?
Solved

Using WCCP on a Cisco ASA 5510 to route traffice to a BlueCoat

Posted on 2008-10-21
3
Medium Priority
?
9,052 Views
Last Modified: 2011-10-19
I am trying to utilize Bluecoat web filtering by using WCCP from a Cisco Firewall ASA 5510.  Are there any suggestions as to setup or configurations?  Attached you will find a simple diagram of my infrastructure.


Simple-Diagram-RevA.pdf
0
Comment
Question by:DomacVin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 22791768
0
 
LVL 4

Assisted Solution

by:th3w01f
th3w01f earned 500 total points
ID: 22945436
Here is a working config.

I was reading the deployment guide for WCCP on the ASA and I found this.
WCCP redirect is supported only on the ingress of an interface. The only topology that the security appliance supports is when client and cache engine are behind the same interface of the security appliance and the cache engine can directly communicate with the client without going through the security appliance.

My testing showed this to be true; the only way I was able to get WCCP working on the ASA was to have the cache attached to the same interface that the client traffic entered the ASA (inside). There does not appear to be a way to get WCCP working for a device attached to a DMZ port when client traffic enterers the ASA from the inside interface.

ASA Configuration;

access-list wccp extended permit tcp host 192.168.31.32 any log debugging (192.168.31.32 is my client machine)
access-list wccp extended permit tcp 192.168.12.0 255.255.255.0 any log debugging (192.168.12.0/24 is my server subnet)
wccp 90 redirect-list wccp
wccp interface inside 90 redirect in
wccp interface SHNet 90 redirect in (this is the port that my server subnet is connected to)
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question