Cisco WAN :: 6500 / Setting Up Config To Have WCCP With Optimizer?

May 28, 2012

I'm setting up a config to have WCCP with Blue Coat WAN Optimizer. I have following sinple setup at the moment. Cisco 6500 <----> Firewall. How should my topology should be. Should I have whe WAN-Optimizer in between (in path of switch and firewall on the same VLAN) or have different vlan hanging off the 6500 and have WCCP redirect traffic?

View 2 Replies


ADVERTISEMENT

Cisco Switching/Routing :: WCCP On 6500 With Squid Proxy

May 19, 2012

I have been tasked to setup a Transparent Squid proxy and do redirection on  a Cisco 6513 Switch.I don't have access to the SQUID but think that my config below should be OK. We have setup a TEST user Vlan 13 . Any traffic from this destined for the we on 80 or 443 should be redirected. Vlan 10 is where the Squid proxy is sitting. [code]

View 3 Replies View Related

Cisco Firewall :: WCCP Support On FWSM Running 6500

Mar 10, 2011

What the support for WCCP on a FWSM running 4.0(7) is like, if there is any at all ?
 
I've read that the earliest PIX release that supports WCCP was 7.2(1) but I'm not sure how FWSM 4.0(7) aligns with the PIX versions.The only doc's i can find refrencing WCCP on a 6500 with FWSM is in the 6500 12.2 IOS guide.

View 1 Replies View Related

Cisco Switching/Routing :: 6500 - Acl Object Group With Wccp Redirect List

Dec 31, 2012

Can i use acl object group with wccp redirect list?My platforms are 6500 and isr 2921

View 1 Replies View Related

Cisco Switching/Routing :: 6500 STP Config On Port-channel Best Practice

Apr 3, 2012

I have 2 cisco 6500 in a VSS configuration , All of my Lan access switches are Stack switches and every Stack is connected to the VSS in a Port-channel so basically this is a loop free environment with no blocked ports .As a best practice I left STP in the Background (mstp)which enhanced cisco features to STP should I configure on the Aggregator (6500-VSS) and on the Access switches ?
 
Because of my topology I dont see the need in configuring most features like Uplink Fast and Backbone Fast but I have configured Loop Guard in addition to UDLD on the 6500 Aggregation Switches (on the port-channels).On the access ports I have configured portfast , bpduguard and guard root (seems a little pointless to configure the two...)
 
1.should I Leave UDLD on and get rid of LoopGuard and configure Guard root instead ? since LoopGuard cannot be configured with Guard Root.
 
2.should I configure GuardRoot on access ports if I already have BpduGuard on them ?
 
3.Is there anything I need to configure on the physicall interface or is everything configured on the port-channel since STP reguards port- channel as a single interface ?

View 4 Replies View Related

Cisco Switching/Routing :: 6500 How To Remove Ports From Config For Non-existent Line Card

Aug 6, 2012

On a number of 6500 chassis it appears that linecard 3 did exist at somepoint, but was removed.Problem is that when issuing the 'show int desc'  or  'show ip int brie'  the ports for the still appear, and indeed same with 'show run'  and  'show conf'.

View 1 Replies View Related

Cisco WAN :: Config Steps Required For Setting Up Fiber Link Between Two C3650v2

May 15, 2012

i would like to know the config. steps required for setting up fiber link between two cisco c3650v2

View 4 Replies View Related

TCP Optimizer Has Destroyed LAN Connection

Aug 3, 2011

Downloaded TCP Otimizer and ran it to improve my internet connection. It instantly killed my Wired Lan connection. I still can access internet via wireless connection. When I run a diagnose problem thingy it tells me to connect my cable to PC. It is connected.

View 3 Replies View Related

Cisco Switching/Routing :: L3 - Traffic Between Two Servers Leave Switch And Go Up To Optimizer

May 15, 2013

I have a setup where two servers are on the same network are plugged into a L3 switch.  Off that switch there is a WAN Optimizer device which is inline going to the MPLS cloud.  Also off that switch is an ASA firewall which leads to the Internet for the location.  When the two servers communicate with each other i would think the traffic would only go through the L3 switch between the two servers.  I am seeing traffic between these two servers hitting the WAN optimizer for some reason.  I would think being that these two servers are on the same network the traffic between them would stay at Layer 2.  routing is enabled on the switch because of other vlans on the network. What would cause the traffic between the two servers to leave the switch and go up to the optimizer?  Below is a diagram that shows the basic setup. 

View 6 Replies View Related

Cisco Switching/Routing :: 6500 - Setting An Interface Back To Defaults?

Feb 12, 2012

On a 6500 switch running ios 12.2, is there a way of clearing all config settings for a specified interface?  I want to avoid going through and having to type "no blah blah etc" for each line.

View 2 Replies View Related

Cisco Switching/Routing :: ASA 5505 Upload Config File Into Start-up Config

Apr 17, 2012

If i connected the latop to brand new out of the box ASA 5505 through consloe cable and i have a config file on this laptop from other ASA5505, is there anyway i can upload that config file into startup-config of this new ASA5505 through console cable, without using TFTP or FTP?

View 5 Replies View Related

Cisco WAN :: 2811 - Startup Config Is Not Copying To Running Config

Nov 15, 2009

I have a Cisco 2811 router and when I turn of the router the running config is lost. I have to the following to get the router running of the start-up config settings.

router#copy start-up running-config

View 9 Replies View Related

Cisco :: Squid And WCCP On ASA

Mar 26, 2011

So Im trying to learn a little bit more about WCCP so I thought I'd load up a centos VM and just install squid on it. With the base config running I can setup an explicit proxy by configuring my IE session to use the squid IP on port 3128. Proxy works fine and I see entries in the access log on the centos box. Now, since Im only running squid on the box Im going to change the listening port to 80 so I can transparent proxy with WCCP on my ASA. So I set the WCCP2 config on squid as shown.

View 10 Replies View Related

Cisco WAN :: Does 881 Support PBR And WCCP Protocols?

Oct 18, 2011

We have 881 routers and are planning on testing out some WAN optimizing hardware, we're told that our router needs to support PBR and WCCP protocols.  Will this router handle it?

View 3 Replies View Related

Cisco WAN :: WS-C3560X-48P Support WCCP?

Feb 28, 2013

if the Cisco Switches in my enviorment can support WCCP?

View 1 Replies View Related

Cisco Switching/Routing :: Upgrade 6500 Non Modular IOS To Normal 6500?

Dec 21, 2011

how can we upgrade 6500 non modular ios to normal 6500 ios?

View 5 Replies View Related

Cisco :: Roll Out A Bluecoat As A WCCP For A ASA 5520

May 25, 2012

I need to roll out a Bluecoat as a WCCP for a ASA 5520.

View 3 Replies View Related

Cisco :: WCCP Not Working With McAfee Web Gateway?

Oct 31, 2012

I'm using a Cisco AG3560 to run my wccp re-direct and have a McAfee for my web gateway. My IP for the web gateway is 10.1.252.19, and my wccp router is 10.1.3.10. For whatever reason the web gateway is able to see the router and the "here i am packets" but I cannot get anything to redirect to it. My wccp config is below.

ip wccp 51 redirect-list 120
!
interface Loopback0
ip address 10.1.254.17 255.255.255.255

[code]...

I have the Web Gatewy setup with process 51 and my router on the WG is 10.1.252.10.

View 1 Replies View Related

Cisco Firewall :: WCCP Redirection On ASA 5520

Jul 17, 2011

I currently have WCCP redirection setup on my ASA 5520 to redirect to an ironport on ip address 10.11.1.10. The ASA inside ip is 10.11.1.1 and the ironport is setup for transparent redirection to that IP. This all works well and the Service Identifier i'm using for WCCP is 95.I am now creating another WCCP group because on my ironport I have 4 interfaces so I wanted to use them for our admin network. So I created an ACL on the ASA for our admin traffic and I want to redirect that using Service Identifier 94 to the ip on the ironport of 10.11.1.22. But I can't get traffic to redirect.

View 1 Replies View Related

Cisco Infrastructure :: WCCP Configuration On 4507

Jun 16, 2012

I am trying to setup WCCP on our 4507. For some reason I cannot get this to work! The config I have tried is below. I can't figure out
 
ip wccp web-cache group-list IRONPORT-GROUPLIST
ip wccp source-interface GigabitEthernet2/24
!
Interface Vlan160

[Code].....

View 2 Replies View Related

Cisco WAN :: 3750 / WCCP Error IOS Version 12.2(46)SE?

Jul 19, 2011

When the following was issued:

ip wccp 0 redirect-list wccp_acl group-list 10 password 0 ourpassword
 
Received this error:

MDT: %COMMON_FIB-3-FIBIDBINCONS2: An internal software error occurred. WCCP:0 linked to wrong idb Loopback0 (xyz node name)
 
When the following was issued 10 minutes later:

ip wccp 70 redirect-list wccp_acl group-list 10 password 0 ourpassword
 
No error msg (but now wccp was active)WCCP appears to be working but we are ** having problems connecting ** with our websense (7.6) box via GRE.Websense is connected to the 6509 which is connected this 3750 switch.

View 2 Replies View Related

Cisco WAN :: 7200 - WCCP And CPU Utilization On Routers?

Jul 20, 2011

I’m currently trying to work out what router we need to do WCCP redirections to some WAN optimizers. We plan that there will 100-200Mbps worth of traffic that needs to be redirected.
 
We currently have a 7200 with NPE-G2 which already runs at 30% cpu without WCCP redirection. (From shaping and QoS.)
I’m worried that this will not be powerful enough for the redirections.
 
We would like to upgrade, but I want to do some research beforehand.I have looked everywhere and I cannot find any WCCP performance figures for the devices below.

-7200 with NPE-G2 -ASR1000 -3800 -3750 -6500 I am aware that the catalyst and the ASR can do the redirecting in hardware, so these means there is no real CPU hit until we exhaust  the TCM? We plan to use in bound redirection and the redirect ACL is only 20 lines.

View 1 Replies View Related

Cisco Application :: WCCP Web-cash On 2801 12.4(22)T

Nov 14, 2011

My problem is, it doesn’t seem like packets are making it to the linux/squid caching device, based on cache logs. Workstations that are being redirected in the router have no web browser access (they can ping 8.8.8.8 and google.com)
 
I have a linux box running squid successfully, which supports GRE WCCP. For the sake of argument, I will say that I am confident I have successfully configured that machine.
 
What’s really strange is this morning I came in and hind sight my test workstation looked like it may had restarted from an update. (maybe had internet access). The first thing I did was tweak the cisco config, as I was reading last night and saw:
 
“Be warned that if you are using NAT you MUST use the inbound interface otherwise the router only sees the NATted IP address as the source of your clients. This is bad, because the router is also therefore unable to see your cache engine and it will redirect the cache engine requests back upon itself.”
 
So I turned <ip cef> on and removed the <ip wccp web-cache redirect out> (I had in fa0/1 and out fa0/0 on overnight).
 
Then I proceeded to check the workstation and saw it had network access, I tested to see if it was in fact filtered by the proxy, and it was! (verified by cache logs aswell)
 
After some further successful testing, I made sure I saved any unsaved configuration changes, I rebooted the linux box and the router. Sadly the outcome was not good, I am back to where I was last night.
 
 
My router does routing/NAT and has two interfaces and is currently not running CEF
 
ip wccp web-cache redirect-list SQUID_PROXY
!
interface FastEthernet0/0
description WAN
ip address 1.2.3.4 255.255.255.248
ip nat outside
ip virtual-reassembly max-reassemblies 64
speed 100
full-duplex(code)

View 6 Replies View Related

Cisco Firewall :: WCCP Redirection On ASA 5540?

Apr 3, 2013

I have the following topology, WCCP is configurated on ASA, inside interface, lan users and websense machine are located on the same VLAN of my catalyst 3750G?I want to filter traffic on port 80 (www) to the users on the LAN side debug on the ASA show me that comunication between that device and Websense is OK,  there is Here_I_Am and I_See_You packets
  
WCCP-PKT:D00: Sending I_See_You packet to WEBSENSE_PROXY w/ rcv_id 0000015B
 WCCP-PKT:D00: Received valid Here_I_Am packet from WEBSENSE_PROXY w/rcv_id 0000015B
 WCCP-PKT:D00: Sending I_See_You packet to WEBSENSE_PROXY w/ rcv_id 0000015C
 WCCP-PKT:D00: Received valid Here_I_Am packet from WEBSENSE_PROXY w/rcv_id 0000015C
 WCCP-PKT:D00: Sending I_See_You packet to WEBSENSE_PROXY w/ rcv_id 0000015D
  
From show WCCP i saw that WCCP engine and ASA were detected
 
FW# sh wccp 
Global WCCP information:
Router information:
Router Identifier:                   200.X.X.X
Protocol Version:                    2.0

[code]....

View 5 Replies View Related

Cisco :: WCCP Not Working Between Squid (OpenBSD) And 3560?

Jul 26, 2012

I'm testing WCCP in a lab environment (Another checkbox on my way to CCIE).The setup- a WS-C3560-8PC switch running IOS 15.0(1), IP Services with crypto.- Two client computers connected by wire to the switch, running Windows 7.- A virtual machine in bridged mode running on one of the machines, running OpenBSD 5.0 with Squid 2.7 installed and running.- Everything in the same subnet: 192.168.163.0/24, the OpenBSD is at .5, the switch at .3 and functions as the default-gateway for the computers with no ICMP redirects (the real gateway is at .1 but the switch forwards everything).Squid seems to work, albeit inefficient, but that's not the issue.illing in the IP of the OpenBSD in the browser as proxy with the proper port works.Since the 3560 does only support WCCP over layer 2 adjacencies and masks, not hash buckets, I've configured these options on both the Squid and the 3560.

View 19 Replies View Related

Cisco WAN :: 2811 - WCCP Transparent Proxy Over DMVPN

Nov 20, 2010

I´m trying to config a wccp web-proxy in a ISR 2811 at branch network. I have an Iron Port at Head-Quarter.
 
The idea is that the users at branch network, transparently forward http traffic to Iron Port at Central-Office and from them go to Internet.
 
The communication between sites is over DMVPN. I have two GRE tunnels running OSPF.
 
The Iron Port is configured as wccp v2 transparent redirection with forwarding method L2 or GRE an retunr method as L2 or GRE.
 
I receive packets on the branch router "Here I Am" but it get a message on debug:

Nov 21 19:26:07.067 GMT-2: WCCP-EVNT:D10: Here_I_Am packet from 172.16.10.10 w/bad fwd method L2, received indirectly via Tunnel1Nov 21 19:26:07.067 GMT-2: WCCP-EVNT:D10: Here_I_Am packet from 172.16.10.10 with incompatible capabilites

Nov 21 19:46:07.035 GMT-2: WCCP-PKT:D10: Sending I_See_You packet to 172.16.10.10 w/ rcv_id 0000004F

View 1 Replies View Related

Cisco Firewall :: ASA 5512 WCCP Configuration With Web Filter

Oct 31, 2012

I am currently trying to enable WCCP between a Cisco ASA 5512 firewall and Barraccuda Webfilter 410 Vx applicance. The ASA firewall is running IOS version 8.6(1)2 and the Barracuda is funning firemware 6.0.0.013. Both the ASA and Barracuda are in the same network and can ping eachother. The ASA has several interfaces, outside, inside, data and dmz. The PCs and barracuda appliance are behind the data interface.  ASA data IP 172.16.18.1 Barracuda IP 172.16.18.40   All PCs in the 172.16.18.0/24 subnet use the ASA as the default gateway and should have web requests redirected to the Barracuda. 
 
Below are the respecive bits of my ASA config
 
interface GigabitEthernet0/0
description Management
speed 1000

[Code].....
 
I suspect my issue is that the ASA is generating a Router Identifier of 172.21.20.1 which is my inside network and the barracuda cannot communicate with it.  how I can get this working ?

View 3 Replies View Related

Cisco WAN :: WCCP HTTP Access Timeouts With 3750

Jan 29, 2012

I have a web cache server, and I redirect all the HTTP request to it using WCCP.
 
Everything works without a problem, however I have a monitoring system that every minute tests the access to some customer sites that are hosted inside our infra-strutcture.
 
As soon as I configured the WCCP the monitoring system complains of timeouts accessing those sites, about 20% of the requests start to fail (timeout).
 
I don't think it is the fault of the cache because in the WCCP ACL I exclude all traffic that comes from my monitoring system. However as soon as I turn of WCCP the monitoring system never ever gives timeouts accessing those sites.
 
Is there anything I should do in WCCP to tweak it? I have WCCP configured in my core gateway that is a CISCO 3750.

View 2 Replies View Related

Cisco Switching/Routing :: WCCP On 6509 Connection

Apr 5, 2012

Is there a way to use 2 redirects inbound on vlan 1?
 
int vlan 1
ip wccp 80 redirect in
ip wccp 81 redirect in
 
The reason for this is because we need the return traffic from the firewall to come in on group 81 and the source subnet will go out group 80.

View 1 Replies View Related

Cisco Switching/Routing :: 3750 12.2(46) WCCP Stack

Nov 21, 2011

I'm setting up a web cache using the wccp protocol on a Catalyst 3750 stack.
 
Probably missing something real simple here but when I from the global configuration mode are trying to enter the ip wccp command it just says "invalid input" from wccp. There is no such command.. should be supported on my device from IOS 12.2(37)

View 1 Replies View Related

Cisco Security :: Dual ASA 5520 WCCP Configuration?

Dec 6, 2012

I recently configured WCCP with a Sophos Web Filter on my network it works good but the problem I am having is I have two 5520s so I am directing the device to look at 2 different IP addresses and since the devices are in an Active/Passive failover.  The problem is because the second device is in a passive failover it is not responding which is throwing connection errors to my Sophos device.  I know you can have a single management connection for the ASA's but is there a way to have a single IP for the ASAs for the WCCP?

View 1 Replies View Related

Cisco Application :: 7200 - WCCP Router Identifier

Nov 19, 2011

I am getting the following message while trying to configure WCCP redirection on my 7200 router.
 
I have added this router to the routerlist of the WAE edge device. Ping is successful, but the following problem prevails.
 
NASCM-MPLS#show ip wccp
Global WCCP information:
Router information:

[Code]....

View 1 Replies View Related

Cisco Switching/Routing :: 6509 - WCCP For HTTPS

Feb 27, 2012

I am trying to enable wccp on 6509. Its works fine on port 80 but not with https (443). Also i have noticed when i use the following
 
ip wccp web-cache redirect in similarly adding to interface HTTP works. but when i use the service no 0 instead of web-cache even the HTTP stops working. wccp v2 is enabled in the switch. Both the source & the Squid server are in same V LAN.

View 9 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved