<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WCCP Service blocking DMVPN tunnels on Cisco ASR 1001 in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033853#M45796</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; There are no known issues with DMPVPN , WCCP and redirect applied for WCCP intercept. I would need a lot more data to analyze and to see what is wrong here. lets start with some simple questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1: What WCCP Client is running WCCP with ASR? (IronPort, ACNS ?)&lt;/P&gt;&lt;P&gt;2: Do this issue happened when WCCP is configured globally but no redirect applied on interfaces?&lt;/P&gt;&lt;P&gt;3: What TCP / UDP services are asked by WCCP Client for redirect&lt;/P&gt;&lt;P&gt;4: It is important to udnerstant where WCCP redirects are applied, on Tunnel interface or on Physical interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Better if you can provide a topology and show techs. but answers to above may hold the key. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ahsan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Sep 2012 16:00:06 GMT</pubDate>
    <dc:creator>ahskhan</dc:creator>
    <dc:date>2012-09-28T16:00:06Z</dc:date>
    <item>
      <title>WCCP Service blocking DMVPN tunnels on Cisco ASR 1001</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033851#M45794</link>
      <description>&lt;P&gt;I am trying to configure WCCP on&amp;nbsp; my Routers in a DMVPN environment, in order to setup WAN Optimization. The issue is as soon as i activate the WCCP service on my ASR or any router at my remote sites with either 'ip wccp 98 group-list ACL' or 'ip wccp 98 redirect-list ACL' (ive tried both with troubleshooting) the DMVPN tunnels quit communicating back to my ASR1001 (DMVPN Hub). As soon as i run a traceroute to what is specified in the ACLthe traffic gets lost. Anything not in that ACL is fine. This happens before i even apply it to an interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone ran into this before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, my ASR does have both these configured, as i've seen recommended in other forums:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no ip wccp variable-timers&lt;/P&gt;&lt;P&gt;ip wccp check services all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it is running wccp version 2 by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC couldnt figure it out and are digging for bugs, but i thought i'd jump on here as well. Any help is much appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 17:03:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033851#M45794</guid>
      <dc:creator>mshammans</dc:creator>
      <dc:date>2012-09-27T17:03:32Z</dc:date>
    </item>
    <item>
      <title>WCCP Service blocking DMVPN tunnels on Cisco ASR 1001</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033852#M45795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this WCCP redirection for WAAS?&amp;nbsp; This is the WAAS forum.&amp;nbsp; WAAS uses wccp 61 and 62 by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regardless,&lt;/P&gt;&lt;P&gt;wccp 98 is for http traffic on a port other than port 80, so I am assuming that this is a web caching or proxy server that you are redirecting to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me take a shot in the dark here, wccp 98 is redirecting non port 80 traffic both tcp and udp, DMVPN requires the following protocols&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; margin: 0px 0em 7px 0.25in; text-indent: -0.25in; background-color: #ffffff;"&gt;UDP Port 500—ISAKMP as source and destination&lt;/P&gt;&lt;P&gt; &lt;A name="wp38562" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; margin: 0px 0em 7px 0.25in; text-indent: -0.25in; background-color: #ffffff;"&gt;UDP Port 4500—NAT-T as a destination&lt;/P&gt;&lt;P&gt; &lt;A name="wp38563" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; margin: 0px 0em 7px 0.25in; text-indent: -0.25in; background-color: #ffffff;"&gt;IP Protocol 50—ESP&lt;/P&gt;&lt;P&gt; &lt;A name="wp38564" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; margin: 0px 0em 7px 0.25in; text-indent: -0.25in; background-color: #ffffff;"&gt;IP Protocol 51—AH (if AH is implemented)&lt;/P&gt;&lt;P&gt; &lt;A name="wp38565" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11.818181991577148px; margin: 0px 0em 7px 0.25in; text-indent: -0.25in; background-color: #ffffff;"&gt;IP Protocol 47—GRE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My guess would be that you need to exclude UDP ports 500 and 4500 from your ACL to ensure that you are not intercepting VPN tunnel traffic. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 15:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033852#M45795</guid>
      <dc:creator>Natalie Ramirez</dc:creator>
      <dc:date>2012-09-28T15:42:00Z</dc:date>
    </item>
    <item>
      <title>WCCP Service blocking DMVPN tunnels on Cisco ASR 1001</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033853#M45796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; There are no known issues with DMPVPN , WCCP and redirect applied for WCCP intercept. I would need a lot more data to analyze and to see what is wrong here. lets start with some simple questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1: What WCCP Client is running WCCP with ASR? (IronPort, ACNS ?)&lt;/P&gt;&lt;P&gt;2: Do this issue happened when WCCP is configured globally but no redirect applied on interfaces?&lt;/P&gt;&lt;P&gt;3: What TCP / UDP services are asked by WCCP Client for redirect&lt;/P&gt;&lt;P&gt;4: It is important to udnerstant where WCCP redirects are applied, on Tunnel interface or on Physical interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Better if you can provide a topology and show techs. but answers to above may hold the key. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ahsan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 16:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033853#M45796</guid>
      <dc:creator>ahskhan</dc:creator>
      <dc:date>2012-09-28T16:00:06Z</dc:date>
    </item>
    <item>
      <title>WCCP Service blocking DMVPN tunnels on Cisco ASR 1001</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033854#M45797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Beau - thanks, i'll give that a shot too and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ahsan - &lt;/P&gt;&lt;P&gt;1. Its a VM based WAN Optimization Client called Certeon. &lt;/P&gt;&lt;P&gt;2. Yes. This happens as soon as WCCP is enabled globally before i even apply it to an interface&lt;/P&gt;&lt;P&gt;3. No specific services are being sent during WCCP negotiation&lt;/P&gt;&lt;P&gt;4. Eventually we will apply WCCP to the inside physical interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology is standard on my sites with: Internet-&amp;gt;Router-&amp;gt;Switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 17:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-service-blocking-dmvpn-tunnels-on-cisco-asr-1001/m-p/2033854#M45797</guid>
      <dc:creator>mshammans</dc:creator>
      <dc:date>2012-09-28T17:28:03Z</dc:date>
    </item>
  </channel>
</rss>

