Cisco Application :: WCCP Web-cash On 2801 12.4(22)T

Nov 14, 2011

My problem is, it doesn’t seem like packets are making it to the linux/squid caching device, based on cache logs. Workstations that are being redirected in the router have no web browser access (they can ping 8.8.8.8 and google.com)
 
I have a linux box running squid successfully, which supports GRE WCCP. For the sake of argument, I will say that I am confident I have successfully configured that machine.
 
What’s really strange is this morning I came in and hind sight my test workstation looked like it may had restarted from an update. (maybe had internet access). The first thing I did was tweak the cisco config, as I was reading last night and saw:
 
“Be warned that if you are using NAT you MUST use the inbound interface otherwise the router only sees the NATted IP address as the source of your clients. This is bad, because the router is also therefore unable to see your cache engine and it will redirect the cache engine requests back upon itself.”
 
So I turned <ip cef> on and removed the <ip wccp web-cache redirect out> (I had in fa0/1 and out fa0/0 on overnight).
 
Then I proceeded to check the workstation and saw it had network access, I tested to see if it was in fact filtered by the proxy, and it was! (verified by cache logs aswell)
 
After some further successful testing, I made sure I saved any unsaved configuration changes, I rebooted the linux box and the router. Sadly the outcome was not good, I am back to where I was last night.
 
 
My router does routing/NAT and has two interfaces and is currently not running CEF
 
ip wccp web-cache redirect-list SQUID_PROXY
!
interface FastEthernet0/0
description WAN
ip address 1.2.3.4 255.255.255.248
ip nat outside
ip virtual-reassembly max-reassemblies 64
speed 100
full-duplex(code)

View 6 Replies


ADVERTISEMENT

Cisco Application :: 7200 - WCCP Router Identifier

Nov 19, 2011

I am getting the following message while trying to configure WCCP redirection on my 7200 router.
 
I have added this router to the routerlist of the WAE edge device. Ping is successful, but the following problem prevails.
 
NASCM-MPLS#show ip wccp
Global WCCP information:
Router information:

[Code]....

View 1 Replies View Related

Cisco Application :: 2900 Router WCCP Support For GRE Encapsulated Redirects

May 23, 2012

I've been looking around Cisco's website but I can't find an answer to this -- If the 2900 platform suppots WCCP redirection using GRE? 

View 1 Replies View Related

Cisco Application :: ASA 5505 To Bypass WCCP For Specific Public IP Address

Jun 29, 2011

Currently using WCCP with squid for content filtering. One of our sites we connect to needs to see the connection coming from our public IP address, not the proxy server IP. I've created a acl in squid for direct lookup, but the website gets angry with the X-Forwarder-Header squid attaches to each packet. Is there a way in a cisco ASA 5505 to bypass wccp for a specific public ip address or url?

View 4 Replies View Related

Cisco Application :: 3945 - WCCP Redirection For WAAS On Same Platform Using Different Service Group?

Nov 9, 2011

if a Cisco router or switch can handle wccp redirection enabled for both waas and some other web content filtering appliance using a different service group?
 
seems like the priority value would come into play determining which service group gets handled first?
 
we currently do WCCP for WaaS on our 3945s.
 
I am going to advocate to my customer that we separate this out for CPU load issues, config complexity issues, IOS issues, etc... but the question is going to come up - "can we do WCCP for different applications on our Catalyst 3750 core switch, or our 3945 WAN routers?"

View 2 Replies View Related

Cisco :: Squid And WCCP On ASA

Mar 26, 2011

So Im trying to learn a little bit more about WCCP so I thought I'd load up a centos VM and just install squid on it. With the base config running I can setup an explicit proxy by configuring my IE session to use the squid IP on port 3128. Proxy works fine and I see entries in the access log on the centos box. Now, since Im only running squid on the box Im going to change the listening port to 80 so I can transparent proxy with WCCP on my ASA. So I set the WCCP2 config on squid as shown.

View 10 Replies View Related

Cisco WAN :: Does 881 Support PBR And WCCP Protocols?

Oct 18, 2011

We have 881 routers and are planning on testing out some WAN optimizing hardware, we're told that our router needs to support PBR and WCCP protocols.  Will this router handle it?

View 3 Replies View Related

Cisco WAN :: WS-C3560X-48P Support WCCP?

Feb 28, 2013

if the Cisco Switches in my enviorment can support WCCP?

