Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA WCCP Question

Hi all,

Hopefully a quick question...

When it comes to web-cache redirection, the ASA's only supported method is via GRE encapsulation.

If my proxy server is in the same subnet as the ASA's 'INSIDE' interface, will the ASA's still be able to setup a GRE tunnel between itself and the server?

For several reasons the web-cache server (Blue Coat ProxySG 900-20) has to stay within this subnet...

Regards,

Brett

Everyone's tags (4)
4 REPLIES

Re: ASA WCCP Question

ASA currently supports WCCP only on the same interface (it should be inside interface) and only in the same subnet as it's inside interface. So your setup is only one possible for ASA and everything should work fine.

New Member

ASA WCCP Question

Hmm...

Is the 'same subnet' part true? My understanding was that the server and client worksations had to be 'under' the same interface.

FROM CISCO - "The only topology that the security appliance supports is when client and cache engine are behind the same interface of the security appliance and the cache engine can directly communicate with the client without going through the security appliance."

If they HAD to be within the same subnet, would that remove the need for a GRE tunnel?

Brett

ASA WCCP Question

Actually now i'm not 100% sure that they should be on the same subnet, but they 100% will work, when in the same subnet. As for the GRE it's the only one possible way for ASA to connect to the webcache engine. Surely when in the same subnet it's not required technically, but it's ok for GRE to work between hosts on the same subnet.

New Member

Re:ASA WCCP Question

Thanks Andrew,

Cisco aren't very informative with the WCCP functionality on the ASAs. I just want to make sure my topology will work before writing up project proposals and promising the business all this functionality. Otherwise the WCCP config on both the ASAs and the Blue Coat proxy seems very straight forward...

Brett

185
Views
0
Helpful
4
Replies