Hello ,
Application control live and view log not working
tested with ff and chrome with cache reset many times
pls let me know which log will help
thanks
This would suggest that the rule was controlled by packet filter and not http proxy[:S]
2013:04:01-12:33:54 acenn ulogd[4820]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="11" outitf="eth1.50" mark="0x21fa" app="506" srcmac="0:c:29:7b:b4:8f" srcip="192.168.7.125" dstip="23.52.177.224" proto="6" length="229" tos="0x00" prec="0x00" ttl="63" srcport="42964" dstport="443" tcpflags="ACK PSH"
2013:04:26-09:19:25 acenn httpproxy[6031]: id="0066" severity="info" sys="SecureWeb" sub="http" name="web request blocked, forbidden application detected" action="block" method="GET" srcip="192.168.7.125" dstip="31.13.86.16" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="3949" request="0x202e0800" url="www.facebook.com/.../like.php"FACEBOOK"
2013:04:26-09:40:50 acenn ulogd[4947]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="14" outitf="eth1.50" mark="0x21fa" app="506" srcmac="0:c:29:7b:b4:8f" srcip="192.168.7.125" dstip="23.52.177.224" proto="6" length="358" tos="0x00" prec="0x00" ttl="63" srcport="42404" dstport="80" tcpflags="ACK PSH"
2013:04:26-10:56:03 acenn httpproxy[26844]: id="0066" severity="info" sys="SecureWeb" sub="http" name="web request blocked, forbidden application detected" action="block" method="GET" srcip="192.168.7.125" dstip="31.13.86.16" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2981" request="0x2087d548" url="https://www.facebook.com/" exceptions="" error="" country="Ireland" category="195" reputation="trusted" categoryname="Social Networking" content-type="text/html" application="FACEBOOK"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x206c4068" function="ssl_log_errors" file="ssl.c" line="79" message="C 192.168.7.125: 3941190512:error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1 alert unknown ca:s3_pkt.c:1256:SSL alert number 48"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x206c4068" function="ssl_log_errors" file="ssl.c" line="79" message="C 192.168.7.125: 3941190512:error:140940E5:SSL routines:SSL3_READ_BYTES:ssl handshake failure:s3_pkt.c:989:"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="" srcip="192.168.7.125" dstip="" user="" statuscode="000" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction=" ()" size="0" request="0x206c4068" url="199.47.219.159" exceptions="" error=""
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x206c4968" function="is_server_certificate_valid" file="ssl.c" line="683" message="Unable to get peer certificate"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="" srcip="192.168.7.125" dstip="" user="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction=" ()" size="0" request="0x206c4968" url="46.105.99.93" exceptions="" error="Failed to verify server certificate"
2013:04:26-09:19:25 acenn httpproxy[6031]: id="0066" severity="info" sys="SecureWeb" sub="http" name="web request blocked, forbidden application detected" action="block" method="GET" srcip="192.168.7.125" dstip="31.13.86.16" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="3949" request="0x202e0800" url="www.facebook.com/.../like.php"FACEBOOK"
2013:04:26-09:40:50 acenn ulogd[4947]: id="2019" severity="info" sys="SecureNet" sub="packetfilter" name="AFC Block" action="drop" fwrule="14" outitf="eth1.50" mark="0x21fa" app="506" srcmac="0:c:29:7b:b4:8f" srcip="192.168.7.125" dstip="23.52.177.224" proto="6" length="358" tos="0x00" prec="0x00" ttl="63" srcport="42404" dstport="80" tcpflags="ACK PSH"
2013:04:26-10:56:03 acenn httpproxy[26844]: id="0066" severity="info" sys="SecureWeb" sub="http" name="web request blocked, forbidden application detected" action="block" method="GET" srcip="192.168.7.125" dstip="31.13.86.16" user="" statuscode="403" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="2981" request="0x2087d548" url="https://www.facebook.com/" exceptions="" error="" country="Ireland" category="195" reputation="trusted" categoryname="Social Networking" content-type="text/html" application="FACEBOOK"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x206c4068" function="ssl_log_errors" file="ssl.c" line="79" message="C 192.168.7.125: 3941190512:error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1 alert unknown ca:s3_pkt.c:1256:SSL alert number 48"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x206c4068" function="ssl_log_errors" file="ssl.c" line="79" message="C 192.168.7.125: 3941190512:error:140940E5:SSL routines:SSL3_READ_BYTES:ssl handshake failure:s3_pkt.c:989:"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="" srcip="192.168.7.125" dstip="" user="" statuscode="000" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction=" ()" size="0" request="0x206c4068" url="199.47.219.159" exceptions="" error=""
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x206c4968" function="is_server_certificate_valid" file="ssl.c" line="683" message="Unable to get peer certificate"
2013:04:26-10:56:06 acenn httpproxy[26844]: id="0002" severity="info" sys="SecureWeb" sub="http" name="web request blocked" action="block" method="" srcip="192.168.7.125" dstip="" user="" statuscode="502" cached="0" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction=" ()" size="0" request="0x206c4968" url="46.105.99.93" exceptions="" error="Failed to verify server certificate"