cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1320
Views
0
Helpful
6
Replies

transparent mode using L4 switch

horol_ironport
Level 1
Level 1

Hello,
I don't understand how can I use transparent mode using L4 switch (it's load-balancer, right?). I'm friendly with L4 switches, even though I can not imagine the topology and data flow.

I have two WSA boxes and I need configure active-backup model (therefore I can't use WCCP). I think, only one method is use WSA in forwarding mode and set 'proxy server' on clients.

Do you have any other idea?
What is better, one-arm, or routed mode for this situation?

martin

6 Replies 6

jowolfer
Level 1
Level 1

An L4 switch is one that can utilize PBR (policy based routing) to make routing decisions based on the port information.

So instead of sending traffic destined for an outside webserver on port 80 to the default route, it will send it to the WSA.

The configuration for this will differ depending on the particular L4 switch you are using. The configuration for active failover should be possible as well.

horol_ironport
Level 1
Level 1

Thank you Josh,
it's clear now for me.

martin

angfeglandagan
Level 1
Level 1

hi, is layer 4 switch better than wccp router?


and does WSA supports the web 2.0 applications?

khoanguy
Level 1
Level 1

the WSA should work fine with "web 2.0" application (it's still http/https), there might be issues with specific site where the app fails to authenticate from auth request, but a auth bypass policy can be implemented.

As for wccp vs L4 switch?

wccp is the better choice because when wccp fails, it fails open and users still have internet access (depend on admin config with FW) and you can load balance with multiple web cache.

L4 switch is policy based routing, very specific, not as flexible with changes in environment, unless a load-balance appliance is considered.

sir_yrwins
Level 1
Level 1

thank you . 
wow.. that it is getting more clear.
Do you guys have a example of how the L4 switch is configure. 
so I can see . and also you have to tell the WSA that you have a L4 (host) and receive all the traffic?

 

amojarra
Cisco Employee
Cisco Employee

Hello @sir_yrwins 

 

Maybe this could help : 

Microsoft Word - Tech Note ASA PBR for WSA.doc (cisco.com)

 

Regards,

Amirhossein Mojarrad

+++++++++++++++++++++++++++++++++++++++++++++++++++

++++        If you find this answer helpful, please rate it as such      ++++

+++++++++++++++++++++++++++++++++++++++++++++++++++

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: