<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA ASA WCCP Redirection for HTTPS traffic in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3820999#M8366</link>
    <description>&lt;P&gt;Retro&lt;/P&gt;</description>
    <pubDate>Sun, 17 Mar 2019 23:55:35 GMT</pubDate>
    <dc:creator>Territorymine345</dc:creator>
    <dc:date>2019-03-17T23:55:35Z</dc:date>
    <item>
      <title>WSA ASA WCCP Redirection for HTTPS traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3820134#M8365</link>
      <description>&lt;P&gt;My WSA appliances can service http/https traffic when configured in explicit forward mode (no WSA https proxy enabled).&lt;/P&gt;
&lt;P&gt;However I am unable to get Transparent mode https redirection to work unless I enable https proxy mode on the WSA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An ASA is doing the WCCP redirection for http/https traffic. It appears that http redirection works as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could somebody explain why http/https work in explicit proxy mode without https proxy enabled on the WSA and is there a way to get https rwccp redirection to work in Transparent mode without https proxy enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ian&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 12:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3820134#M8365</guid>
      <dc:creator>iwearing</dc:creator>
      <dc:date>2019-03-15T12:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: WSA ASA WCCP Redirection for HTTPS traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3820999#M8366</link>
      <description>&lt;P&gt;Retro&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 23:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3820999#M8366</guid>
      <dc:creator>Territorymine345</dc:creator>
      <dc:date>2019-03-17T23:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: WSA ASA WCCP Redirection for HTTPS traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3830071#M8404</link>
      <description>&lt;P&gt;f you can make logs or images available, it is easier to help you.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 16:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3830071#M8404</guid>
      <dc:creator>Josiane de Barros Silva</dc:creator>
      <dc:date>2019-04-01T16:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: WSA ASA WCCP Redirection for HTTPS traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3835515#M8440</link>
      <description>&lt;P&gt;So this is the one thing I have struggled with the WSA/ASA WCCP pair for a while. I recently found out that in the ASA WCCP implementation HTTPS DNS traffic is not forwarded to the WSA. Without the DNS information redirected the WSA is unable to filter or see the traffic for HTTPS. So this limitation is actually the ASA, and impacts any ASA WCCP compatible proxy solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There may also be a way to change this default ASA behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 23:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3835515#M8440</guid>
      <dc:creator>Paul Cardelli</dc:creator>
      <dc:date>2019-04-09T23:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: WSA ASA WCCP Redirection for HTTPS traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3835524#M8441</link>
      <description>Https dns traffic is still port 53, isnt it? Possibly just add that to the wccp and proxy config?&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Apr 2019 23:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3835524#M8441</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2019-04-09T23:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: WSA ASA WCCP Redirection for HTTPS traffic</title>
      <link>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3836067#M8442</link>
      <description>&lt;H4&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The following is adapted from deployment information from another cache solution. It begins to explain some of the limitations of Cisco's implementation of WCCP on the ASA's the first one also applies to ISRs. I was not able to find the same information on a Cisco site, but through my own testing and experience these limitations appear to be accurate. Especially for guest networks were the only information you can log/filter on is the DNS. These limitations appear to be by design, likely to allow other ASA features to function properly.&lt;/FONT&gt;&lt;/H4&gt;&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;&lt;H4&gt;Limitations and Requirements of a WCCP Deployment With an ASA&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;The only topology that the adaptive security appliance (ASA) supports is when both the client and the cache engine are behind the same interface of the ASA and the cache engine can directly communicate with the client without going through the adaptive security appliance.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;Due to the Cisco ASA limitations on redirecting DNS responses, the&amp;nbsp;cache engine is not able to log all HTTPS traffic. The only traffic that can be logged is HTTPS traffic that is being inspected/monitored and the HTTPS URLs that are blocked.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 10 Apr 2019 14:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-asa-wccp-redirection-for-https-traffic/m-p/3836067#M8442</guid>
      <dc:creator>Paul Cardelli</dc:creator>
      <dc:date>2019-04-10T14:43:49Z</dc:date>
    </item>
  </channel>
</rss>