View 1 Replies View Related

Cisco :: Roll Out A Bluecoat As A WCCP For A ASA 5520

May 25, 2012

I need to roll out a Bluecoat as a WCCP for a ASA 5520.

View 3 Replies View Related

Cisco :: WCCP Not Working With McAfee Web Gateway?

Oct 31, 2012

I'm using a Cisco AG3560 to run my wccp re-direct and have a McAfee for my web gateway. My IP for the web gateway is 10.1.252.19, and my wccp router is 10.1.3.10. For whatever reason the web gateway is able to see the router and the "here i am packets" but I cannot get anything to redirect to it. My wccp config is below.

ip wccp 51 redirect-list 120
!
interface Loopback0
ip address 10.1.254.17 255.255.255.255

[code]...

I have the Web Gatewy setup with process 51 and my router on the WG is 10.1.252.10.

View 1 Replies View Related

Cisco Firewall :: WCCP Redirection On ASA 5520

Jul 17, 2011

I currently have WCCP redirection setup on my ASA 5520 to redirect to an ironport on ip address 10.11.1.10. The ASA inside ip is 10.11.1.1 and the ironport is setup for transparent redirection to that IP. This all works well and the Service Identifier i'm using for WCCP is 95.I am now creating another WCCP group because on my ironport I have 4 interfaces so I wanted to use them for our admin network. So I created an ACL on the ASA for our admin traffic and I want to redirect that using Service Identifier 94 to the ip on the ironport of 10.11.1.22. But I can't get traffic to redirect.

View 1 Replies View Related

Cisco Infrastructure :: WCCP Configuration On 4507

Jun 16, 2012

I am trying to setup WCCP on our 4507. For some reason I cannot get this to work! The config I have tried is below. I can't figure out
 
ip wccp web-cache group-list IRONPORT-GROUPLIST
ip wccp source-interface GigabitEthernet2/24
!
Interface Vlan160

[Code].....

View 2 Replies View Related

Cisco WAN :: 3750 / WCCP Error IOS Version 12.2(46)SE?

Jul 19, 2011

When the following was issued:

ip wccp 0 redirect-list wccp_acl group-list 10 password 0 ourpassword
 
Received this error:

MDT: %COMMON_FIB-3-FIBIDBINCONS2: An internal software error occurred. WCCP:0 linked to wrong idb Loopback0 (xyz node name)
 
When the following was issued 10 minutes later:

ip wccp 70 redirect-list wccp_acl group-list 10 password 0 ourpassword
 
No error msg (but now wccp was active)WCCP appears to be working but we are ** having problems connecting ** with our websense (7.6) box via GRE.Websense is connected to the 6509 which is connected this 3750 switch.

View 2 Replies View Related

Cisco WAN :: 7200 - WCCP And CPU Utilization On Routers?

Jul 20, 2011

I’m currently trying to work out what router we need to do WCCP redirections to some WAN optimizers. We plan that there will 100-200Mbps worth of traffic that needs to be redirected.
 
We currently have a 7200 with NPE-G2 which already runs at 30% cpu without WCCP redirection. (From shaping and QoS.)
I’m worried that this will not be powerful enough for the redirections.
 
We would like to upgrade, but I want to do some research beforehand.I have looked everywhere and I cannot find any WCCP performance figures for the devices below.

-7200 with NPE-G2 -ASR1000 -3800 -3750 -6500 I am aware that the catalyst and the ASR can do the redirecting in hardware, so these means there is no real CPU hit until we exhaust  the TCM? We plan to use in bound redirection and the redirect ACL is only 20 lines.

View 1 Replies View Related

Cisco Firewall :: WCCP Redirection On ASA 5540?

Apr 3, 2013

I have the following topology, WCCP is configurated on ASA, inside interface, lan users and websense machine are located on the same VLAN of my catalyst 3750G?I want to filter traffic on port 80 (www) to the users on the LAN side debug on the ASA show me that comunication between that device and Websense is OK,  there is Here_I_Am and I_See_You packets
  
WCCP-PKT:D00: Sending I_See_You packet to WEBSENSE_PROXY w/ rcv_id 0000015B
 WCCP-PKT:D00: Received valid Here_I_Am packet from WEBSENSE_PROXY w/rcv_id 0000015B
 WCCP-PKT:D00: Sending I_See_You packet to WEBSENSE_PROXY w/ rcv_id 0000015C
 WCCP-PKT:D00: Received valid Here_I_Am packet from WEBSENSE_PROXY w/rcv_id 0000015C
 WCCP-PKT:D00: Sending I_See_You packet to WEBSENSE_PROXY w/ rcv_id 0000015D
  
From show WCCP i saw that WCCP engine and ASA were detected
 
FW# sh wccp 
Global WCCP information:
Router information:
Router Identifier:                   200.X.X.X
Protocol Version:                    2.0

[code]....

View 5 Replies View Related

Cisco :: WCCP Not Working Between Squid (OpenBSD) And 3560?

Jul 26, 2012

I'm testing WCCP in a lab environment (Another checkbox on my way to CCIE).The setup- a WS-C3560-8PC switch running IOS 15.0(1), IP Services with crypto.- Two client computers connected by wire to the switch, running Windows 7.- A virtual machine in bridged mode running on one of the machines, running OpenBSD 5.0 with Squid 2.7 installed and running.- Everything in the same subnet: 192.168.163.0/24, the OpenBSD is at .5, the switch at .3 and functions as the default-gateway for the computers with no ICMP redirects (the real gateway is at .1 but the switch forwards everything).Squid seems to work, albeit inefficient, but that's not the issue.illing in the IP of the OpenBSD in the browser as proxy with the proper port works.Since the 3560 does only support WCCP over layer 2 adjacencies and masks, not hash buckets, I've configured these options on both the Squid and the 3560.

View 19 Replies View Related

Cisco WAN :: 6500 / Setting Up Config To Have WCCP With Optimizer?

May 28, 2012

I'm setting up a config to have WCCP with Blue Coat WAN Optimizer. I have following sinple setup at the moment. Cisco 6500 <----> Firewall. How should my topology should be. Should I have whe WAN-Optimizer in between (in path of switch and firewall on the same VLAN) or have different vlan hanging off the 6500 and have WCCP redirect traffic?

View 2 Replies View Related

Cisco WAN :: 2811 - WCCP Transparent Proxy Over DMVPN

Nov 20, 2010

I´m trying to config a wccp web-proxy in a ISR 2811 at branch network. I have an Iron Port at Head-Quarter.
 
The idea is that the users at branch network, transparently forward http traffic to Iron Port at Central-Office and from them go to Internet.
 
The communication between sites is over DMVPN. I have two GRE tunnels running OSPF.
 
The Iron Port is configured as wccp v2 transparent redirection with forwarding method L2 or GRE an retunr method as L2 or GRE.
 
I receive packets on the branch router "Here I Am" but it get a message on debug:

Nov 21 19:26:07.067 GMT-2: WCCP-EVNT:D10: Here_I_Am packet from 172.16.10.10 w/bad fwd method L2, received indirectly via Tunnel1Nov 21 19:26:07.067 GMT-2: WCCP-EVNT:D10: Here_I_Am packet from 172.16.10.10 with incompatible capabilites

Nov 21 19:46:07.035 GMT-2: WCCP-PKT:D10: Sending I_See_You packet to 172.16.10.10 w/ rcv_id 0000004F

View 1 Replies View Related

Cisco Firewall :: ASA 5512 WCCP Configuration With Web Filter

Oct 31, 2012

I am currently trying to enable WCCP between a Cisco ASA 5512 firewall and Barraccuda Webfilter 410 Vx applicance. The ASA firewall is running IOS version 8.6(1)2 and the Barracuda is funning firemware 6.0.0.013. Both the ASA and Barracuda are in the same network and can ping eachother. The ASA has several interfaces, outside, inside, data and dmz. The PCs and barracuda appliance are behind the data interface.  ASA data IP 172.16.18.1 Barracuda IP 172.16.18.40   All PCs in the 172.16.18.0/24 subnet use the ASA as the default gateway and should have web requests redirected to the Barracuda. 
 
Below are the respecive bits of my ASA config
 
interface GigabitEthernet0/0
description Management
speed 1000

[Code].....
 
I suspect my issue is that the ASA is generating a Router Identifier of 172.21.20.1 which is my inside network and the barracuda cannot communicate with it.  how I can get this working ?

View 3 Replies View Related

Cisco WAN :: WCCP HTTP Access Timeouts With 3750

Jan 29, 2012

I have a web cache server, and I redirect all the HTTP request to it using WCCP.
 
Everything works without a problem, however I have a monitoring system that every minute tests the access to some customer sites that are hosted inside our infra-strutcture.
 
