Using WCCP on a Cisco ASA 5510 to route traffice to a BlueCoat

Posted on 2008-10-21
Last Modified: 2011-10-19
I am trying to utilize Bluecoat web filtering by using WCCP from a Cisco Firewall ASA 5510.  Are there any suggestions as to setup or configurations?  Attached you will find a simple diagram of my infrastructure.

Question by:DomacVin
LVL 79

Accepted Solution

lrmoore earned 125 total points
ID: 22791768

Assisted Solution

th3w01f earned 125 total points
ID: 22945436
Here is a working config.

I was reading the deployment guide for WCCP on the ASA and I found this.
WCCP redirect is supported only on the ingress of an interface. The only topology that the security appliance supports is when client and cache engine are behind the same interface of the security appliance and the cache engine can directly communicate with the client without going through the security appliance.

My testing showed this to be true; the only way I was able to get WCCP working on the ASA was to have the cache attached to the same interface that the client traffic entered the ASA (inside). There does not appear to be a way to get WCCP working for a device attached to a DMZ port when client traffic enterers the ASA from the inside interface.

ASA Configuration;

access-list wccp extended permit tcp host any log debugging ( is my client machine)
access-list wccp extended permit tcp any log debugging ( is my server subnet)
wccp 90 redirect-list wccp
wccp interface inside 90 redirect in
wccp interface SHNet 90 redirect in (this is the port that my server subnet is connected to)

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Radius Debug Error 16 91
How can I find which network appliance is acting as our gateway with the IP address? 4 51
ASA and ICMP 4 20
Connecting a New Subnet to Network 4 29
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question