Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Using WCCP on a Cisco ASA 5510 to route traffice to a BlueCoat

Posted on 2008-10-21
3
Medium Priority
?
9,078 Views
Last Modified: 2011-10-19
I am trying to utilize Bluecoat web filtering by using WCCP from a Cisco Firewall ASA 5510.  Are there any suggestions as to setup or configurations?  Attached you will find a simple diagram of my infrastructure.


Simple-Diagram-RevA.pdf
0
Comment
Question by:DomacVin
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 22791768
0
 
LVL 4

Assisted Solution

by:th3w01f
th3w01f earned 500 total points
ID: 22945436
Here is a working config.

I was reading the deployment guide for WCCP on the ASA and I found this.
WCCP redirect is supported only on the ingress of an interface. The only topology that the security appliance supports is when client and cache engine are behind the same interface of the security appliance and the cache engine can directly communicate with the client without going through the security appliance.

My testing showed this to be true; the only way I was able to get WCCP working on the ASA was to have the cache attached to the same interface that the client traffic entered the ASA (inside). There does not appear to be a way to get WCCP working for a device attached to a DMZ port when client traffic enterers the ASA from the inside interface.

ASA Configuration;

access-list wccp extended permit tcp host 192.168.31.32 any log debugging (192.168.31.32 is my client machine)
access-list wccp extended permit tcp 192.168.12.0 255.255.255.0 any log debugging (192.168.12.0/24 is my server subnet)
wccp 90 redirect-list wccp
wccp interface inside 90 redirect in
wccp interface SHNet 90 redirect in (this is the port that my server subnet is connected to)
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

572 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question