Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


When the web proxy was deployed using WCCP, on Production datacenter and Redundancy datacenter, how can I set up an automatic or semi-automatic method for fail-over and fail-back?

Posted on 2016-10-13
Medium Priority
Last Modified: 2016-11-07
Hello team,

Now days we have deployed our organizational web proxy as explicit proxy.

Datacenter side:
We have two datacenters, one for production and one for redundancy. We have one web proxy on each datacenter. All users go to Internet through on proxy at a time (i.e. production web proxy in normal conditions).
Our core switch of the production DC is a Cisco Nexus 7000, and of the redundancy DC is a Cisco Catalyst 4500.
At mid days of november we will upgrade the core switch of the redundancy DC to a Cisco Nexus 9000.
Both datacenters are geographically dispersed.

User side:
By Active Directory GPO, we have set the proxy configuration on IE using a DNS name (A register) for the proxy hostname. We also manage the exceptions and other browser settings by GPO.
All the offices (headquarters and branches) are connected to the datacenter through WAN links.
On each office we have a Cisco ISR Router for the WAN link.

Current fail-over and fail-back methods:
When the production web proxy got offline or have to enter into maintenance, we manually change the IP address of the A register of the web proxy on the DNS for the IP address of the redundancy web proxy. And then we force the DNS zone replication between all the domain controllers through the entire network.

What we're planning to do:
We're planning to deploy the organizational web proxy using WCCP, in order to make it a transparent proxy.

Our question:
Would you provide us with:
  1. Examples of how to set up an automatic or semi-automatic method for fail-over and fail-back compatible with our Cisco communication infrastructure; and,
  2. A pros-cons comparison between explicit proxy and and transparent proxy (WCCP).
Question by:usaroc82
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
LVL 62

Expert Comment

ID: 41843934
You must use proxy.pac or DNS load balancing.

Author Comment

ID: 41843987
Hello gheist.

The problem we see when using PAC or WPAD files is that many desktop applications that take the proxy configuration from the IE does not understand or support PAC/WPAD file. So we got a lot of work doing like that.

As mentioned in my question we're moving to transparent proxy. At this time we have explicit proxy, and we use DNS for the fail over, and yes, it is pretty easy to do the fail-over and fail-back. So, what we need now is to know a method to do the fail-over and fail-back when using WCCP, considering that all the Internet Web traffic have to go through the production proxy (main DC), in normal conditions.
LVL 83

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1000 total points (awarded by participants)
ID: 41845107
most enterprises will use another management server that does this for you. F5 comes to mind immediately
 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

LVL 62

Assisted Solution

gheist earned 1000 total points (awarded by participants)
ID: 41845244
All applications using wininet.dll (Internet explorer settings) perfectly support WPAD and PAC
Problem applications are those which do not support any kind of javascript, there DNS balancing (well just multiple IPs for same host name) should perfrom better.
There are applications which will never fail over, here you can calculate F5 cost vs gain of them having 24x7 net connection.

Author Comment

ID: 41846122
Hello team. Maybe I have not been clear. Our two web proxies (the one in the production datacenter and the one on the redundancy datacenter) are deployed in explicit mode. We are going to deploy those two web proxies in transparent mode (by using WCCP) because we have been required to, not for getting a fail-over method, we already have a fail-over and a fail-back method (DNS round robin) in explicit mode.

As we will have our two web proxies deployed by using WCCP, we need to know how to force all the web traffic coming from all the offices (please check the attached diagram) to go to Internet through the production proxy alone, and having that, we need to know feasible methods for fail-over and fail-back between datacenters, regarding the transparent proxy.
LVL 62

Accepted Solution

gheist earned 1000 total points (awarded by participants)
ID: 41848885
Fallback from transparent proxy is bypass...
LVL 62

Expert Comment

ID: 41876848
Thats all options. If bypass is not an option then PAC/WPAD should be good approximation of 'transparent'

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question