<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic This is an ASA limitation.  in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510277#M4752</link>
    <description>&lt;P&gt;This is an ASA limitation.&amp;nbsp; WCCP redirection is only supported when the client and the wccp device is behind the same ASA interface.&lt;/P&gt;&lt;P&gt;Are you able to utilize a second interface on the WSA and connect it to your Inside network?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2014 05:27:06 GMT</pubDate>
    <dc:creator>Vance Kwan</dc:creator>
    <dc:date>2014-07-29T05:27:06Z</dc:date>
    <item>
      <title>WCCP communication issue between ASA and WSA</title>
      <link>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510276#M4751</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to setup wccp for my guest wifi setup for internet connectivity. I can see the traffic is redirected as per the below output but internet is not working on client system.&lt;/P&gt;&lt;P&gt;In my setup I have Client connected through wifi has default gateway as ASA and WSA connected to another interface of the same ASA. Communication flow will be like this. Attached network diagram.&lt;/P&gt;&lt;P&gt;Client --&amp;gt; ASA (inside) ---&amp;gt; WSA (ASA DMZ interface) ---&amp;gt; Internet&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client subnet : 192.168.230.0/24&lt;/P&gt;&lt;P&gt;WSA inside : 10.231.47.0/26&lt;/P&gt;&lt;P&gt;WSA default route pointing to internet router.&lt;/P&gt;&lt;P&gt;============================&lt;/P&gt;&lt;P&gt;Below is the output from ASA.&lt;/P&gt;&lt;P&gt;sh wccp 90 detail&lt;/P&gt;&lt;P&gt;WCCP Cache-Engine information:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Web Cache ID: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10.231.47.6&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Protocol Version: &amp;nbsp; &amp;nbsp; &amp;nbsp;2.0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; State: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Usable&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Initial Hash Info: &amp;nbsp; &amp;nbsp; 00000000000000000000000000000000&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;00000000000000000000000000000000&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Assigned Hash Info: &amp;nbsp; &amp;nbsp;FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Hash Allotment: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;256 (100.00%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Packets Redirected: &amp;nbsp; &amp;nbsp;916&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Connect Time: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2d23h&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2014 14:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510276#M4751</guid>
      <dc:creator>Chirag Prajapati</dc:creator>
      <dc:date>2014-07-28T14:42:00Z</dc:date>
    </item>
    <item>
      <title>This is an ASA limitation. </title>
      <link>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510277#M4752</link>
      <description>&lt;P&gt;This is an ASA limitation.&amp;nbsp; WCCP redirection is only supported when the client and the wccp device is behind the same ASA interface.&lt;/P&gt;&lt;P&gt;Are you able to utilize a second interface on the WSA and connect it to your Inside network?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 05:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510277#M4752</guid>
      <dc:creator>Vance Kwan</dc:creator>
      <dc:date>2014-07-29T05:27:06Z</dc:date>
    </item>
    <item>
      <title>Hi,I have used both P1 &amp; P2</title>
      <link>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510278#M4753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have used both P1 &amp;amp; P2 for inside and internet connectivity. Not sure if i can use any other interface of WSA for this setup.&lt;/P&gt;&lt;P&gt;Any possibility to create subinterface on WSA?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chirag&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 06:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510278#M4753</guid>
      <dc:creator>Chirag Prajapati</dc:creator>
      <dc:date>2014-07-29T06:22:44Z</dc:date>
    </item>
    <item>
      <title>You can create a sub</title>
      <link>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510279#M4754</link>
      <description>&lt;P&gt;You can create a sub interface by going to the SSH and using the 'etherconfig' command, and adding a new interface and specify it to use a specific VLAN.&amp;nbsp; Not sure if it can work for your purposes though.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 16:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510279#M4754</guid>
      <dc:creator>Vance Kwan</dc:creator>
      <dc:date>2014-07-29T16:34:01Z</dc:date>
    </item>
    <item>
      <title>Thanks, I will try for</title>
      <link>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510280#M4755</link>
      <description>&lt;P&gt;Thanks, I will try for subinterface.&lt;/P&gt;&lt;P&gt;As per my setup, WSA(Prosy) will direct all internet connection towards internet instead of ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Still i need NAT on ASA for my client subnet? (I dont think its required Pl confirm)&lt;/P&gt;&lt;P&gt;2) Do i need to configure WPAD (Pac file hosting) on WSA? My understandin is all internet traffic will be redirected by ASA to WSA hence no need of proxy script, Pl confirm.&lt;/P&gt;&lt;P&gt;3) if second step is not required then how client internet request will redirect to proxy through wccp on ASA on port 83 on which proxy is running.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chirag&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 10:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wccp-communication-issue-between-asa-and-wsa/m-p/2510280#M4755</guid>
      <dc:creator>Chirag Prajapati</dc:creator>
      <dc:date>2014-07-30T10:42:58Z</dc:date>
    </item>
  </channel>
</rss>

