WCCP redirection on ASA 5520

Unanswered Question
Jul 18th, 2011

I currently have WCCP redirection setup on my ASA 5520 to redirect to an ironport on ip address 10.11.1.10. The ASA inside ip is 10.11.1.1 and the ironport is setup for transparent redirection to that IP. This all works well and the Service Identifier i'm using for WCCP is 95.

I am now creating another WCCP group because on my ironport I have 4 interfaces so I wanted to use them for our admin network. So I created an ACL on the ASA for our admin traffic and I want to redirect that using Service Identifier 94 to the ip on the ironport of 10.11.1.22. But I can't get traffic to redirect, instead I see the following:

10ASA-LAN1(config)# sh wccp

Global WCCP information:

    Router information:

        Router Identifier:                   X.X.X.X

        Protocol Version:                    2.0

    Service Identifier: 94

        Number of Cache Engines:             0

        Number of routers:                   0

        Total Packets Redirected:            0

        Redirect access-list:                WCCP_redirect_to_ironport_Admin

        Total Connections Denied Redirect:   0

        Total Packets Unassigned:            0

        Group access-list:                   WCCP_Ironport_Admin

        Total Messages Denied to Group:      94

        Total Authentication failures:       0

        Total Bypassed Packets Received:     0

    Service Identifier: 95

        Number of Cache Engines:             1

        Number of routers:                   1

        Total Packets Redirected:            772571105

        Redirect access-list:                WCCP_redirect_to_ironport-Users

        Total Connections Denied Redirect:   0

        Total Packets Unassigned:            1487

        Group access-list:                   WCCP_IronportInterface_for_Users

        Total Messages Denied to Group:      0

        Total Authentication failures:       0

        Total Bypassed Packets Received:     0

You can see that ID group 94 is the one I'm having difficulty with. All messages are denied and I'm not sure why? I can still get out to the web, my traffic just isn't being redirected to the ironport?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Average Rating: 0 (0 ratings)
mirober2 Wed, 07/20/2011 - 13:15

Hi Justin,

The messages are being denied because there are no cache engines available for service group 94:

Number of Cache Engines:             0

I would suggest setting up a quick packet capture on the interface for all traffic to and from 10.11.1.22. This will give you a better idea of where the communication between the ASA and the WSA is failing.

-Mike

Actions

Login or Register to take actions

This Discussion

Posted July 18, 2011 at 1:00 PM
Stats:
Replies:1 Avg. Rating:
Views:2024 Votes:0
Shares:0
Tags: wccp, asa, ironport
+

Related Content

Discussions Leaderboard

Rank Username Points
1 7,861
2 6,140
3 3,170
4 1,473
5 1,446