Details
| ID | CiscoWSA |
|---|---|
| Provider | Cisco Systems |
| Category | Utilities |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.10.10.48392 |
| Supported Modules | Agentix XSIAM |
README
Cisco WSA
This integration was integrated and tested with version vSeries-100 of Cisco-WSA
Configure CiscoWSA in Cortex
| Parameter | Required |
|---|---|
| BASE_URL | True |
| API_KEY | True |
| PORT | False |
| Trust any certificate (not secure) | False |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
wsa-get-access-policies
Retrieving all access policies
Base Command
wsa-get-access-policies
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| wsa.AccessPolicies | string | Retrieving all access policies |
Command Example
#### Context Example
```json
{
"access_policies": [
{
"amw_reputation": {
"state": "use_global"
},
"avc": {
"state": "use_global"
},
"http_rewrite_profile": "use_global",
"membership": {
"identification_profiles": [
{
"profile2": {
"auth": "No Authentication"
}
}
],
"protocols": [
{
"id_profile": "profile2",
"value": [
"http",
"https",
"ftp"
]
}
]
},
"objects": {
"state": "use_global"
},
"policy_description": "",
"policy_expiry": "",
"policy_name": "policy2",
"policy_order": 1,
"policy_status": "enable",
"protocols_user_agents": {
"state": "use_global"
},
"url_filtering": {
"custom_cats": {
"use_global": [
"SocialURLCategorynader1"
]
},
"exception_referred_embedded_content": {
"state": "disable"
},
"state": "custom",
"update_cats_action": "use_global",
"yt_cats": {
"use_global": [
"Film & Animation",
"Autos & Vehicles",
"Music",
"Pets & Animals",
"Sports",
"Travel & Events",
"Gaming",
"People & Blogs",
"Comedy",
"Entertainment",
"News & Politics",
"Howto & Style",
"Education",
"Science & Technology",
"Nonprofits & Activism"
]
}
}
},
{
"amw_reputation": {
"state": "use_global"
},
"avc": {
"state": "use_global"
},
"http_rewrite_profile": "use_global",
"membership": {
"identification_profiles": [
{
"profile1": {
"auth": "No Authentication"
}
}
],
"protocols": [
{
"id_profile": "profile1",
"value": [
"http",
"https",
"ftp"
]
}
]
},
"objects": {
"state": "use_global"
},
"policy_description": "",
"policy_expiry": "",
"policy_name": "policy1",
"policy_order": 2,
"policy_status": "enable",
"protocols_user_agents": {
"state": "use_global"
},
"url_filtering": {
"custom_cats": {
"use_global": [
"SocialURLCategorynader1"
]
},
"exception_referred_embedded_content": {
"state": "disable"
},
"state": "custom",
"update_cats_action": "use_global",
"yt_cats": {
"use_global": [
"Film & Animation",
"Autos & Vehicles",
"Music",
"Pets & Animals",
"Sports",
"Travel & Events",
"Gaming",
"People & Blogs",
"Comedy",
"Entertainment",
"News & Politics",
"Howto & Style",
"Education",
"Science & Technology",
"Nonprofits & Activism"
]
}
}
},
{
"amw_reputation": {
"state": "use_global"
},
"avc": {
"state": "use_global"
},
"http_rewrite_profile": "use_global",
"membership": {
"identification_profiles": [
{
"profile2": {
"auth": "No Authentication"
}
}
],
"protocols": [
{
"id_profile": "profile2",
"value": [
"http",
"https",
"ftp"
]
}
]
},
"objects": {
"state": "use_global"
},
"policy_description": "",
"policy_expiry": "",
"policy_name": "nader2",
"policy_order": 3,
"policy_status": "enable",
"protocols_user_agents": {
"state": "use_global"
},
"url_filtering": {
"custom_cats": {
"use_global": [
"SocialURLCategorynader1"
]
},
"exception_referred_embedded_content": {
"state": "disable"
},
"state": "custom",
"update_cats_action": "use_global",
"yt_cats": {
"use_global": [
"Film & Animation",
"Autos & Vehicles",
"Music",
"Pets & Animals",
"Sports",
"Travel & Events",
"Gaming",
"People & Blogs",
"Comedy",
"Entertainment",
"News & Politics",
"Howto & Style",
"Education",
"Science & Technology",
"Nonprofits & Activism"
]
}
}
},
{
"amw_reputation": {
"state": "use_global"
},
"avc": {
"state": "use_global"
},
"http_rewrite_profile": "use_global",
"membership": {
"identification_profiles": [
{
"profile1": {
"auth": "No Authentication"
}
}
],
"protocols": [
{
"id_profile": "profile1",
"value": [
"http",
"https",
"ftp"
]
}
]
},
"objects": {
"state": "use_global"
},
"policy_description": "",
"policy_expiry": "",
"policy_name": "nader1",
"policy_order": 4,
"policy_status": "enable",
"protocols_user_agents": {
"state": "use_global"
},
"url_filtering": {
"custom_cats": {
"use_global": [
"SocialURLCategorynader1"
]
},
"exception_referred_embedded_content": {
"state": "disable"
},
"state": "custom",
"update_cats_action": "use_global",
"yt_cats": {
"use_global": [
"Film & Animation",
"Autos & Vehicles",
"Music",
"Pets & Animals",
"Sports",
"Travel & Events",
"Gaming",
"People & Blogs",
"Comedy",
"Entertainment",
"News & Politics",
"Howto & Style",
"Education",
"Science & Technology",
"Nonprofits & Activism"
]
}
}
},
{
"amw_reputation": {
"cisco_dvs_amw": {
"amw_scanning": {
"amw_scan_status": "disable",
"amw_scanners": {
"mcafee": "unavailable",
"sophos": "unavailable",
"webroot": "unavailable"
}
},
"other_categories": {},
"suspect_user_agent_scanning": "scan"
},
"web_reputation": {
"filtering": "unavailable"
}
},
"avc": {
"state": "unavailable"
},
"http_rewrite_profile": "None",
"membership": {
"identification_profiles": [
{
"_all_": {
"auth": "No Authentication"
}
}
]
},
"objects": {
"max_object_size_mb": {
"ftp": 0,
"http_or_https": 0
},
"object_type": {
"Archives": {
"monitor": [
"StuffIt",
"BinHex",
"LHARC",
"ARC",
"ARJ"
]
},
"Document Types": {
"monitor": [
"PostScript Document (PS)",
"OpenOffice Document",
"OASIS Open Document Format",
"Microsoft Office",
"XML Document",
"Portable Document Format (PDF)",
"FrameMaker Document (FM)",
"Rich Text Format (RTF)"
]
},
"Executable Code": {
"monitor": [
"UNIX Executable",
"Windows Executable",
"Java Applet"
]
},
"Inspectable Archives": {
"allow": [
"BZIP2",
"CPIO",
"7zip",
"RAR",
"LHA",
"ZIP Archive",
"GZIP",
"Compress Archive (Z)",
"TAR",
"Microsoft CAB"
]
},
"Installers": {
"monitor": [
"UNIX/LINUX Packages"
]
},
"Media": {
"monitor": [
"Photographic Images",
"Video",
"Audio"
]
},
"Miscellaneous": {
"monitor": [
"Calendar Data"
]
},
"P2P Metafiles": {
"monitor": [
"BitTorrent Links (.torrent)"
]
},
"Web Page Content": {
"monitor": [
"Images",
"Flash"
]
}
},
"state": "custom"
},
"policy_description": "Default settings",
"policy_expiry": "",
"policy_name": "global_policy",
"policy_status": "enable",
"protocols_user_agents": {
"allow_connect_ports": [
"8080",
"21",
"443",
"563",
"4431",
"6443",
"8443",
"20",
"6080"
],
"block_custom_user_agents": [],
"block_protocols": [],
"state": "custom"
},
"url_filtering": {
"custom_cats": {
"exclude": [
"SocialURLCategorynader1"
]
},
"exception_referred_embedded_content": {
"state": "disable"
},
"update_cats_action": "least restrictive",
"yt_cats": {
"monitor": [
"Film & Animation",
"Autos & Vehicles",
"Music",
"Pets & Animals",
"Sports",
"Travel & Events",
"Gaming",
"People & Blogs",
"Comedy",
"Entertainment",
"News & Politics",
"Howto & Style",
"Education",
"Science & Technology",
"Nonprofits & Activism"
]
}
}
}
]
}
Human Readable Output
Results
access_policies
wsa-get-domain-map
Retrieving the Domain Map Details
Base Command
wsa-get-domain-map
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| wsa.DomainMaps | string | Retrieving the Domain Map Details |
Command Example
#### Context Example
```json
{
"res_code": 400,
"res_message": "The feature key for https proxy has expired or is unavailable."
}
Human Readable Output
Results
res_code res_message 400 The feature key for https proxy has expired or is unavailable.
wsa-get-url-categories
Retrieving URL Categories
Base Command
wsa-get-url-categories
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| wsa.UrlCategories | string | Retrieving URL Categories |
Command Example
#### Context Example
```json
{
"custom": [
"SocialURLCategorynader1"
],
"predefined": null
}
Human Readable Output
Results
custom predefined SocialURLCategorynader1
wsa-get-identification-profiles
Modifying identification profiles
Base Command
wsa-get-identification-profiles
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
| Path | Type | Description |
|---|---|---|
| wsa.Profiles | string | Retrieving Identification Profiles |
Command Example
#### Context Example
```json
{
"identification_profiles": [
{
"description": "",
"identification_method": {},
"members": {
"protocols": [
"http",
"https",
"ftp"
]
},
"order": 1,
"profile_name": "profile2",
"status": "enable"
},
{
"description": "",
"identification_method": {},
"members": {
"protocols": [
"http",
"https",
"ftp"
]
},
"order": 2,
"profile_name": "profile1",
"status": "enable"
},
{
"description": "Default settings",
"identification_method": {},
"profile_name": "global_identification_profile",
"status": "enable"
}
]
}
Human Readable Output
Results
identification_profiles
wsa-modify-access-policies
Modifying an Access Policy
Base Command
wsa-modify-access-policies
Input
| Argument Name | Description | Required |
|---|---|---|
| policyname | Name of the policy. Unique identifier of the policy. | Required |
| profile_name | (profile_name, auth). Use “No Authentication” in case of no authentication required for the specific profile. Empty strings represents “global identification profile”. all represents “All identification profiles”. Please all inputs comma separated. | Required |
| auth | (profile_name,auth). Use “No Authentication” in case of no authentication required for the specific profile. Empty strings represents “global identification profile”. all represents “All identification profiles”. Please all inputs comma separated. | Required |
| policy_order | Index of this specific profile in the collection. Its starts from 1. Order of policy in collection of policies. Not applicable for global_policy. | Required |
| policy_status | Whether profile is enabled or disabled. Possible values: enable, disable. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| wsa.response | string | whether the result indicates if request is success or failure |
Command Example
!wsa-modify-access-policies policyname=policy1 profile_name=profile1 policy_order=2 policy_status=disable auth="No Authentication"
Context Example
{
"wsa": {
"response": "The modifying request has been processed successfully and all the given access policies are updated with the given payload"
}
}
Human Readable Output
Results
wsa
wsa-delete-access-policies
Deleting an Access Policy
Base Command
wsa-delete-access-policies
Input
| Argument Name | Description | Required |
|---|---|---|
| policy_name | Name of the policy. Unique identifier of the policy. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| wsa.response | unknown | whether the result indicates if request is success or failure |
Command Example
!wsa-delete-access-policies policy_name=policy2
Context Example
{
"wsa": {
"response": "The deleting request has been processed successfully and all the given access policies are updated with the given payload"
}
}
Human Readable Output
Results
wsa
Configuration parameters
url— Server URL (required)apikey— API Key (required)port— Portinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (6)
-
wsa-delete-access-policiesDeleting an Access Policy
-
wsa-get-access-policiesRetrieving all access policies
-
wsa-get-domain-mapRetrieving the Domain Map Details
-
wsa-get-identification-profilesModifying identification profiles
-
wsa-get-url-categoriesRetrieving URL Categories
-
wsa-modify-access-policiesModifying an Access Policy
commonfields: id: CiscoWSA version: -1 name: CiscoWSA display: CiscoWSA (Deprecated) category: Utilities provider: Cisco Systems deprecated: true description: Deprecated. Use CiscoWSAV2 instead. configuration: - display: "Server URL" name: url defaultvalue: http://192.168.1.1 type: 12 required: true - display: "API Key" name: apikey type: 4 required: true - display: "Port" name: port type: 0 required: false - display: Trust any certificate (not secure) name: insecure type: 8 required: false - display: Use system proxy settings name: proxy defaultvalue: "false" type: 8 required: false script: script: '' type: python commands: - name: wsa-get-access-policies arguments: [] outputs: - contextPath: wsa.AccessPolicies description: Retrieving all access policies type: string description: Retrieving all access policies - name: wsa-get-domain-map arguments: [] outputs: - contextPath: wsa.DomainMaps description: Retrieving the Domain Map Details type: string description: Retrieving the Domain Map Details - name: wsa-get-url-categories arguments: [] outputs: - contextPath: wsa.UrlCategories description: Retrieving URL Categories type: string description: Retrieving URL Categories - name: wsa-get-identification-profiles arguments: [] outputs: - contextPath: wsa.Profiles description: Retrieving Identification Profiles type: string description: Modifying identification profiles - name: wsa-modify-access-policies arguments: - name: policyname required: true description: Name of the policy. Unique identifier of the policy - name: profile_name required: true description: (profile_name, auth). Use "No Authentication" in case of no authentication required for the specific profile. Empty strings represents "global identification profile". _all_ represents "All identification profiles". Please all inputs comma separated. - name: auth required: true description: (profile_name,auth). Use "No Authentication" in case of no authentication required for the specific profile. Empty strings represents "global identification profile". _all_ represents "All identification profiles". Please all inputs comma separated. - name: policy_order required: true description: Index of this specific profile in the collection. Its starts from 1. Order of policy in collection of policies. Not applicable for global_policy. - name: policy_status required: true description: 'Whether profile is enabled or disabled. Possible values: enable, disable' outputs: - contextPath: wsa.response description: whether the result indicates if request is success or failure type: string description: Modifying an Access Policy - name: wsa-delete-access-policies arguments: - name: policyname required: true description: Name of the policy. Unique identifier of the policy - name: policy_status description: Enable/disable - name: profile_name description: (profile_name, auth). Use "No Authentication" in case of no authentication required for the specific profile. Empty strings represents "global identification profile". _all_ represents "All identification profiles". Please all inputs comma separated. - name: policy_order description: Index of this specific profile in the collection. Its starts from 1. Index of this specific profile in the collection. Its starts from 1. Order of policy in collection of policies. Not applicable for global_policy. - name: auth description: (profile_name,auth). Use "No Authentication" in case of no authentication required for the specific profile. Empty strings represents "global identification profile". _all_ represents "All identification profiles". Please all inputs comma separated. outputs: - contextPath: wsa.response description: whether the result indicates if request is success or failure description: Deleting an Access Policy dockerimage: demisto/python3:3.10.10.48392 subtype: python3 fromversion: 6.0.0 tests: - No tests (deprecated)