enhanced routing policies (failover, load balancing, and conditional routing to multiple upstream proxies)
* New Feature: User-agent based policies
* New Feature: Policy trace tool
* New Feature: Custom EUN pages
* New Feature: SNMP enhancements (SNMPv1, 2, and 3, with support for traps and community strings)
* New Feature: Transparent bypass list
* New Feature: PAC file hosting
* New Feature: Active mode FTP over HTTP
* New Feature: GUI-based packet capture
Let us know what you think.
Regards,
Chris Haag
Manager, Technical Support

I need two identical identity policies that just say the authentication is CORP. Then in the access policies I limit the users. It would seem the user limiting should be done in the Identity Policy.
No, you only need one identity! In fact, if you've got 2 identities which are the same then the 2nd one will never actually match.
Identities and Access Policies are both a top-down, first match - with identities done first. So in your case you'd need one identity matching the domain CORP, and then in the access policy you can further limit that since identity based on the username.
Processing-wise it will do a top-down match on the identity to find the first match (your CORP identity) and then do a top-down match in the access policies to find a policy based on the CORP identity which matches the extra criteria you've added (ie, specific users/groups).
You can certainly end up in a situation where you can implement the same rules in a few different ways through a mixture of identities/policies, but at the end of the day it probably doesn't matter how you do it - pick whichever makes most sense for you!

Similar Messages

  • AsyncOS 5.1.2 for Web is now available

    IronPort Systems is pleased to announce the availability of AsyncOS 5.1.2-001 for Web on IronPort S-Series Web Security Appliances.
    This maintenance release contains all of the critical fixes from the 4 hot patch builds since the AsyncOS 5.1.1 maintenance build (5.1.1-002). These fixes fall into the following general categories:
    * HTTP proxy, protocol, and caching
    * Authentication
    * URL filtering
    * Policy configuration

    5.2.0 Stage 1 limited public release is available right now. If you contact your sales / SE person, they can have you provisioned to upgrade.
    The full public release will be available within the next 4-6 weeks.
    It is general policy to trickle the availability of a minor version before making it generally available, but this is an official (non-beta) release.

  • VMware vCenter Application Discovery Manager 6.2.2 is now generally available

    Hello all,
    We are pleased to announce that VMware vCenter Application Discovery Manager 6.2.2 is now generally available.
    If you have purchased the product, you can download it from the Application Discovery Manager home page.
    vCenter Application Discovery Manager 6.2.2 is a maintenance release.
    Support for VMware vSphere 5.0 has been added to this release.
    The release notes and guides are available here.
    Best regards,
    The VMware vCenter Application Discovery Manager team

    There is no open source version of vADM.  What you are probably looking at is a list of open source components that are included inside the vADM image.  We list all open source component for compliance reasons.
    The installation steps for vADM can be found in the Administrator Guide.
    I hope this helps.

  • VMware vCenter Application Discovery Manager 6.2 is now generally available

    Hello all,
    We are glad to announce that VMware vCenter Application Discovery Manager 6.2 is now generally available.
    If you have purchased the product, you can download it from the Application Discovery Manager home page.
    We've added the following new features in this release:
    User authentication over LDAP
    A built-in Application Pattern for Microsoft SharePoint
    NMAP as an additional discovery method during IP Discovery
    The release notes and guides are available here.
    Best regards,
    The VMware vCenter Application Discovery Manager team

    There is no open source version of vADM.  What you are probably looking at is a list of open source components that are included inside the vADM image.  We list all open source component for compliance reasons.
    The installation steps for vADM can be found in the Administrator Guide.
    I hope this helps.

  • AsyncOS 6.3.3 for Web is GA

    Hi,
    Cisco is pleased to announce a maintenance release of AsyncOS 6.3.3-015 for Web to all customers (GA). This release applies to all our Web Security Appliances (S-Series).
    Enhancements and Fixes in AsyncOS 6.3.3-015 for Web
    Fixed: Web Proxy returns incomplete web pages from objects in the web cache in some cases [Defect ID: 66076]
    Fixed: Uploading data to servers using a POST command fails in some cases [Defect ID: 52504]
    Fixed: Appliance may lock up or reboot when tailing access logs in some cases [Defect ID: 42438]
    Fixed: TLS/SSL Man-in-the-Middle Vulnerability [Defect ID: 55972]
    Fixed: hostkeyconfig CLI command erroneously returns a traceback in some cases [Defect ID: 48748]
    Fixed: Cannot join the Active Directory domain in some cases [Defect ID: 54854]
    For further information about this release, please refer to the AsyncOS Release Notes. The release notes are available on our Support
    Portal.
    Release Stage
    General Availability (GA): This release is available to all our customers and is a recommended build to be used in your production environments.
    Please have a look at the release notes and give the new build a spin!
    Thank you for choosing Cisco IronPort Security Products.
    Cheers,
    Jakob

    .

