Cisco Cloud Web Security

Link

Cisco acquired a company named ScanSafe in 2009 to provide cloud based web proxy services and this service was renamed to Cisco Cloud Web Security (CWS). Cloud Web Security offers an alternative to on premise proxy services by hosting proxy services in data centers around the world. There is a single management portal where an administrator can create policies and run reports. Once a policy is created it is available across all the proxy servers around the world which greatly decreases the burden of creating consistent policies.

There are a variety of ways to leverage CWS including:

  • Cisco AnyConnect
  • Connectors for Cisco ISR G2 routers (1900, 2900, and 3900 series)
  • Connectors for Cisco ISR 4000 routers (4300, 4400 series)
  • Connector for Cisco ASA firewalls
  • Integration with the on premise Web Security Appliance (WSA)
  • Direct integration via client proxy configuration (point your operating system to the CWS proxy)

The connectors for the routers and firewalls offer transparent redirection which makes deployment very straightforward. The integration with AnyConnect provides a very simply solution for securing internet access for users when they are outside of the corporate network without requiring all internet traffic to be backhauled.

More information on the service can be found here http://www.cisco.com/c/en/us/products/security/cloud-web-security/index.html and information on the current proxy locations is available here http://servicestatus.sco.cisco.com/status

Wireshark Geolocation

Link

Wireshark is the de facto packet analysis tool and it comes with a wealth of options beyond what is included in a default installation. One option I discovered recently was to leverage the free version of the MaxMind geolocation database to enhance the visibility of packet data within Wireshark to include BGP AS assignment information, cities, and countries. This allows you to create filters based on this geolocation data which can be incredibly useful to quickly include or exclude interesting traffic based upon country or origin for example.

The complete setup guide can be found here.