<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA redundancy and WCCP questions in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185834#M3237</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The WCCP protocol allows for automatic detection of all connected devices, both proxies and routers/firewalls/switches. When configuring WCCP with multiple WSAs, they're all in the WCCP cluster, with the router doing the load balancing beween the detected proxies. From what I've seen, you can't configure an active/passive scenario.&lt;BR /&gt;&lt;BR /&gt;As you mentioned , WSAs don't support clustering seen in ESAs. You could use a M-series box to provide central management and reporting for multiple WSAs in your enviromment.&lt;BR /&gt;&lt;BR /&gt;Regarding VRFs: WSAs support IP spoofing, which allows you to send out requests with the client's instead of WSA's external address. You could perform PAT of multiple addresses on the edge router/firewall to send the requests out with a different IP address for each VRF for example.&lt;BR /&gt;&lt;BR /&gt;I don't think you can fully disable the explicit proxy on the WSA. You can set up a firewall rule to prevent direct client access to the proxy ports..&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 09 Mar 2013 22:53:17 GMT</pubDate>
    <dc:creator>stojanr</dc:creator>
    <dc:date>2013-03-09T22:53:17Z</dc:date>
    <item>
      <title>WSA redundancy and WCCP questions</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185833#M3236</link>
      <description>&lt;P&gt;Hello! My customer bought a pair of S370 WSA prior to deployment planning. I need to deploy both of them into existing network and I'd like to ask few questions with somebody who knows how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. As I know from manuals, WSA doesn't support any clustering but I'd like to use both of my S370 for redundancy. I'm planning to use WCCP only, no explicit proxy mode will be used. What methods can I use to deploy redundant WCCP cache on pair of WSA? If it possible, I'd prefer to use something like Active\Passive but not load balancing scheme. Does it have Centralized management feature like ESA to share configs between devices?&lt;/P&gt;&lt;P&gt;2. I have fusion router which "mixes" traffic from different vrf. Is it possible to configure router such way that every vrf(which corresponds every interface and different subnets) will be seen with its own ip address in internet or all of them will be using just WSA's address like in explicit proxy mode?&lt;/P&gt;&lt;P&gt;3. When I tried to test my WSA in explicit proxy mode prior to configuring WCCP, I found out that I can use it as a proxy without any authentication, just setting it's address and port in my browser. How can I disable explicit proxy mode or set any authentication(no LDAP or NTLM) to prevent unauthorized access to using my proxy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm newbie with IronPorts so I will appreciate any help including links to manuals &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2013 19:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185833#M3236</guid>
      <dc:creator>Andrey Kornienko</dc:creator>
      <dc:date>2013-03-04T19:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: WSA redundancy and WCCP questions</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185834#M3237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The WCCP protocol allows for automatic detection of all connected devices, both proxies and routers/firewalls/switches. When configuring WCCP with multiple WSAs, they're all in the WCCP cluster, with the router doing the load balancing beween the detected proxies. From what I've seen, you can't configure an active/passive scenario.&lt;BR /&gt;&lt;BR /&gt;As you mentioned , WSAs don't support clustering seen in ESAs. You could use a M-series box to provide central management and reporting for multiple WSAs in your enviromment.&lt;BR /&gt;&lt;BR /&gt;Regarding VRFs: WSAs support IP spoofing, which allows you to send out requests with the client's instead of WSA's external address. You could perform PAT of multiple addresses on the edge router/firewall to send the requests out with a different IP address for each VRF for example.&lt;BR /&gt;&lt;BR /&gt;I don't think you can fully disable the explicit proxy on the WSA. You can set up a firewall rule to prevent direct client access to the proxy ports..&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Mar 2013 22:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185834#M3237</guid>
      <dc:creator>stojanr</dc:creator>
      <dc:date>2013-03-09T22:53:17Z</dc:date>
    </item>
    <item>
      <title>WSA redundancy and WCCP questions</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185835#M3238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The current versions of WCCP do not support fail over or active/passive, yet.&amp;nbsp; There are plans for WCCP to support that down the road.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Christian Rahl&lt;/P&gt;&lt;P&gt;Customer Support Engineer&lt;/P&gt;&lt;P&gt;Cisco Web Content Security Appliance&lt;/P&gt;&lt;P&gt;Cisco Technical Assistance Center RTP &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 22:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185835#M3238</guid>
