A VPN is setup between the Branch RTR and DC Tier1 ASA. Branch WAE is registered with the natted IP of the core CM on Y.Y.Y.a. Branch users access the servers on their natted IPs Y.Y.Y.Y/16. At the Branch wccp redirection is setup at the Branch router while at the DC L2 redirection is configured on the Core SW.
I got the follwoing results from the tests I perfomed:
With the VPN at the DC terminated on Tier1 ASA, traffic is not being optimization and even dropped after activating wccp redirection. the Branch WAE is able to see the connection statistics with the peer wae while the Core WAE is able to the connections without the peer. In brief no optimization is occurring and traffic is being dropped.
With the VPN at the DC terminated on Tier2 ASA (matching traffic changed to X.X.X.X/16 -> Z.Z.Z.Z/16), optimization is wotking properly
With the VPN at the DC terminated on Tier1 ASA with identity nat configured on Tier2 ASA (Z.Z.Z.Z/16 - Z.Z.Z.Z/16), optimization is working properly
As a summary it seems it is something related to a NAT issue where the Branch WAE is seeing the initiated sessions as X.X.X.X/16 - Y.Y.Y.Y/16 while the core sees them as Z.Z.Z.Z/16 - X.X.X.X/16.
Considering that I cannot perform identity nat or terminate the VPN on Tier2 ASA, is there any solution to make the waas work with the servers natted to the Y.Y.Y.Y/16 range?
Introduction This article will help you understand the steps on how to
download the UCS licenses from the Cisco Systems website and then
installing it on the UCS. The redacted (blue lines) just covers up
certain numbers for privacy please do not take them...
Introduction This article will help you understand and educate the
customer on how to clear their "expired licenses"
(license-graceperiod-expired) from their UCS-M. If a customer just
purchased a license and needs a step by step guide on how to download
Introduction Prepositioning is a powerful tools on the WAAS platform but
it is not always easy to figure out why your jobs are failing when
trying to retrieve the files.Here is a method that should help you to
figure out the reason why they are not succes...