The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This document describes Cisco Hybrid Web Appliance FAQ.
AsyncOS 9.2.0 for Web build 075.
Yes, it's a one time use only for each WSA.
60 minutes or one hour.
120 seconds or two minutes.
Hybrid Web Security mode provides unified cloud and on-premise policy enforcement and threat defense, using policies defined in Cisco ScanCenter—the administrative portal to Cloud Web Security (CWS) —which are automatically downloaded to the Web Security appliance.
No, it’s direct access to the Internet.
Features key Set are the same as WSA deployed in Proxy mode.
AsyncOS 9.2.0 for Web build 075 and Higher.
Features key Set are the same as WSA deployed in Proxy mode.
Features key Set are the same as WSA deployed in Proxy mode.
Cisco Contract number, Serial number of the Appliance, and CWS contract ID.
Cisco Contract number, VLN#, and CWS contract ID.
This functionality moved to Scan Center portal which is a part ofCloud Management Portal.
Current schedule is every two weeks.
Revert command is not supported with Hybrid Web Appliance.
Revert will be performed as an upgrade and requires provisioning from Cisco TAC. Please open support case.
https://tools.cisco.com/squish/B4cff
https://tools.cisco.com/squish/1D334
http://www.cisco.com/c/en/us/support/security/web-security-appliance/products-user-guide-list.html
https://tools.cisco.com/squish/0B343
Upgrade command is not supported with the Hybrid Web Appliance. To know more click https://youtu.be/Mpr8rmwR3a8.
No, only System Capacity reporting page is supported. Will require Cisco Advanced Web Security Reporting Application.
Make sure customers understand they need both CWS and WSA accounts/licenses to use this solution.
https://tools.cisco.com/squish/9982D
hybridd_logs, you can Grep or tail hybridd_logs for the details. User Interface (UI) improvements are coming in later versions.
Currently, default policy download is configured for 120 sec and this value cannot be modified.
From the Appliance GUI navigate to Support and Help > Web Policy Connectivity > change registration
From the Appliance GUI navigate to Reporting > System Status > Cloud Policy Communication
hybridd_logs that provide communication details between Web Appliance and Scan Center
TCP port 443 must be open through firewall.
Networking, interface, routes, Web and HTTPS proxy, Authentication Realm(s), EUN page, email alerts, Global
setting, Transparent re-direction and Proxy bypass.
No, and it’s not recommended.
In order to keep Cisco Hybrid Web Appliance up to date with the latest build and to keep the appliance in sync with the cloud.
Administrators can update the Upgrade and Update Setting from GUI navigate to System Administration > Upgrade and Update Setting > Edit Time Windows.
As long as the Active Directory Domain names are unique, that should not be an issue.
The only way this can be achieved is to run the setup wizard again and change the deployment mode.
Please reach out to Cisco TAC for the timeline.
Not at this time.
Native FTP, SOCKS, SaaS, DLP, SNMP trap, and setting threshold of WBRS service are not supported at this time.
For most part, we use advanced membership criteria in access policies to differentiate traffic hitting the particular
policy. For authentication, we expect a specific Identification Profile to be created with authentication realms and subnet.
Yes, these are the options:
There is list of exceptions in user guide please review.
Grep or tail hybridd_logs for realtime information - communication update between WSA and CWS portal.
We skip the failure part of the policy and convert they rest of the policy if there are no errors.