cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2233
Views
0
Helpful
7
Replies

What ports need to be open on Fw for Waas Communication--Urgent

bhisham Sharma
Level 1
Level 1

                   Hi All,

 

This product is new to need your help in configuring this. I am explaining the architecture below:-

We have a requirement to use WAVE-594-K9 Software Release 5.3.1 and in our Manila location and it will not talk to Waas central Manager in our client location instead client has installed one same model Wave-594 in PHX.

So now client has said it will only be used for caching contents and not for optimizing, they have some video training on web which will be passed through this wave and for making them highly/fastly available to agents they want to use this.

We have installed one Wave in Manila in application-accelerator mode and using PBR to redirect the desired traffic via Wave. As per our client Manila Wave will talk to PHX wave and PHX wave will get registered to Waas Manager in client network.

We have firewall between PHX wave & Manila wave, please let me know do we need to opened tcp/udp ports on FW for opening the communication between these two waves?

and what else i need to configure on Manila wave?

This is very urgent quick reply will be highly appreciated!!

Thanks!!

Bhisham

7 Replies 7

Kanwaljeet Singh
Cisco Employee
Cisco Employee

Hi Bhisham,

For communication between WAE and CM you should ensure that TCP 443 is allowed on FW in both directions. For WAAS discovery (WAE to WAE communication) you should ensure that TCP options are not removed by FW because by default FW's do that. I would suggest reading the below two links for more details:

https://supportforums.cisco.com/docs/DOC-15128

https://supportforums.cisco.com/docs/DOC-21885

Let me know if that helps.

Also, communication between primary and standby CM happens on TCP 8443.

Regards,

Kanwal

Thanks for the quick reply Kanwal!!

I checked with my team in PHX and we have Juniper FW in between these two Wave's, so what i understand from the links which you have shared.

In Manila Wave i need to configure that in Directed Mode and udp port 4050 needs to be opened bi-directionally on Juniper FW between IPs configured on wave devices.

In Manila we have 10.111.x.189 (Virtual-Blade IP) & 10.111.x.190 IPs & in PHX we 63.149.23.x & 63.149.23.x (VB) so from both IPs we required to open udp 4050 bi-directionally? Want to be sure before raising any request :-)

In PHX wave i am not sure whether we can configure that in directed mode and if it’s not then also it will work by opening port 4050 on FW Right?

In last our client was saying that Manila Wave will only be used as cache engine (VB is configured as content-engine) and it will download contents from PHX Wave (which is registered to CM at client side), what does it mean and do i need to do any special config on wave to achieve this?

I am very new to this device and lot of research on net confused me a lot, please don’t mind!!

Will wait for your reply then only i will raise request with FWteam.

Thanks,

Bhisham

Have opened udp 4050 bi-directionally on Juniper FW and when we initiated URL then seeing below PT in progress & after that PT No Peer

What does it mean? in our scenario we will use Manila Wave just for content engine and all contents will be downloaded from PHX wave.

Can somebody help me here!!!

FIS-SPRT-PHP-WAVE#sh statistics connection

Current Active Optimized Flows:                      0
   Current Active Optimized TCP Plus Flows:          0
   Current Active Optimized TCP Only Flows:          0
   Current Active Optimized TCP Preposition Flows:   0
Current Active Auto-Discovery Flows:                 0
Current Reserved Flows:                              10
Current Active Pass-Through Flows:                   1
Historical Flows:                                    0


Local IP:Port         Remote IP:Port        Peer ID           ConnType
10.x.x.199:58519   166.x.x.43:443     N/A               PT No Peer

166.x.x.43:80      10.x.x.199:58493   N/A           PT In Progress

Hi Bhisham,

PT means Pass through and PT no peer means this WAE cannot find WAE at other location. To TS this you need to see if other device is getting the packet sent by this device and if that packet has TCP options intact. WAE adds TCP options to let the other device know of it's existence and vice-versa.

Regards,

Kanwal

Thanks Kanwaljeet!!

I have configured our Manila Wave in Directed mode and other side wave (in PHX) that is not in directed mode, will this be an issue?

And how i can check TCP packets? means what cmd i need to run and what result should i expect. i know i am bothering you buddy but this product is new to me!!

Thanks,

Bhisham

Hi Bhisham,

No problem at all. The delay in response is due to me being busy on other things.

I read your PD again and it seems that you don't want optimization but just caching and communication between two WAE's, is that correct?

For WAAS to do optimization there should be two WAE's, one at each site. The WAE's should be able to discover each other (through TCP options) and then optimization will start.

Regards,

Kanwal

Thanks a lot Buddy your words have given me new hope!!!

Yes our client said this will only be used for Caching the video material.

Agents in Manils will access URL (Training video) and to make them highly available to agent wave has been deployed.

We have one Wave in Manila (Virtual blade is configured and using it as content engine) which will download those video contents from PHX wave  and this PHX wave is registered to Client Waas manager. this is the complete architecture!!

and configured PBR on our core switch to redirec the URLs via this Manila Wave..

Do i need to configure something on Virtual-session? like http proxy outgoing/incoming?

If you want to see i can attached the configuration!!

Thanks,

Bhisham