As soon as I configured the WCCP the monitoring system complains of timeouts accessing those sites, about 20% of the requests start to fail (timeout).
 
I don't think it is the fault of the cache because in the WCCP ACL I exclude all traffic that comes from my monitoring system. However as soon as I turn of WCCP the monitoring system never ever gives timeouts accessing those sites.
 
Is there anything I should do in WCCP to tweak it? I have WCCP configured in my core gateway that is a CISCO 3750.

View 2 Replies View Related

Cisco Switching/Routing :: WCCP On 6509 Connection

Apr 5, 2012

Is there a way to use 2 redirects inbound on vlan 1?
 
int vlan 1
ip wccp 80 redirect in
ip wccp 81 redirect in
 
The reason for this is because we need the return traffic from the firewall to come in on group 81 and the source subnet will go out group 80.

View 1 Replies View Related

Cisco Switching/Routing :: 3750 12.2(46) WCCP Stack

Nov 21, 2011

I'm setting up a web cache using the wccp protocol on a Catalyst 3750 stack.
 
Probably missing something real simple here but when I from the global configuration mode are trying to enter the ip wccp command it just says "invalid input" from wccp. There is no such command.. should be supported on my device from IOS 12.2(37)

View 1 Replies View Related

Cisco Security :: Dual ASA 5520 WCCP Configuration?

Dec 6, 2012

I recently configured WCCP with a Sophos Web Filter on my network it works good but the problem I am having is I have two 5520s so I am directing the device to look at 2 different IP addresses and since the devices are in an Active/Passive failover.  The problem is because the second device is in a passive failover it is not responding which is throwing connection errors to my Sophos device.  I know you can have a single management connection for the ASA's but is there a way to have a single IP for the ASAs for the WCCP?

View 1 Replies View Related

Cisco Switching/Routing :: 6509 - WCCP For HTTPS

Feb 27, 2012

I am trying to enable wccp on 6509. Its works fine on port 80 but not with https (443). Also i have noticed when i use the following
 
ip wccp web-cache redirect in similarly adding to interface HTTP works. but when i use the service no 0 instead of web-cache even the HTTP stops working. wccp v2 is enabled in the switch. Both the source & the Squid server are in same V LAN.

View 9 Replies View Related

Cisco Switching/Routing :: WCCP On 6500 With Squid Proxy

May 19, 2012

I have been tasked to setup a Transparent Squid proxy and do redirection on  a Cisco 6513 Switch.I don't have access to the SQUID but think that my config below should be OK. We have setup a TEST user Vlan 13 . Any traffic from this destined for the we on 80 or 443 should be redirected. Vlan 10 is where the Squid proxy is sitting. [code]

View 3 Replies View Related

Cisco Firewall :: ASA5585 WCCP-GRE Redirection To Websense Times Out?

Dec 9, 2012

I have a ASA5585 running 8.4 that is redirecting Internet http to a websense server via GRE.The integration is working fine, except when a user PC sends a large packet (~1500 bytes).With WCCP/GRE headers, the user packet is too large to be transmitted to websense, so the ASA fragments the packet in two and transmits both to websense.
 
A sniffer trace confirms that both fragments reach the websense server, but the TCP packet is never acknowledged.User-side TCP retransmits the large packet three times over 15 seconds, and eventually retransmits fine with smaller packets.  The 15 second delay is of course not acceptable.Users and Websense server are both on the Inside interface.
 
We are considering imposing browser proxy to websense (which works fine), but would prefer not, considering the increasing diversity of devices.

View 4 Replies View Related

Cisco Firewall :: WCCP Support On FWSM Running 6500

Mar 10, 2011

What the support for WCCP on a FWSM running 4.0(7) is like, if there is any at all ?
 
I've read that the earliest PIX release that supports WCCP was 7.2(1) but I'm not sure how FWSM 4.0(7) aligns with the PIX versions.The only doc's i can find refrencing WCCP on a 6500 with FWSM is in the 6500 12.2 IOS guide.

View 1 Replies View Related

Cisco Switching/Routing :: 3560 With WCCP Not Working Correctly

Jun 17, 2012

I am trying to configure a 3560 (Version 12.2(55)SE3) with IPServices to run WCCP to two to an Ironport WSA.
 
I believe everything is setup correctly, however WCCP is still not operational. I have check the debug logs on the switch and I'm presented with a number of messages along the lines of...
 
*Mar  1 03:44:47.891: WCCP-EVNT:wccp_update_assignment_status: enter
*Mar  1 03:44:47.891: WCCP-EVNT:wccp_update_assignment_status: exit
*Mar  1 03:44:47.891: WCCP-EVNT:wccp_copy_wc_assignment_data: enter

[Code]....

View 7 Replies View Related

Cisco Firewall :: 2921 Enable WCCP - SSH Connections Fail

Feb 22, 2012

I have a IOS firewall on a 2921 router, zone-based config. The remote and main sites have Cisco WAAS , running 4.4.1 software. I am using WCCP redirection on the WAAS/router combination. If I leave it off the firewall passes SSH correctly to the devices on the other side of the firewall. If I enable WCCP the SSH connections fail. The SSH to the router itself is fine, I am not using the self zone for router protection. I had seen a few posts on WAAS but the only one mentioning a config statement in the firewall was on 4.0 WAAS and the command is no longer on the IOS firewall. Is this supposed to work transparently or am I missing a config?

View 2 Replies View Related

Cisco Firewall :: ASA 5520 VPN Users With WCCP Redirection To IronPort

Apr 11, 2012

I have a 5520 ASA using wccp redirection to our IronPorts on the inside and everything works great for inside users. What I'm trying to do is get VPN users off split tunneling and to filter their traffic through the IronPorts as well but I can't figure out how. When they connect they seem to bypass the Ironport completely.

View 5 Replies View Related

Cisco Switching/Routing :: WCCP And High CPU Utilization On 2851

Jan 23, 2010

I have a Head Quarter and a remote site running over a OC3 circuit. [code]

On the HQ, I have a Cisco VXR7204 running IOS 12.4.15T(10) Advanced IP Serviceand the remote site is a Cisco 2851 also running IOS 12.4.15T(10) Advanced Ip Service.  The HQ has a Riverbed Steelhead 5050H capable of delivering 100MbpsWCCP throughput.  The remote site has a Riverbed Steelhead 1050H which can deliver 10Mbps WCCP throughput.  At the HQ, the LAN network is 192.168.251.0/24.The Steelhead residing on the 192.168.251.0 network.At the remote site, the LAN network is 192.168.103.0/24 and 192.168.211.0/24.The Riverbed resides on the 192.168.103.0/24 network.
 
When a host on network 192.168.211.0/24 download a file from network192.168.251.0/24 network via http, the CPU on the Cisco 2851 goes to 99% utilization and that it stays there for the duration of the http session.  There is very little traffic goes across the WAN whichis the way it should be but the CPU on the 2851 stays at constant at99% CPU utilization.
 
Why would WCCP consume so much CPU on the Cisco 2851?  By the way, I am only getting about 5Mbps download instead of 90Mbps download, I think because of the high CPU on the router?

View 2 Replies View Related

Cisco Switching/Routing :: WCCP Configuration On Catalyst 3750G?

Jul 5, 2010

I have a WCCP Configuration on a Catalyst 3750G and a IronPort Webappliance. I have configured this situation many times before with cisco asa and ironport wsa, but with a switch, this is my first time.
 
VLAN 147 is a transportation vlan between the cisco switch and a hp coreswitch with the clients and servers behind the hp coreswitch.
 
VLAN 147 IP Address of the Catalyst is 172.30.47.1
 
IP of the IronPort Appliance is 172.30.47.10
 
IP of the HP Coreswitch is 172.30.47.2
 
Plan  is to redirect the webtraffic coming from clients and servers from the 10.0.0.0/8 net behind the hp switch to the ironport wsa. In have configured these settings.
 
ip wccp web-cache group-list 15 password 7 091D1C5Aip wccp 80 redirect-list 16 group-list 15 password 7 14464058
interface GigabitEthernet1/0/22 description IRONPORT P1 BUWOG switchport access vlan 147 switchport mode access
interface Vlan115 ip address 172.30.15.2 255.255.255.0 standby 10 ip 172.30.15.1 standby 10 priority 90 standby 10 preempt standby 10 track Vlan115!interface Vlan147 ip address 172.30.47.1 255.255.255.0 ip wccp web-cache redirect in ip wccp 80 redirect in

[code]....

View 6 Replies View Related

Cisco Switching/Routing :: WCCP V2 - Unable To Redirect The HTTPS Traffic?

Jun 3, 2013

I am unable to redirect the HTTPS traffic on my cisco router with WCCP V2

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved