Solved

moving wccp

Posted on 2013-05-26
13
251 Views
Last Modified: 2013-10-26
See attached for the Before and After network diagram.

I have wccp running, the Internet, and a Websnese connected to my 3750-core. The traffic for all vlans were directed to the Websnese appropriately.

I then moved the Websense and the Internet to the 3560. I also enabled wccp. But it only directs traffic for the wireless VLAN.

Any thoughts on why wccp does not working properly will be greatly apprciated.

Thanks
net-diagram.jpg
0
Comment
Question by:leblanc
  • 6
  • 6
13 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 39199469
You need to make sure all vlans have wccp rules directing the traffic to the new location.

Check the various location with wccp status/neighbor.
Wccp when it is unable to establish a connection allows all traffic out.
0
 
LVL 1

Author Comment

by:leblanc
ID: 39199699
yes all vlans have the redirecton in statement. I took the code from the working existing wccp on the 3750.
0
 
LVL 77

Expert Comment

by:arnold
ID: 39199886
Is the setup on the 3650 identical to that of the 3750?

the path from the 3650 to the websense might be running into an ACL.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 1

Author Comment

by:leblanc
ID: 39200124
They are not identical. But I moved the same wccp config from the 3750 to the 3560.

What do you mean by "the path from the 3650 to the websense might be running into an ACL. "? Thx
0
 
LVL 77

Expert Comment

by:arnold
ID: 39200140
You may have a restriction on the 3650 such that it can not reach the websense servers IP.

i.e. the IP for websense on the 3750 was 172.16.12.13

you changed the IP for websense to 172.18.16.34
the 3750 can reach this segment.

You then copied the same configuration to the 3650, but it can not have a network path to 172.18.16.34
traceroute/ping from the 3650 to 172.18.16.34.

You may have an Access list where the websense server is and it allowed the access from the management IP of the 3750 but there is no rule that allowed the 3650 access.
0
 
LVL 1

Author Comment

by:leblanc
ID: 39200218
Below are the configs that are relevant to our discussion. They are the "before" wccp config. For the "after" wccp config, I just took all the wccp code from the 3750 and moved it to the 3560.

3750-core before wccp move:
...
!
ip routing
ip wccp 0 redirect-list TRAFFIC_REDIRECT group-list 10
!
ip dhcp pool wireless-users
   network 10.10.100.0 255.255.255.0
   default-router 10.10.100.1
!
vlan 10
 name USERS
!
vlan 19
 name MANAGEMENT_VLAN
!
vlan 100
 name WIRELESS_USERS
!
interface GigabitEthernet1/0/1
 description TO 3560
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
...
!
interface GigabitEthernet1/0/8
 description UPLINK TO fw
 switchport access vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet1/0/10
 description TO WEBSENSE PORT1
 switchport access vlan 10
!
...
!
interface Vlan1
 shutdown
!
interface Vlan10
 ip address 10.10.1.1 255.255.255.0
 ip wccp 0 redirect in
!
interface Vlan19
 description MANAGEMENT VLAN
 ip address 10.10.19.1 255.255.255.0
 ip wccp 0 redirect in
!
interface Vlan100
 ip address 10.10.100.1 255.255.255.0
 ip wccp 0 redirect in
!
ip access-list extended TRAFFIC_REDIRECT
 deny   ip host 10.10.1.17 any              >>> THIS IS THE PORT 1 OF THE WEBSENSE
 deny   ip any 10.10.0.0 0.0.255.255
 permit ip 10.10.0.0 0.0.255.255 any
!
access-list 10 permit 10.10.1.17
!
ip route 0.0.0.0 0.0.0.0 10.10.1.40
...
end

-----------------------------------------------
3560 before wccp move:
...
!
ip routing
!
interface GigabitEthernet0/1
 switchport access vlan 10
 switchport mode access
!
...
!
interface GigabitEthernet0/23
 description TO WIRELESS CONTROLLER
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport mode trunk
!
interface GigabitEthernet0/24
 description TO 3750-core
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
...
!
interface Vlan1
 shutdown
!
interface Vlan10
 ip address 10.10.1.18 255.255.255.0
!
interface Vlan19
 ip address 10.10.19.18 255.255.255.0
!
interface Vlan100
 ip address 10.10.100.2 255.255.255.0
 no ip route-cache cef
 no ip route-cache
!
ip route 0.0.0.0 0.0.0.0 10.10.1.40
!
...
end
0
 
LVL 77

Expert Comment

by:arnold
ID: 39200227
Where is the after on 3650
ip access-list extended TRAFFIC_REDIRECT
 deny   ip host 10.10.1.17 any              >>> THIS IS THE PORT 1 OF THE WEBSENSE
 deny   ip any 10.10.0.0 0.0.255.255
 permit ip 10.10.0.0 0.0.255.255 any
access-list 10 permit 10.10.1.17

3750
Has wccp in each VLAN.
0
 
LVL 1

Author Comment

by:leblanc
ID: 39200261
Like I said, for the "after" 3560, just add:
ip access-list extended TRAFFIC_REDIRECT
 deny   ip host 10.10.1.17 any              >>> THIS IS THE PORT 1 OF THE WEBSENSE
 deny   ip any 10.10.0.0 0.0.255.255
 permit ip 10.10.0.0 0.0.255.255 any
access-list 10 permit 10.10.1.17

and

add  ip wccp 0 redirect in for each vlan.
0
 
LVL 77

Expert Comment

by:arnold
ID: 39200817
Did you also make configuration changes to the websense setup? to include the 3650 as a wccp client?
I think wccp on the websense side needs info on the router IP which is currently pointing to the 3750?
0
 
LVL 1

Author Comment

by:leblanc
ID: 39201063
Yes. wccp is working on the 3560 for vlan 100 but not for vlan 10.
0
 
LVL 77

Expert Comment

by:arnold
ID: 39202067
Look at your VLAN definition on the 3650 after the change
Look at your VLAN100 definition.
0
 
LVL 28

Accepted Solution

by:
mikebernhardt earned 500 total points
ID: 39202707
What is the default gateway of the web sense- did you change it when you moved it?

It looks to me like the 3560 is layer 2 between the websense and the 3750, correct? If so, then the WCCP needs to remain on the 3750 and the default gateway for the websense has to remain 10.10.1.1.
0
 
LVL 1

Author Comment

by:leblanc
ID: 39243353
yes the default gateway has changed to 10.10.1.18 on the Websense.
yes there is a trunk between the 3560 and the 3750. I will try your recommendation by configuring wccp on both the 3560 and the 3750.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question