Websense issues?

Hey there. I'm having a problem with websense. The websense is already installed and used by a PIX to limit web browsing for the internal wired users.
I have now installed a wireless LAN which terminates on a seperate box - an ASA. The ASA is connected to both the PIX and websense on the inside LAN. I have copied the config from the PIX for the websense filtering (this works fine), but changed the source IP address to the wireless LAN range.
I have attached the config and relevant show commands below. It doesn't look like the ASA is actually sending the request to websense? The wireless users have unrestricted web access which I don't want to happen. Any ideas anyone?
ASA# sh running-config | inc url
url-server (inside) vendor websense host 10.135.6.248 timeout 10 pro
rsion 1 connections 5
filter url http 10.213.133.0 255.255.255.128 0.0.0.0 0.0.0.0 allow
filter url 443 10.213.133.0 255.255.255.128 0.0.0.0 0.0.0.0 allow
ASA# sh runn int g0/3.11
interface GigabitEthernet0/3.11
vlan 11
nameif wlan-guest
security-level 10
ip address 10.213.133.1 255.255.255.128
ASA# sh nameif
Interface Name Security
GigabitEthernet0/0 outside 0
GigabitEthernet0/1 inside 100
GigabitEthernet0/2 internet 50
GigabitEthernet0/3.10 wlan-management 60
GigabitEthernet0/3.11 wlan-guest 10
Management0/0 websense 40
ASA# sh runn int g0/1
interface GigabitEthernet0/1
description == Connection To LAN ==
nameif inside
security-level 100
ip address 10.135.6.202 255.255.255.128
ASA#
ASA# sh url-server statistics
Global Statistics:
URLs total/allowed/denied 0/0/0
URLs allowed by cache/server 0/0
URLs denied by cache/server 0/0
HTTPSs total/allowed/denied 0/0/0
HTTPSs allowed by cache/server 0/0
HTTPSs denied by cache/server 0/0
FTPs total/allowed/denied 0/0/0
FTPs allowed by cache/server 0/0
FTPs denied by cache/server 0/0
Requests dropped 0
Server timeouts/retries 0/0
Processed rate average 60s/300s 0/0 requests/second
Denied rate average 60s/300s 0/0 requests/second
Dropped rate average 60s/300s 0/0 requests/second
Server Statistics:
10.135.6.248 UP
Vendor websense
Port 15868
Requests total/allowed/denied 0/0/0
Server timeouts/retries 0/0
Responses received 0
Response time average 60s/300s 0/0
URL Packets Sent and Received Stats:
Message Sent Received
STATUS_REQUEST 20 20
LOOKUP_REQUEST 0 0
LOG_REQUEST 0 NA
Errors:
RFC noncompliant GET method 0
URL buffer update failure 0
ASA#
Many thanks
Darren

Hi Playne,
I recently solve an issue like yours putting the command 'management-access inside' in the configure mode.
the teory is that the ASA needs to know the websense from the inside interface with the command that propose Jennifer,
i hope this resolve your problem,
regards,
derly_ali

Similar Messages

  • Adobe Creative Cloud connectivity issue on Websense run network; Failed to send the request to server to get the response - 12002

    Hi all,
    I am able to install the Windows Adobe Creative Cloud application fine on Windows 7 box but the application fails to establish a connection with Adobe server/-s.
    We use a proxy with Websense as our network security solution. Proxy configuration script is set in Internet Options. We have not tried to whitelist anything as per http://helpx.adobe.com/creative-cloud/kb/proxy-authentication-support-creative-cloud.html as the errors suggest the application does not even connect to the proxy server/Websense at all.
    Please see below snippet from that DLM.log file that contains the error messages - please have a look. Could anybody tell me what it means or advise how to resolve this please? I don't see the Adobe Creative Cloud tool to have any options where manual proxy settings can be setup to try that.
    <snip>
    11/05/14 08:50:48:184 | [INFO] | |  |  |  |  |  | 5236 | **File download complete.**
    11/05/14 08:50:52:145 | [INFO] | |  |  |  |  |  | 3732 | **File download complete.**
    11/05/14 08:51:05:327 | [INFO] | |  |  |  |  |  | 1784 | **File download complete.**
    11/05/14 08:51:06:968 | [ERROR] |  | |  |  |  |  | 3452 | The windows error code is - 12002
    11/05/14 08:51:06:968 | [ERROR] |  | |  |  |  |  | 3452 | Failed to send the request to server to get the response - 12002
    11/05/14 08:51:06:968 | [ERROR] |  | |  |  |  |  | 3452 | the download job (0) failed to execute. The job state is STOPPED_STATE
    11/05/14 08:51:06:992 | [INFO] | |  |  |  |  |  | 6844 | some intermittent error. Retrying now. Error code is 12002 and error type is -45
    11/05/14 08:51:11:514 | [INFO] | |  |  |  |  |  | 6844 | incrementing the thread. now the active thread count is 2
    11/05/14 08:51:12:519 | [INFO] | |  |  |  |  |  | 6648 | **File download complete.**
    11/05/14 08:51:16:541 | [INFO] | |  |  |  |  |  | 6844 | decrementing the thread count. now the active thread count is 1
    11/05/14 08:51:22:281 | [INFO] |  | |  |  |  |  | 3452 | resetting intermitent error 9 from to 1 to 0
    11/05/14 08:51:29:022 | [INFO] | |  |  |  |  |  | 1836 | **File download complete.**
    11/05/14 08:52:22:381 | [INFO] | |  |  |  |  |  | 7220 | incrementing the thread. now the active thread count is 2
    11/05/14 08:52:26:971 | [ERROR] |  | |  |  |  |  | 6756 | The windows error code is - 12002
    11/05/14 08:52:26:971 | [ERROR] |  | |  |  |  |  | 6756 | Failed to send the request to server to get the response - 12002
    11/05/14 08:52:26:971 | [ERROR] |  | |  |  |  |  | 6756 | the download job (5) failed to execute. The job state is STOPPED_STATE
    11/05/14 08:52:27:383 | [INFO] | |  |  |  |  |  | 7220 | some intermittent error. Retrying now. Error code is 12002 and error type is -45
    11/05/14 08:52:27:663 | [INFO] |  | |  |  |  |  | 4908 | resetting intermitent error 9 from to 1 to 0
    11/05/14 08:52:28:733 | [INFO] | |  |  |  |  |  | 6064 | **File download complete.**
    11/05/14 08:52:42:810 | [INFO] | |  |  |  |  |  | 7220 | **File download complete.**
    11/05/14 08:52:45:570 | [INFO] | |  |  |  |  |  | 3788 | **File download complete.**
    </snip>
    There is also an INFO class message that talks about resetting an ‘error 9’ from 1 to 0.

    Hi all,
    I am able to install the Windows Adobe Creative Cloud application fine on Windows 7 box but the application fails to establish a connection with Adobe server/-s.
    We use a proxy with Websense as our network security solution. Proxy configuration script is set in Internet Options. We have not tried to whitelist anything as per http://helpx.adobe.com/creative-cloud/kb/proxy-authentication-support-creative-cloud.html as the errors suggest the application does not even connect to the proxy server/Websense at all.
    Please see below snippet from that DLM.log file that contains the error messages - please have a look. Could anybody tell me what it means or advise how to resolve this please? I don't see the Adobe Creative Cloud tool to have any options where manual proxy settings can be setup to try that.
    <snip>
    11/05/14 08:50:48:184 | [INFO] | |  |  |  |  |  | 5236 | **File download complete.**
    11/05/14 08:50:52:145 | [INFO] | |  |  |  |  |  | 3732 | **File download complete.**
    11/05/14 08:51:05:327 | [INFO] | |  |  |  |  |  | 1784 | **File download complete.**
    11/05/14 08:51:06:968 | [ERROR] |  | |  |  |  |  | 3452 | The windows error code is - 12002
    11/05/14 08:51:06:968 | [ERROR] |  | |  |  |  |  | 3452 | Failed to send the request to server to get the response - 12002
    11/05/14 08:51:06:968 | [ERROR] |  | |  |  |  |  | 3452 | the download job (0) failed to execute. The job state is STOPPED_STATE
    11/05/14 08:51:06:992 | [INFO] | |  |  |  |  |  | 6844 | some intermittent error. Retrying now. Error code is 12002 and error type is -45
    11/05/14 08:51:11:514 | [INFO] | |  |  |  |  |  | 6844 | incrementing the thread. now the active thread count is 2
    11/05/14 08:51:12:519 | [INFO] | |  |  |  |  |  | 6648 | **File download complete.**
    11/05/14 08:51:16:541 | [INFO] | |  |  |  |  |  | 6844 | decrementing the thread count. now the active thread count is 1
    11/05/14 08:51:22:281 | [INFO] |  | |  |  |  |  | 3452 | resetting intermitent error 9 from to 1 to 0
    11/05/14 08:51:29:022 | [INFO] | |  |  |  |  |  | 1836 | **File download complete.**
    11/05/14 08:52:22:381 | [INFO] | |  |  |  |  |  | 7220 | incrementing the thread. now the active thread count is 2
    11/05/14 08:52:26:971 | [ERROR] |  | |  |  |  |  | 6756 | The windows error code is - 12002
    11/05/14 08:52:26:971 | [ERROR] |  | |  |  |  |  | 6756 | Failed to send the request to server to get the response - 12002
    11/05/14 08:52:26:971 | [ERROR] |  | |  |  |  |  | 6756 | the download job (5) failed to execute. The job state is STOPPED_STATE
    11/05/14 08:52:27:383 | [INFO] | |  |  |  |  |  | 7220 | some intermittent error. Retrying now. Error code is 12002 and error type is -45
    11/05/14 08:52:27:663 | [INFO] |  | |  |  |  |  | 4908 | resetting intermitent error 9 from to 1 to 0
    11/05/14 08:52:28:733 | [INFO] | |  |  |  |  |  | 6064 | **File download complete.**
    11/05/14 08:52:42:810 | [INFO] | |  |  |  |  |  | 7220 | **File download complete.**
    11/05/14 08:52:45:570 | [INFO] | |  |  |  |  |  | 3788 | **File download complete.**
    </snip>
    There is also an INFO class message that talks about resetting an ‘error 9’ from 1 to 0.

  • Websense web filtering not working with 2911 with zone based firewall

    Hi,
    Any one ran into this issue
    We use websense for guest wifi but i dont see requests hitting websense server
    config is below
    class-map type inspect match-any test-1
     match protocol http
    policy-map type inspect Wifi-test
     class type inspect  test-1
      inspect
    urlfilter websense-parmap
     class class-default
      drop
    parameter-map type urlfilter websense-parmap
     server vendor websense 10.10.1.4
     source-interface GigabitEthernet0/2
     allow-mode on
     cache 100
    zone-pair security Wifi-in-out source Wifi destination outside
    service-policy type inspect Wifi-test
    interface GigabitEthernet0/1
     description Internet
     ip address 192.168.10.1 255.255.255.0
     ip nbar protocol-discovery
     ip nat inside
     ip virtual-reassembly in
     zone-member security Wifi
    interface GigabitEthernet0/2
     description LAN
     ip address 10.10.4.1 255.255.255.0
    zone-member security inside

    Hi Stan,
    You should be able to adapt this config example to your environment.
    Andy-
    class-map type inspect match-any http-cm
     match protocol http
    parameter-map type urlfpolicy websense websense-parm
     server <websense server IP>
     source-interface <lan interface>
     allow-mode on
     truncate hostname
    class-map type urlfilter websense match-any websense-cm
     match server-response any
    policy-map type inspect urlfilter websense-pm
     parameter type urlfpolicy websense websense-parm
     class type urlfilter websense websense-cm
      server-specified-action
    policy-map type inspect Inside->Internet-pm
     description Inside trusted to Internet
     class type inspect http-cm
      inspect
      service-policy urlfilter websense-pm
     class type inspect Inside->Internet-cm
      inspect
     class class-default
      drop
    zone-pair security Inside->Internet source Inside destination Internet
     service-policy type inspect Inside->Internet-pm
    ! to check status & url block counts
    show policy-map type inspect zone-pair Inside->Internet urlfilter

  • Disable Websense scanning for specific src networks

    Hi all,
    I have an installation of Forefront TMG 2010 with Websense Web Filter Plug-In. The task I am supposed to do is to disable redirecting requests to Websense for specific source networks. It is impossible to do it from Websense Server, due to license limitations.
    I know there's a way to ignore some source users from isa_ignore.txt but I should filter this basing on source IP addresses. Please help me solving this issue.
    Kind Regards,

    Hi,
    You could try to create a network for these IP addresses and create a account for this network. Then add this account into isa_ignore.txt.( I haven't tested it)
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Wccp redirection for waas on same platform as wccp for websense?

    just wondering if anyone knows if a Cisco router or switch can handle wccp redirection enabled for both waas and some other web content filtering appliance using a different service group?
    seems like the priority value would come into play determining which service group gets handled first?
    we currently do WCCP for WaaS on our 3945s.
    I am going to advocate to my customer that we separate this out for CPU load issues, config complexity issues, IOS issues, etc... but the question is going to come up - "can we do WCCP for different applications on our Catalyst 3750 core switch, or our 3945 WAN routers?"
    Thanks,
    Paul

    Hi Paul,
    Yes, it's technically possible to have WCCP redirection for several services even in those devices that don't support setting the priority. However, in this case, both WAAS and Websense need to redirect HTTP traffic, and that's what makes things complicated.
    Assuming you first want to send the traffic to Websense and then to WAAS, I would recommend doing the WAAS redirection only on the WAN link (with one service inbound and the other outbound). You can then configure Web-cache redirection inbound on the client vlan and, a service for the return traffic (I'm not sure if this is required for websense), inbound on the interface where the WAE is connected (with a redirect-list to match only the return direction)
    Even if it's possible to have both redirections in the same device, if possible, I would strongly suggest you to either use different devices for the redirection or to make them mutually exclusive (for example, not sending HTTP to WAAS), otherwise, if you make a small mistake with the configuration, you can end up with a redirection loop.
    Regards
    Daniel

  • Increased time_wait on Websense systems after LB HTTP with ACE

    I was wondering if anyone knew why we would see an increase of tcp sessions in time_wait status after setting up HTTP load balancing. The systems are Websense boxes that are being used both as a proxy (which the VIP is for) and with WCCP. We have 5 total systems but only 3 have been added to the serverfarm. The two that are are not in the serverfarm and not having this issue. The we are using L4 LB. So the two, non LB systems are on the client side VLAN. Any ideas?

    Hi,
    According to the article below:
    Windows 8.1 Update for x64-based Systems (KB2919355)
    http://www.microsoft.com/en-us/download/details.aspx?id=42335&e6b34bbe-475b-1abd-2c51-b5034bcdd6d2=True
    1. These KB's must be installed in the following order: clearcompressionflag.exe, KB2919355, KB2932046, KB2959977, KB2937592, KB2938439, and KB2934018.
    2. KB2919442 is a prerequisite for Windows 8.1 Update and should be installed before attempting to install KB2919355
    Did all the client fulfil the requirement?
    And if reboot is required in the KB article, we’d better reboot it and install the next.
    Hope this helps.

  • Need Help on Configuring the Site to Site VPN from Cisco 2811 to Websense Cloud for web Traffic redirect

    Hi All,
    I need help on Configuring the Site to Site VPN from Cisco 2811 to Websense Cloud for web Traffic redirect
    2811 having C2800NM-ADVIPSERVICESK9-M
    2811 router connects to the Internet SW then connects to the Internet router.
    Note- For Authentication am using the Device ID & Pre share key. I am worried as all user traffic goes with PAT and not firing up my tunnel for port 80 traffic. Can you please suggest what can be the issue ?
    Below is router config for VPN & NAT
    crypto keyring ISR_Keyring
      pre-shared-key hostname vpn.websense.net key 2c22524d554556442d222d565f545246
    crypto isakmp policy 1
    encr 3des
    authentication pre-share
    group 2
    crypto isakmp keepalive 10
    crypto isakmp profile isa-profile
       keyring ISR_Keyring
       self-identity user-fqdn [email protected]
       match identity user vpn-proxy.websense.net
    crypto ipsec transform-set ESP-NULL-SHA esp-null esp-sha-hmac
    crypto map GUEST_WEB_FILTER 10 ipsec-isakmp
    set peer vpn.websense.net dynamic
    set transform-set ESP-NULL-SHA
    set isakmp-profile isa-profile
    match address 101
    interface FastEthernet0/1
    description connected to Internet
    ip address 216.222.208.101 255.255.255.128
    ip access-group HVAC_Public in
    ip nat outside
    ip virtual-reassembly
    duplex full
    speed 100
    no cdp enable
    crypto map GUEST_WEB_FILTER
    access-list 101 permit tcp 192.168.8.0 0.0.3.255 any eq www
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 host 85.115.41.187 log
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 host 85.115.41.181 log
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 host 85.115.41.182 log
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 86.111.216.0 0.0.1.255
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 116.50.56.0 0.0.7.255
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 86.111.220.0 0.0.3.255
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 103.1.196.0 0.0.3.255
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 177.39.96.0 0.0.3.255
    access-list 103 deny   ip 192.168.8.0 0.0.3.255 196.216.238.0 0.0.1.255
    access-list 103 permit ip 192.168.8.0 0.0.3.255 any
    ip nat pool mypool 216.222.208.101 216.222.208.101 netmask 255.255.255.128
    ip nat inside source list 103 interface FastEthernet0/1 overload
    ip nat inside source route-map nonat pool mypool overload

    How does Websense expect your source IPs in the tunnel? 192.168.8.0 0.0.3.255 or PAT'ed 216.222.208.101 ?
    Check
    show crypto isakmp sa
    show crypto ipsec sa
    show crypto session
    You'd better remove the preshared key from your post.

  • Office 365 ProPlus Shared Computer Activation - users are prompted to activate, proxy issue?

    Hi all,
    We're currently testing the roll-out of Office 365 ProPlus with shared computer activation but are having problems with Office automatically activating (with no user prompts) when using our web proxy.
    I've already added proxy exceptions (in our PAC file) for the 'Office 365 portal and identity' and 'Office 365 ProPlus' URLs (not Content Delivery Network) from
    https://technet.microsoft.com/en-us/library/hh373144.aspx but test licensed Office 365 E4 users still get the 'Activate Office' prompt and even if they enter in their credentials are ultimately
    told 'There is a problem with your account. Please try again later'.
    Testing this on a computer not directed through the web proxy works fine and users get no pop-ups whatsoever and Office is licensed.
    The problem is I can check the traffic passing through the proxy in real-time and no traffic destined for any of the URLs on the TechNet page actually goes out over the proxy, indeed there is no Microsoft orientated traffic at all. It's as if simply
    specifying a proxy on IE's connection settings breaks shared computer activation.
    I'm in the process of a support case with our web proxy company itself but if there's anyone out there who can shed any light on this it'd be appreciated.
    Thanks in advance.

    Read this:
    https://technet.microsoft.com/en-us/library/gg702620.aspx
    Next read this:
    http://blogs.technet.com/b/neiljohn/archive/2012/01/26/office-365-proxy-server-exclusion-list-office-365-service-url-s.aspx
    Last: My workaround that's about 6 months old:I
    went through the same issue with Websense Cloud Web Security Gateway in my RDSH environment.
    Off and on, and seemingly without provocation, users would be prompted for credentials and these credentials would sometimes be accepted and other times they could just cancel out and continue working.
    I chalked this up to Microsoft's continual tuning and scaling of their cloud environment (we use Office 365).  I suspect Websense was not able to add hosts fast enough and the authentication issue just popped up from time to time.
    My solution? A workaround...set the list of recommended MS servers on "bypass" so that any traffic destined to these servers Websense would essentially permit without interference.
    Best of luck to you.

  • Leased Line issues

    My organisation leased line is down. Our exchange servers are mainteined locally. We have public ip. Since our leased line is down, we are handicapped of retrieving mails.
     i would like to know the options of retrieving mails atleast outside organisation network. I am as well looking for data centre or disaster management solution which can take care of such situations in future.
    thanks in advance.

    Hi Gitala,
    There are primarily two options:
    1. Emails gets queued in an external server (cloud based or other Data Centre), while your organization network\server is getting fixed. Once up it delivers all the emails to your Exchange server.
    While the network\server is down users don't have access to emails in transit (In or Out the org)
    Cloud based Services like Microsoft Exchange Online protection, Websense Email Security, MessageLabs (Symantec). Or a simple server in alternate location running SMTP service would also queue.
    2. Have cross-site resilient infrastructure in place. Email services continue without issues.
    In your case, you have complete cut off from the internet to the site hosting the email services, hence to have a DR solution, rather High Availability I would say, you need to have:
    a. Multiple Internet networks (Network based redundancy) in same site.
    b. SiteB with internet connection with lower preference\cost (so that it’s not used in normal conditions),
    c. Have a Private Link between both the sites, have DAG members in SiteB with passive copies of critical user DBs.
    So in short you can't achieve this without redundancy at each level.

  • NAC guest server and guest proxy filtering issue.

    Hi all
    Continuing our issues log for the NAC guest server install, our toplogy and issue is as follows:
    We have a guest NAC server and a 4404 anchor controller successfully deployed in the DMZ, the anchor WLC has a mobilty anchor which is a WISM on the corporate network, DHCP services for guest clients are issued with no problems from the WLC in the DMZ. The first port of the DMZ controller is located on the DMZ and the second port directly connects to the firewall interface.
    All works correctly, DNS, DHCP, NTP, SNMP etc all work fine through the firewall.
    What options do I have to filter Internet access in this scenario, we have Websense and Nokia firewalls, don't think I can use WCCP as I have nowhere to place it, the second connection on the WLC is directly connected to the firewal so nowhere to intercept the traffic, our security team has tried some tricks on the Nokia to try to redirect the traffic on the firewall using a type of redirect, WPAD, I can't see as an option. Any ideas. If I place the second interface into the DMZ, could I use WCCP that way maybe, but won't traffic still have to go to the firewall??
    options please ??

    Well you will need to use a 3rd party certificate..  Here is a link to generate and install a 3rd party certificate on the WLC for the use with Web-Auth:
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00806e367a.shtml
    Here is a link for the NGS:
    http://tools.cisco.com/search/display?url=http%3A%2F%2Fwww.cisco.com%2Fen%2FUS%2Fdocs%2Fsecurity%2Fnac%2Fappliance%2Fconfiguration_guide%2F410%2Fcas%2Fcas41ug.pdf&pos=1&strqueryid=2&websessionid=RK88fQNWy8TCDUakpNGLOqZ
    The applicances are using a self generated Cisco certificate which of course is not a trusted certificate store in most of all operating systems.  So using a 3rd party certificate like RapidSSL, Verisign, etc will eliminate the certificate issue.

  • Sun Java Web Proxy Server 4.0.12 is supports Websense Web Security

    Hello All,
    I am using Sun Java Web Proxy 4.0.12 server and installed in RedHat Linux 5.0 OS and I can found software for Websense Web Security aoftware to protect my users and filter the traffic.
    How can I integrate with Websense Web Security
    Thanks & looking forward hear from you guys
    Ifthekhar Javed
    Riyadh.

    We have migrated several reverse and acl proxy from 3.6 to 4.0.6 and have hit a few issues. If anyone has encountered these we would appriate input.
    First, we thought we had caching disabled in the GUI but the server.xml still have it set to "true" in the FILECAHE entry. Will changing the entry to "false" totally disable chaching?
    When we started the migrated proxy instances the server hit memory issues with swap being eaten up very quickly.
    Second issue is MaxProcs in the magnus.conf. In 3.6 MaxProcs set the number of processes to start and it now for determening the number of processors in the server for threading. We are currently on a server with 6 processors. Should MaxProcs be set to six?
    We will be migrating to Solaris 10 and then to a T2000 so we assume the setting will have to change for each of those migigrations.
    The third issue is, has anyone run 3.6 on Solaris 10 and then migrated to 4.0 later? Sun site shows 3.6 not tested on Solaris 10 but I am sure some one has tried it.

  • Skype for Desktop through Websense Triton Cloud Security

    We have just implemented the Websense Triton-APX Cloud Web Security and Skype does not connect through. I have allowed Skype in the category lists however it does not connect still. Can you shed any light on how we can get Skype to connect through the proxy server? Thanks

    I would appreciate that Any skype modorators or Administrators please contact me for copyright issues  when it comes to imaging usage on a post: I was not contacted for any violation in the TOS Policy what so ever; therefor there was no reason for my image to be removed.

  • CE560/WCCP/Websense dies - lot of RST's seen

    We have a CE560 which we use for caching and websense integration for almost 2 years w/ no problems. Recently, Internet browsing complaints from customers have ramped up. Have an open case w/ TAC & thought might be hitting 100% every 30 min bug but some info we sent development now shows the cache engine is getting a huge # of RST's which looks like it may be causing the issue.
    We're wondering if our Checkpoint NG FP3 firewall may be sending the RST's & if anyone has had a similar issue w/ a similar config. Need advise on a place to start looking on the checkpoint (or really any other firewall) w/ regard to the possible RST's issue. Don't expect much help from the FW guys unfortunately.
    Our config is 6000 wan & lan users funnel to 2 6513's doing wccp v2 to single CE560 which sits behind a Checkpoint/Nokia FW cluster. ACNS 5.1x w/ websens onbox. Same problem when websense was on Win2k server.
    I understand the CE560 to be rated to about 25mb throughput & we're currently running our Internet DS-3 at a max of about 12mb so I would hope load isn't the main culprit here. We turn wccp back on, browsing fast & blocking works. Within minutes it stalls.
    TIA for any insight. Our users are having WAY too much fun while CE/Websense is down <G>

    I've seen that the PIX sometimes denies the last packet in a TCP connection and sends a TCP RST. This happens intermittently, but may be related to amount of data transferred during the connection (it seems to occur when there is little data transferred). However am not sure if it holds good for the Check point firewall too.

  • New DVR Issues (First Run, Channel Switching, etc.)

    I've spent the last 30 minutes trying to find answers through the search with no luck, so sorry if I missed something.
    I recently switched to FIOS from RCN cable in New York.  I've gone through trying to setup my DVR and am running into issues and was hoping for some answers.
    1.  I setup two programs to record at 8PM, I was watching another channel at the time and only half paying attention.  Around 8:02 I noticed a message had popped up asking if I would like to switch channels to start recording.  I was expecting it to force it to switch like my old DVR, but in this case it didn't switch and I missed the first two minutes of one of the shows.  I typically leave my DVR on all day and just turn off the TV, this dual show handling will cause issues with that if I forget to turn off the DVR.  Is there a setting I can change that will force the DVR to choose one of the recording channels?
    2.  I setup all my recordings for "First Run" because I only want to see the new episodes.  One show I setup was The Daily Show on comedy central, which is shown weeknights at 11pm and repeated 3-4 times throughout the day.  My scheduled recordings is showing all these as planned recordings even though only the 11pm show is really "new".  Most of the shows I've setup are once a week so they aren't a problem, but this seems like it will quickly fill my DVR.  Any fixes?
    Thanks for the help.
    Solved!
    Go to Solution.

    I came from RCN about a year ago.  Fios is different in several ways, not all of them desirable.  Here are several ways to get--and fix--unwanted recordings from a series recording setup.
    Some general principles. 
    Saving changes.  When you originally create a series with options, or if you go back to edit the options for an existing series, You MUST save the Series Options changes.  Pretty much everywhere else in the user interface, when you change an option, the change takes effect immediately--but not in Series Options.  Look at the Series Options window.  Look at the far right side.  There is a vertical "Save" bar, which you must navigate to and click OK on to actually save your changes.  Exiting the Series Options window without having first saved your changes loses all your attempted changes--immediately.
    Default Series Options.  This is accessed  from [Menu]--DVR--Settings--Default Series Options.  This will bring up the series options that will automatically be applied to the creation of a NEW series. The options for every previously created series will not be affected by a subsequent modification of the Default Series Options.  You should set these options to the way you would like them to be for the majority of series recordings that you are likely to create.  Be sure to SAVE your changes.  This is what you will get when you select "Create Series Recording" from the Guide.  When creating a new series recording where you think that you may want options different from the default, select "Create Series with Options" instead.  Series Options can always be changed for any individual series set up later--but not for all series at once.
    Non-series recordings.  With Fios you have no directly available options for these.  With RCN and most other DVRs, you can change the start and end times for individual episodes, including individual episodes that are also in a series.  With Fios, your workarounds are to create a series with options for a single program, then delete the series later;  change the series options if the program is already in a series, then undo the changes you made to the series options later; or schedule recordings of the preceding and/or following shows as needed.
    And now, to the unwanted repeats. 
    First, make sure your series options for the specific series in question--and not just the series default options--include "First Run Only".  If not, fix that and SAVE.  Then check you results by viewing the current options using the Series Manager app under the DVR menu.
    Second, and most annoying, the Guide can have repeat programs on your channel tagged as "New".  It happens.  Set the series option "Air Time" to "Selected Time".  To make this work correctly, you must have set up the original series recording after selecting the program in the Guide at the exact time of a first run showing (11pm, in your case), and not on a repeat entry in the Guide.  Then, even it The Daily Show is tagged as New for repeat showings, these will be ignored. 
    Third, another channel may air reruns of the program in your series recording, and the first showing of a rerun episode on the other channel may be tagged as "New".  These can be ignored in your series if you set the series option "Channel" to "Selected Channel".  Related to this, if there is both an SD and HD channel broadcasting you series program, you will record them both if the series option "Duplicates" is set to "Yes".  However, when the Channel option is set to "Selected Channel", the Duplicates Option is always effectively "No", regardless of what shows up on the options screen.  
    As for you missing two minutes,  I have sereral instances in which two programs start recording at the same time.  To the best of my recollection, whenever the warning message has appeared, ignoring it has not caused a loss of recording time.  You might have an older software version.  Newest is v.1.8.  Look at Menu--Settings--System Info.  Or, I might not have noticed the loss of minutes.  I regularly see up to a minute of previous programming at the start of a recording, or a few missing seconds at the beginning or end of a recording.  There are a lot of possibilities for that, but the DVR clock being incorrect is not one of them.  With RCN, the DVR clocks occasionally drifted off by as much as a minute and a half.

  • Pension issue Mid Month Leaving

    Dear All,
    As per rule sustem should deduct mid month joining/leaving/absences or transfer scenarios, the Pension/PF Basis will be correspondingly prorated. But our system is not doing this. In RT table i have found 3FC Pension Basis for Er c 01/2010                    0.00           6,500.00.
    Employee leaving date is 14.04.2010. system is picking pension amout as 541. Last year it was coming right.
    Please suggest.
    Ashwani

    Dear Jayanti,
    We required prorata basis pension in case of left employees and system is not doing this. This is the issue. As per our PF experts Pension amount should come on prorata basis for left employees in case they left mid of month.System is doing prorata basis last year but from this year it is deducting 541. I am giving two RT cases of different years.
    RT table for year 2010. DOL 26.04.2010
    /111 EPF Basis              01/2010                    0.00           8,750.00 
    /139 VPF Basis              01/2010                    0.00           8,750.00 
    /3F1 Ee PF contribution     01/2010                    0.00           1,050.00 
    /3F3 Er PF contribution     01/2010                    0.00             509.00 
    /3F5 Ee Mon PF contribution 01/2010                    0.00           1,050.00 
    /3F6 Ee Ann PF contribution 01/2010                    0.00          12,600.00 
    /3F9 PF adm chrgs * 1,00,00 01/2010                    0.00              96.25 
    /3FA PF basis for Ee contri 01/2010                    0.00           8,750.00 
    /3FB PF Basis for Er Contri 01/2010                    0.00           8,750.00 
    /3FJ VPF basis for Ee contr 01/2010                    0.00           8,750.00 
    /3FL PF Basis for Er Contri 01/2010                    0.00           6,500.00 
    /3F4 Er Pension contributio 01/2010                    0.00             541.00
    /3FC Pension Basis for Er c 01/2010                    0.00           6,500.00
    /3FB PF Basis for Er Contri 01/2010                    0.00           8,750.00
    /3FC Pension Basis for Er c 01/2010                    0.00           6,500.00
    /3FJ VPF basis for Ee contr 01/2010                    0.00           8,750.00
    /3FL PF Basis for Er Contri 01/2010                    0.00           6,500.00
    /3R3 Metro HRA Basis Amount 01/2010                    0.00           8,750.00
    1BAS Basic Salary           01/2010                    0.00           8,750.00
    RT table for year 2009. DOL 27.10.2009
                                                                                    /111 EPF Basis              07/2009                    0.00           9,016.13
    /139 VPF Basis              07/2009                    0.00           9,016.13
    /3F1 Ee PF contribution     07/2009                    0.00           1,082.00
    /3F3 Er PF contribution     07/2009                    0.00             628.00
    /3F5 Ee Mon PF contribution 07/2009                    0.00           1,082.00
    /3F6 Ee Ann PF contribution 07/2009                    0.00           8,822.00
    /3F9 PF adm chrgs * 1,00,00 07/2009                    0.00              99.18
    /3FA PF basis for Ee contri 07/2009                    0.00           9,016.00
    /3FB PF Basis for Er Contri 07/2009                    0.00           9,016.00
    /3FJ VPF basis for Ee contr 07/2009                    0.00           9,016.00
    /3FL PF Basis for Er Contri 07/2009                    0.00           5,452.00
    /3FB PF Basis for Er Contri 07/2009                    0.00           9,016.00 
    /3FC Pension Basis for Er c 07/2009                    0.00           5,452.00 
    /3FJ VPF basis for Ee contr 07/2009                    0.00           9,016.00 
    /3FL PF Basis for Er Contri 07/2009                    0.00           5,452.00 
    /3R4 Non-metro HRA Basis Am 07/2009                    0.00           9,016.13 
    1BAS Basic Salary           07/2009                    0.00           9,016.13 
    Now please suggest what to do. where is the problem  ? If have also checked EXIT_HINCALC0_002 but nothing written in it.
    With Regards
    Ashwani

Maybe you are looking for

  • I have a Galaxy SIII and I stopped receiving visual notification for text messages.  How do I correct it?

    I have a Galaxy SIII and recently stopped receiving visual notification for text messages.  How do I correct it?

  • Production schedule report/Standard v/s actual report

    Dear experts, Need two standard report for 1) Production schedule report- production during the perion and their cost component and items break up 2) Standard v/s actual report - Standard defined for material  and actually consumed in term of qty and

  • Erreur serveur facetime macbook

    Bonjour à tous, Je suis nouvelle sur Moutain Lion (c'est vraiment trop bien !!!!!) C'est sur, j'étais sur Léopard hier et voilà que je saute 3 OS. Je découvre petit à petit toutes les nouveautés. J'ai reussi à paramètrer facebook, mais pas twitter, t

  • Unable to sync to itunes

    i keep trying to sync to itunes with my 3gs, just updated to ios4, and it said The iphone can not be synced, the required file can not be found.!!!!!!!!!! help

  • Understanding  a Loss of audio output

    I have switched on my G5 after it being switched off for a week. I have no audio from my firewire attached speakers or from the G5 speaker or via the iTunes/Airport express hifi connection. There is however sound when headphones are plugged in. I hav