06-25-2014 06:53 AM
Solved! Go to Solution.
09-15-2014 04:52 PM
Hi,
Remember that the ASA has the limitation that the clients and the WSA must be behind the same interface.
That VPN connection is L2L? Because if this is the case, WCCP redirection for the the VPN users must not be the best approach. Have you consider changing the proxy settings the browser? or an On-site solution for this remote site like WSA or Cloud Web Security?
Regards,
Luis Silva
09-15-2014 04:52 PM
Hi,
Remember that the ASA has the limitation that the clients and the WSA must be behind the same interface.
That VPN connection is L2L? Because if this is the case, WCCP redirection for the the VPN users must not be the best approach. Have you consider changing the proxy settings the browser? or an On-site solution for this remote site like WSA or Cloud Web Security?
Regards,
Luis Silva
10-02-2014 04:48 AM
Hi
I've alredy configured a WCCP redirection for all networks which are behind the same interface of an ASA and enabled proxy in remote hosts browsers (VPNs are L2L).
It works fine.
thank you for your answers
regards
09-16-2014 06:17 AM
Depending on which size/model your ASA FW for internetbreakout is, you could create a second context based firewall running on the same fysical hardware.
You could then have the diffent clients run out the same interface on FW context 2 and make WCCP redirect on FW context 1. See attached picture.
It all depends on if your ASA model support context based instances.
br,
M
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide