Guest

Preview Tool

Cisco Bug: CSCvi08772 - WSA - After assigning the ID profile in Decryption /Access policies, member custom url got changed.

Last Modified

Jul 25, 2018

Products (1)

  • Cisco Web Security Appliance

Known Affected Releases

11.5.0-FCS-476

Description (partial)

Symptom:
Scenario:1 - Adding only one Identification profile (with custom URL category) in Access/Decryption Policy.
•	Create 'Identification Profile'  with selecting custom URL category.
•	Include 'Identification Profile' in the Access /Decryption Policy.
•	Member custom URL of Access /Decryption Policy will be excluded immediately and include only custom URL which are added as a part of identification Profile.

Scenario:2 -  Adding multiple Identification profile (with custom URL category) in Access/Decryption Policy.
•	Create multiple 'Identification Profile'  with Selecting custom URL category.
•	Include both 'Identification Profile' in the Access /Decryption Policy.
•	Member custom URL of Access /Decryption Policy will be excluded and add custom URL which are added as a part of identification Profiles. For example if Identification Profile-1 has three custom URL and Identification Profile-2 has two custom URL added. Access / Decryption policy will have total five custom URL ( if there is no common custom URL in between Identification Profile).

Scenario:3 -  Adding multiple Identification profile (one with custom URL category and another with no custom URL) in Access/Decryption Policy.
•	Create multiple 'Identification Profile'  one with Selecting custom URL category and another without selecting custom url.
•	Include both 'Identification Profile' in the Access /Decryption Policy.
•	Member custom URL of Access /Decryption Policy will be excluded and add custom URL which are added as a part of identification Profiles and also it would add the global policy. For example if Identification Profile-1 has three custom URL and Identification Profile-2 has no custom URL added. Also if global Access / Decryption Policy has five custom url as  pass-through.  Access / Decryption policy will have total seven custom URL ( if there is no common custom URL in between Identification Profile and global Access/Decryption Policy).

Scenario:4 -  Adding one or more Identification profile (without no custom URL) in Access/Decryption Policy.
•	Create one or more 'Identification Profile'  without URL category .
•	Include 'Identification Profiles' in the Access /Decryption Policy.
•	If member custom URL of Access /Decryption Policy is there , it would remain same. If there is no member custom url is added, it would inherit the global policy.

Conditions:
Need to have minimum two identification profile with and without custom url.
Identification profile should attached with Access/Decryption policy.
Access/Decryption policy should have different custom url filtering setting than global Access/Decryption policy.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.