      <dc:creator>Christian Rahl</dc:creator>
      <dc:date>2013-03-13T22:47:47Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185836#M3239</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;WSAs don't support clustering seen in ESAs&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;Is this answer still valid? Any update on the technology?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;From my searches i've understood &amp;nbsp;that on WSA&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;1- Failover group for explicit proxy continium,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;2- SMA for central logging and management&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Calibri, sans-serif"&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;will make me achieve&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Calibri, sans-serif"&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;1- no outages on explicity proxy&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Calibri, sans-serif"&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;2- same policies on each boxes managed from central location.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Calibri, sans-serif"&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Calibri, sans-serif"&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;Am i correct?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Calibri, sans-serif"&gt;&lt;SPAN style="font-size: 14.6667px;"&gt;Kind regards&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 18:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185836#M3239</guid>
      <dc:creator>sadik.sener1</dc:creator>
      <dc:date>2017-06-19T18:47:52Z</dc:date>
    </item>
    <item>
      <title>Correct, there is no</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185837#M3240</link>
      <description>&lt;P&gt;Correct, there is no equivalent "clustering" on the WSA.&amp;nbsp; No change in the technology.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You're correct on your second 2 statements also.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;SMA also lets you centralize reporting...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 19:00:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185837#M3240</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2017-06-19T19:00:18Z</dc:date>
    </item>
    <item>
      <title>Hi Ken,</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185838#M3241</link>
      <description>&lt;P&gt;Hi Ken,&lt;/P&gt;
&lt;P&gt;sorry for proceeding with questions everytime. I can not find proper documentation online and can not make sure.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My new question is, i want to deploy explicit proxy ha in active active mode.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I know the builtin ha works in active passive from examples. Does it also work active active?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If not, i am gonna proceed with a load balancer as a distribution point in order to utilize both boxes.&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;Sadik&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 20:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185838#M3241</guid>
      <dc:creator>sadik.sener1</dc:creator>
      <dc:date>2017-06-28T20:29:52Z</dc:date>
    </item>
    <item>
      <title>Basically, the intention of</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185839#M3242</link>
      <description>&lt;P&gt;Basically,&amp;nbsp;the intention of the built-in HA is for it to transparently move the proxy address to a box that's up... its really intended for active-passive installs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you want active-active, you don't need to use the built-in HA&lt;/P&gt;
&lt;P&gt;There are a few ways to get the data flow to the boxes:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;1. a web load balancer&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;2. a pac file (I don't know the syntax, but I do know that you can specify multiple proxies)&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 20:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/2185839#M3242</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2017-06-28T20:47:31Z</dc:date>
    </item>
    <item>
      <title>WSA redundancia y preguntas WCCP</title>
      <link>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/3210674#M7549</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;I would like to know if there is any document that shows the step by step to perform the configuration of load balancing and HA for a WSA and vWSA through WCCP in a Cisco ASA Firewall.&lt;/P&gt;
&lt;P&gt;On the other hand I have the doubt when this type of configuration is done as it is done so that when making some configuration change replicate in the two WSA (physical WSA and virtual vWSA).&lt;/P&gt;
&lt;P&gt;Thank you in advance for the collaboration and help you give me.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 20:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-redundancy-and-wccp-questions/m-p/3210674#M7549</guid>
      <dc:creator>andresmen598</dc:creator>
      <dc:date>2017-11-03T20:08:22Z</dc:date>
    </item>
  </channel>
</rss>

