<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dual S170 Install in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156015#M3085</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Install 1 WSA using this, get it working the way you want it to....&lt;/P&gt;&lt;P&gt;﻿&lt;A href="http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns982/sba_webSec_dg.pdf"&gt;http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns982/sba_webSec_dg.pdf&lt;/A&gt;﻿&lt;/P&gt;&lt;P&gt;﻿I'd suggest putting P1 and T1 on the 10.1.6.x network, put the managment connection anywhere else... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿Get the second box on the network with its own IP's, joined to the domain&lt;/P&gt;&lt;P&gt;Then get the configuration file off of the first box, edit out the unique network/AD stuff and upload it to the second box, and import it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then modify the WCCP acl on the firewall so as to not redirect traffic coming from the WSAs (otherwise you get loops)&lt;/P&gt;&lt;P&gt;It will look something like this:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ﻿access-list WCCP_Redirect extended deny ip any object-group InternalStuff&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list WCCP_Redirect extended deny ip host 10.1.6.11 any &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list WCCP_Redirect extended deny ip host 10.1.6.12 any &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list WCCP_Redirect extended permit ip object-group InternalStuff any&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ken &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Apr 2013 21:31:53 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2013-04-08T21:31:53Z</dc:date>
    <item>
      <title>Dual S170 Install</title>
      <link>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156014#M3084</link>
      <description>&lt;P&gt;I have received 2 - S170 appliances that I be will installing in our network and I would like some suggestions and help as to what would be the best way to implement them and the process of configuration. I currently have an ASA 5510 and a Catalyst 4507 with 5 - WS-X4648-RJ45V+E and 2 WS-X45-SUP6L-E modules in it. I have attached quick and dirty network layout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2013 19:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156014#M3084</guid>
      <dc:creator>NRVCS-cisco</dc:creator>
      <dc:date>2013-04-08T19:28:35Z</dc:date>
    </item>
    <item>
      <title>Dual S170 Install</title>
      <link>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156015#M3085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Install 1 WSA using this, get it working the way you want it to....&lt;/P&gt;&lt;P&gt;﻿&lt;A href="http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns982/sba_webSec_dg.pdf"&gt;http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns982/sba_webSec_dg.pdf&lt;/A&gt;﻿&lt;/P&gt;&lt;P&gt;﻿I'd suggest putting P1 and T1 on the 10.1.6.x network, put the managment connection anywhere else... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿Get the second box on the network with its own IP's, joined to the domain&lt;/P&gt;&lt;P&gt;Then get the configuration file off of the first box, edit out the unique network/AD stuff and upload it to the second box, and import it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then modify the WCCP acl on the firewall so as to not redirect traffic coming from the WSAs (otherwise you get loops)&lt;/P&gt;&lt;P&gt;It will look something like this:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ﻿access-list WCCP_Redirect extended deny ip any object-group InternalStuff&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list WCCP_Redirect extended deny ip host 10.1.6.11 any &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list WCCP_Redirect extended deny ip host 10.1.6.12 any &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list WCCP_Redirect extended permit ip object-group InternalStuff any&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ken &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Apr 2013 21:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156015#M3085</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2013-04-08T21:31:53Z</dc:date>
    </item>
    <item>
      <title>Dual S170 Install</title>
      <link>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156016#M3086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ken,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your quick response. When I setup the second one and have both of the running will they then load balance the traffic between the two?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 16:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156016#M3086</guid>
      <dc:creator>NRVCS-cisco</dc:creator>
      <dc:date>2013-04-09T16:13:44Z</dc:date>
    </item>
    <item>
      <title>Dual S170 Install</title>
      <link>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156017#M3087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, though the WCCP process on the firewall is what's doing the work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look at the WCCP service there's a radio button to pick if you base it on server address or client address.&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/7/4/134476-Capture.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Apr 2013 16:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/dual-s170-install/m-p/2156017#M3087</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2013-04-09T16:22:11Z</dc:date>
    </item>
  </channel>
</rss>

