Solved

Cisco ASA WCCP bypassing when going to certain websites

Posted on 2012-12-28
2
2,049 Views
Last Modified: 2012-12-28
I am running WCCP on a Cisco ASA5510 firmware 8.2.(1)11

My current configuration for WCCP is:
access-list wccp-server extended permit ip host 192.168.0.121 any
access-list wccp-traffic extended permit ip 192.168.0.0 255.255.255.0 any

wccp web-cache redirect-list wccp-traffic group-list wccp-server
wccp 70 redirect-list wccp-traffic group-list wccp-server
wccp interface inside web-cache redirect in
wccp interface inside 70 redirect in

I am running a Sophos web appliance on IP 192.168.0.121.  We're having issues with a particular website that runs a Java app that is being blocked by Sophos.  Sophos support has recommended that we modify the rule on the WCCP and bypass traffic to 209.223.80.74 and 209.223.80.73 on the Cisco from WCCP.

I have never created any exceptions like this before and would like some advice on how to configure this.

Thanks
0
Comment
Question by:tbeasley123
2 Comments
 
LVL 20

Accepted Solution

by:
rauenpc earned 500 total points
ID: 38728234
You should just need to add a couple deny statements above the permit on acl wccp-traffic. In the end the acl will look like:

access-list wccp-traffic extended deny ip 192.168.0.0 255.255.255.0 host 209.223.80.74
access-list wccp-traffic extended deny ip 192.168.0.0 255.255.255.0 host 209.223.80.73
access-list wccp-traffic extended permit ip 192.168.0.0 255.255.255.0 any

This will effectively deny traffic destined to those IP's from being redirected, but permit everything else to be redirected.
0
 

Author Closing Comment

by:tbeasley123
ID: 38728317
That did the trick.  Thanks!
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cisco ACS re-imaging with CIMC 2 46
port 69 error in solarwind TFTP server 1 42
DDOS against DYN 9 86
Cisco ASA NAT question. 9 25
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now