cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1361
Views
5
Helpful
2
Replies

WAAS and firewalls

pthaynes
Level 1
Level 1

I have a WAAS deployment where there is a reasonable amount of traffic that goes through a firewall. Logically speaking the traffic goes from client to waas to remote waas then through a firewall to the server. I believe that the WAAS devices use IP options to communicate between each other.

My question is if the firewall (a Cisco ASA) blocks IP options will this prevent WAAS from working in my topology? I know there is an inspect command to allow WAAS to work through a firewall, but there is a memory leak in that command under 7.2(3) so I would like to avoid using it if I can.

1 Accepted Solution

Accepted Solutions

Zach Seils
Level 7
Level 7

Peter,

WAAS uses TCP option 33, not IP options. By default, ASA will remove unknown options from TCP packets. If the firewall is not sitting in between the WAEs (i.e. in the optimized path), then there shouldn't be any problem with the firewall scrubbing the options.

Regards,

Zach

View solution in original post

2 Replies 2

Zach Seils
Level 7
Level 7

Peter,

WAAS uses TCP option 33, not IP options. By default, ASA will remove unknown options from TCP packets. If the firewall is not sitting in between the WAEs (i.e. in the optimized path), then there shouldn't be any problem with the firewall scrubbing the options.

Regards,

Zach

Zach,

Thanks for your help (and the quick response). That was the answer I was hoping for.

Regards,

Peter