  • Hit Counter For Web Site Now Working?

    I have a web site that was published with iWeb 06. I am using a domain name at GoDaddy and forwarding to .Mac using masking so the site shows with the domain name not the .Mac address. If you went to the site by entering the domain name the hit counter on the first page would not show. However, if you entered the .Mac address to go to the site the counter would show.
    Well the site was republished and upgraded with iWeb 08. Recently I noticed that the hit counter now shows regardless of how you go to the site. I was pleasantly surprised but when did this happen? Of course as others have noticed, on my .Mac home page on the side bar where the website pages are listed the counter numbers no longer show. So they took something away and gave something back?
    John

    I don't think Apple meant to take away the .Mac counter section of the .Mac page. I think it's a bug that they have yet to resolve. It would be interesting to see if anyone has asked Apple about this and if they gave a definitive answer?

  • AsyncOS 6.5.2 for Email now generally available

    We have put out a new maintenance release for Email Security and Security Management. The official announcement can be read here:
    http://preview.tinyurl.com/ql2dxu

    I've updated the title on the Security Alerts page, and included a link to the Secunia Advisory in the announcement. Here is a link to the new announcment
    http://preview.tinyurl.com/llrx8f
    Thanks for pointing this out.
    -karl
    There is an announcement in the Security section, but I see the title doesn't refer to the Secunia alert number, or mention Quarantine, which makes it hard to spot. I'll get that fixed.
    Here's a link to the announcement.
    http://preview.tinyurl.com/pmpbva
    btw it fixes (beside other problems) this XSS Spam Quarantine problem: http://secunia.com/advisories/34895/
    Strange thing that this Security Related Info is no yet listed within the Support Portal. At the moment it can only be found in the Release notes of 6.5.2 linked at the bottom right of the Support Portal.
    Is this as CISO / IronPort Communication Problem?
    :o[url]

  • RE: Skype for Web (Beta) is now available to every...

    Any update as to when Web.skype.com will work for Chromebooks?
    I receive page: https://web.skype.com/en/wrongDevice
    Sorry, Skype for Web (Beta) isn’t available on this device yet. Please try it on your desktop computer instead.

    Please try Skype for Web again on your Chromebook now. It should work (without calling obviously since there's not plugin available).
    Follow the latest Skype Community News
    ↓ Did my reply answer your question? Accept it as a solution to help others, Thanks. ↓

  • AsyncOS 6.3.5-015 for Web is GA

    Hello,
    Cisco is pleased to announce the General Availability (GA) of a maintenance release of AsyncOS 6.3.5-015 for Web to all customers. This release applies to all our Web Security Appliances (S-Series).
    We specifically encourage customers that are using a previous version of AsyncOS 6.3.4 for Web and customers on the S160 hardware platform to take advantage of the fixes outlined below by upgrading their Web Security Appliances to this latest release.
    Partial list of defects fixed in AsyncOS 6.3.5-015 for Web
    Fixed: Web Proxy does not properly tunnel CONNECT requests in some cases [Defect ID: 71947]
    Fixed: Accessing some web servers fails when an upstream proxy server is configured [Defect ID: 56386]
    Fixed: Web Proxy generates a core file connecting to some HTTPS servers [Defect ID: 69397]
    Fixed: Web Proxy generates a core file in some networks with an upstream proxy server [Defect ID: 72022]
    Fixed: Additional logging and robustness fixes have been added to provide stability on 1U platform [Defect ID:68955]
    For further information about this release, please refer to the attached AsyncOS Release Notes.
    Thank you for choosing Cisco IronPort Security Products.
    Best Regards,
    Eduardo

    .

  • AsynOS 5.7.1 for Web / 6.7.0 for Management are GA

    Hi,
    On 07/16 we release the combo of AsynOS 5.7.1 for Web / 6.7.0 for Management to all out customers. Those releases will allow you to centrally manage you WSAs using a Security Management Appliance (M-Series).
    * New Feature: Centralized WSA policy management
    * New Feature: Delegated Administration for WSA policies
    * New Feature: Role-based access control with new pre-built administrator roles
    * New Feature: LDAP – AD/Radius authentication
    * New Feature: Configuration History Logs for compliance/governance needs
    Partial list of defects fixed in 6.7.0-344
    *Fixed: LDAP Connections Greatly Exceed the Maximum Specified in the LDAP Server Profile [Defect ID: 45194]
    * Fixed: Exported IP Address Search Results for Incoming Mail Shows “Last Sender Group” Twice [Defect ID: 43218]
    * Fixed: Revert Does Not Reset Configuration Settings to the Default Values [Defect ID: 47153]
    AsyncOS 5.7.1-006 for Web contains the fixes that were included in 5.6.6-006 as well.
    For further information about these releases, please refer to the AsyncOS Release Notes or contact Cisco IronPort Customer Support if you have questions in regards to anything specific that is not listed there. The release notes are available on our Support Portal:
    https://supportportal.ironport.com
    Once again I'd like to remind everybody that there is no upgrade path between AsyncOs 5.7.1 for Web and AsyncOS 6.0.0 for Web.
    Please read the release notes and have a look at this KB article before making your upgrade decision:
    http://tinyurl.com/mpd4wc
    It has been an interesting week with three new releases each with a different focus. Make your choice and give it a spin :)
    Best,
    Jakob

    Do you guys ever sleep?

  • What is the best way to keep high res when saving "for web"

    the files i'm saving for web so i can get them in jpg (or gif) format are coming out very pixelated.  this is when i print the image. 
    what is the best way to save for web an image and keep the resolution good. 
    using for a business card template.  avery template will let me attach images i want to the project.  to do this..  i "get file from computer" and it drops the image in but real small... then you are supposed to enlarge it onto your work however you want.  well when i enlarge this image file, it gets pixelated badly.  i'm thinking it's the way i'm saving it.  i do not adjust anything when i save.  maybe i should.  this is where i need guidance. 
    this is what avery template notes about the images i am allowed to use - When uploading the image, the maximum size allowed is 4 MB.  You can only upload JPG and PNG images either as RGB or CMYK.  so when you recommend things, can you please keep this in mind
    thank you for oyur time.

    Aida,
    When you save with the default template using save for web it is generally a very low settings.
    While in the save window you can define the pixel size of the image you want with quality as well as resolution too.
    Refer to tv.adobe.com video save for web or Adobe help file for detailed instructions.
    Mandhir

  • AsyncOS 6.3.1-025 and 6.0.2-017 for Web are GA

    Dear Cisco IronPort Customer,
    IronPort, now part of Cisco, is pleased to announce the General Availability (GA) of the two maintenance releases of AsyncOS 6.3.1-025 for Web and 6.0.2-017 for Web to all customers. These releases applies to all our Web Security Appliances (S-Series).
    Enhancements and Fixes in AsyncOS 6.3.1-025 for Web
    Partial list of defects fixed in 6.3.1-025
    * Fixed: Web Security appliance spontaneously reboots due to a slow memory leak when clients used NTLMv1 authentication in some cases. [Defect ID: 52548]
    * Fixed: Webroot scanning engine stops working when downloading some .cab files. [Defect ID: 53793]
    * Fixed: Web Proxy generates a core file after a client sends a POST request to a server that returns a 503 “Service Unavailable” message in some cases. [Defect ID: 54019]
    * Fixed: Web interface erroneously shows 100% CPU utilization when rate is lower. [Defect ID: 54767]
    * Fixed: Web Proxy generates a core file and restarts in some cases. [Defect ID: 54890]
    * Fixed: Web Proxy generates a core file and restarts after processing some HTTPS requests in some cases. [Defect ID: 55407]
    Enhancements and Fixes in AsyncOS 6.0.2-017 for Web
    Partial list of defects fixed in 6.0.2-017
    * Enhancement: Added support for NTLM proxy authentication against Windows 2008 Server R2. [Defect ID: 49114]
    * Fixed: Web Security appliance spontaneously reboots due to a slow memory leak when clients used NTLMv1 authentication in some cases. [Defect ID: 52548]
    * Fixed: Webroot scanning engine stops working when downloading some .cab files. [Defect ID: 53793]
    * Fixed: WBNP engine erroneously runs at 100% due to a memory leak. [Defect ID: 54034]
    * Fixed: Web interface erroneously shows 100% CPU utilization when rate is lower. [Defect ID: 54767]
    * Fixed: Vulnerability in Secure Sockets Layer (SSL) certificates. [Defect ID: 55278]
    * Fixed: Web Proxy generates a core file and restarts after processing some HTTPS requests in some cases. [Defect ID: 55407]
    For further information about these releases, please refer to the AsyncOS Release Notes. The release notes are available on our Support Portal:
    https://supportportal.ironport.com
    If you are concerned about an issue not listed there, please contact your authorized support provider to make an inquiry.
    How to Upgrade
    Prior to upgrading, please read the Release Notes referenced above and save a copy of the configuration file somewhere other than on your appliance.
    Once you have read the Release Notes you may log into the command line of your IronPort Appliance as the 'admin' user, and type 'upgrade', or use the WebUI upgrade functionality in the "System Administration" tab.
    **NOTE** It is important that you follow the upgrade instructions available in the Release Notes. If you do attempt to upgrade and do not see the desired release version available, your appliance is likely not on a version allowed to upgrade directly. See 'Upgrade Paths', below.
    Upgrade Paths
    Please refer to the Release Notes for qualified upgrade paths.
    If your systems are on any other AsyncOS release, you will need to perform multiple upgrades as specified in the release notes. Only the immediate next step in the upgrade path will be shown to you, with the next revision being shown once you are at the approved level.
    Release Stage
    General Availability (GA): This release is available to all our customers and is a recommended build to be used in your production environments.
    Thank you for choosing Cisco IronPort Security Products.
    Best Regards,
    Jakob

    6.3.1-025 is GA and anybody can upgrade. Release notes can be found on the portal.
    Notifications are done in several stages so not every customer is notified on the first day of GA.
    I'll post a GA announcement here on the portal as well - sorry for the delay.
    Best,
    Jakob

  • Cisco AsyncOS 7.5.1-074 for Web FCS Release Notification

    Dear Cisco Web Security Customer,
    Cisco is pleased to announce a new maintenance release of AsyncOS 7.5.1-074 for Web to select customers (FCS). This release applies to all our Web Security Appliances (S-Series).
    Note: If you manage multiple Web Security Appliances using our Security Management Appliance (SMA) you need to upgrade the SMAs to AsyncOS 7.9.1-030 for Security Management (or higher).
    Partial list of defects fixed in AsyncOS 7.5.1-074 for Web
    Fixed: Rebooting an appliance without a proper shutdown sometimes caused irreparable damage to the appliance. This is fixed. [Defect ID: 73467]
    Fixed: Processing client requests sometimes took too long after updating new anti-malware rules. This is fixed. [Defect ID: 81055]
    Fixed: Overloading webroot made the WSA unusably slow. This is fixed. [Defect ID: 81661]
    Fixed: With Safe Search enabled, for URLs that included a question mark (?) in the first position after the domain name, for example, "example.com/?abc", transaction requests were resulting in an HTTP 404 error message. This is fixed. [Defect ID: 83666]
    Fixed: Download time for Web Tracking data in CSV format was excessive when specifying a custom time range for the report. This is fixed. [Defect ID: 85964]
    Fixed: After upgrading to 7.5, attempts to bring additional Web Security Appliances online were unsuccessful due to port-number mismatches between the Appliance and the WCCP router. AsyncOS now sorts port numbers from smallest to largest to prevent mismatches. This is fixed. [Defect ID: 86704]
    For further information about this release, please refer to the AsyncOS Release Notes attached to this annoucement.
    If you are concerned about an issue not listed there, please contact your authorized support provider to make an inquiry.
    How to Upgrade
    Prior to upgrading to this release, please read the Release Notes referenced above and save a copy of the configuration file somewhere other than on your appliance.
    Once you have read the Release Notes you may log into the command line of your IronPort Appliance as the 'admin' user, and type 'upgrade', or use the WebUI upgrade functionality in the 'System Administration' tab.
    You may upgrade directly to the highest version available in the displayed list.
    **NOTE** It is important that you follow the upgrade instructions available in the Release Notes. If you do attempt to upgrade and do not see the desired release version available, your appliance is likely not on a version allowed to upgrade directly. See 'Upgrade Paths' below.
    Upgrade Paths
    Please refer to the Release Notes for qualified upgrade paths.
    If your systems are on any other AsyncOS release, you will need to perform multiple upgrades as specified in the release notes. Only the immediate next step in the upgrade path will be shown to you, with the next revision being shown once you are at the approved level.
    Release Stage
    First Customer Ship (FCS): This release has been fully qualified for production usage by Cisco IronPort. It has been extensively tested for functionality and stability. Following a staged release process, we offer select customers the chance to benefit from new features and enhancements as early adopters.
    Thank you for choosing Cisco Security Products.
    Best Regards,
    Cisco Content Security Customer Support
    Support Portal: http://cisco.com/web/ironport
    Toll-Free Customer Support
    United States: 1-877-641-IRON (4766)
    International: http://www.cisco.com/web/ironport/contacts.html#~tab-3
    NOTICE: CISCO SYSTEMS CONFIDENTIAL AND PROPRIETARY This document contains information which is both confidential and proprietary to IronPort. Neither this document nor the information contained herein shall be copied, disclosed to others or used for any purposes beyond the specific purpose for which this document was delivered without the express written permission of IronPort. If you receive this message in error, please notify the sender and destroy the attached message (and all attached documents) immediately.
    © 2012 Cisco Systems, Inc. All rights reserved.

    Hello Sergio,
    To get to Ironport Dcoumentation, please do the following:
    1) go to www.cisco.com
    2) Login with CCO id and password
    3) Select support
    4) On resulting page, under Prduct Name, select Security
    5) You should see  "Email Security" and "Web Security" option there, which will bring you to the Documents.
    For WSA the doc guides are here http://www.cisco.com/en/US/customer/products/ps10164/products_user_guide_list.html
    For The ESA the doc guides are here http://www.cisco.com/en/US/customer/products/ps10154/products_user_guide_list.html
    Regards,
    Eric

  • AsyncOS 6.3.1-028 for Web is GA

    Hi,
    Cisco is pleased to announce a maintenance release of AsyncOS 6.3.1-028 for Web to all customers (GA).
    This release applies to all our Web Security Appliances (S-Series).
    This new build addresses two severe defects that have been found in the former 6.3.1-025 GA release.
    We encourage you to upgrade to this new build to benefit from the enhanced stability in 6.3.1-028.
    Enhancements and Fixes in AsyncOS 6.3.1-028 for Web
    Fixed: Some transparent HTTPS requests erroneously bypass all Routing Policies
    and go directly to the Internet. [Defect ID: 55596]
    Previously, when Routing Policy membership depended on data in a request header,
    such as the URL, then transparent HTTPS requests failed to match the Routing Policy.
    Instead, they were routed directly to the Internet. This no longer occurs.
    Now, those transparent HTTPS requests match the Default Routing Policy.
    Fixed: Web Proxy generates a core file and restarts in some cases. [Defect ID: 65975]
    Previously, the Web Proxy generated a core file and restarted when repeatedly connecting to
    servers that delivered 503 Bad Gateway responses to the Web Proxy. This no longer occurs.
    For further information about this release, please refer to the AsyncOS Release Notes on our Support Portal:
    http://www.ironport.com/support/
    While you are there, take the chance to have a look at the other new releases available currently:
    Sawmill 7.3.2 and AsyncOS 6.3.3 FCS.
    For an overview over the different release stages, have a look at this knowledge base article:
    http://tinyurl.com/yzm4ysu
    Best Regards,
    Jakob

    .

  • How do i fix my printer when it won't show the print preview for web pages? it worked and now not.

    how do i fix my printer when it won't show the print preview for web pages?  it worked for a while and now it doesn't.  printer is an hp officejet 7310 all-in-one.

    I would suspect this is a hardware issue.  The rollers are probably having issues picking up the relatively smooth thick media.  You might have better results be cleaning the paper pickup rollers with a damp paper towel.  Also make sure the paper is snugly loaded and the paper guides have been correctly positioned.
    Regards,
    Bob Headrick, MS MVP Printing/Imaging
    Bob Headrick,  HP Expert
    I am not an employee of HP, I am a volunteer posting here on my own time.
    If your problem is solved please click the "Accept as Solution" button ------------V
    If my answer was helpful please click the "Thumbs Up" to say "Thank You"--V

Maybe you are looking for

  • Table name stored in another table and how to Build the Dynamic Query

    TblMasterTable Id Unqid Tbl_TemplateNameid Tbl_Template1 Unqid Field1 Filed2 Tbl_Template2 Unqid Field1 Filed2 Filed3 Tbl_Template3 Unqid Field1 Filed2 Filed3 Filed4 Filed5 TblMasterTable contains the reference for the table names. TblMasterTable con

  • Handling events in BSP application using WML tag Extensions

    Hello Everyone  ,                         We are developing a BSP applications for Mobile handheld using WML tag library. I am looking for some code samples to know how we can handle evevents inside the BSP using the WML tag library. Can any one of 

  • Mac mini and Logitech gaming headset

    I have a 2008 Mac Mini running 10.6.4 and I want to use a Logitech headset for online gaming but I can not make the microphone work. The output works fine, but the input wont register at all. The mic uses two standard jacks, one for input and one for

  • Trouble with .dwg conversion

    When I try to convert a .dwg (CAD) file to a PDF file, I only see a small corner of my original file. The .dwg file is my layout page with multiple drawings on one sheet. Any help?

  • Possible CS3 Compatibilty problems

    We've been happily running CS3 on Mac OS 10.5.8 for years now but need to upgrade the OS in order to upload e-books to iTunes. Will we have any compatibilty problems with CS3 in later OS versions?