Solved

Using WCCP on a Cisco ASA 5510 to route traffice to a BlueCoat

Posted on 2008-10-21
3
8,920 Views
Last Modified: 2011-10-19
I am trying to utilize Bluecoat web filtering by using WCCP from a Cisco Firewall ASA 5510.  Are there any suggestions as to setup or configurations?  Attached you will find a simple diagram of my infrastructure.


Simple-Diagram-RevA.pdf
0
Comment
Question by:DomacVin
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 125 total points
ID: 22791768
0
 
LVL 4

Assisted Solution

by:th3w01f
th3w01f earned 125 total points
ID: 22945436
Here is a working config.

I was reading the deployment guide for WCCP on the ASA and I found this.
WCCP redirect is supported only on the ingress of an interface. The only topology that the security appliance supports is when client and cache engine are behind the same interface of the security appliance and the cache engine can directly communicate with the client without going through the security appliance.

My testing showed this to be true; the only way I was able to get WCCP working on the ASA was to have the cache attached to the same interface that the client traffic entered the ASA (inside). There does not appear to be a way to get WCCP working for a device attached to a DMZ port when client traffic enterers the ASA from the inside interface.

ASA Configuration;

access-list wccp extended permit tcp host 192.168.31.32 any log debugging (192.168.31.32 is my client machine)
access-list wccp extended permit tcp 192.168.12.0 255.255.255.0 any log debugging (192.168.12.0/24 is my server subnet)
wccp 90 redirect-list wccp
wccp interface inside 90 redirect in
wccp interface SHNet 90 redirect in (this is the port that my server subnet is connected to)
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now