<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT and WCCP in Branch Office in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/nat-and-wccp-in-branch-office/m-p/1502461#M48770</link>
    <description>&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I have been looking for information relating to the configuration of WCCP in relation to standard client side NAT of private addresses. NAT order of operations gives some indication of how it works but I am wondering if there is any recommended guidelines to insure NAT and WCCP function correctly with the desired outcome being both non NAT and NATed traffic is accelerated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I have attached a diagram for reference.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;In Scenerio 1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Redirection is WCCP GRE/IP Forwarding, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The WAE is on its own subnet. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;A redirection list only redirects traffic between the DC and the BO public range (including NAT global) on the WAN interface (in and out). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Internal Public non-Nat'ed traffic shows up in the connection statistics optimized but the NAT global addresses show up on the DC WAE as "PT no Peer"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;In Scenerio 2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Redirection out of the WAN interface is moved to (in) the LAN interface of the router and the redirect ACL is expanded to include ANY-DC, DC-ANY ( including the private 172.x.x.x/xx range)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;This breaks NAT. I assume&amp;nbsp; because wccp occurs before NAT (inside-outside).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;From the information I have found I guess&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;1. Redirection should be oubound in one direction (WAN interface) if IP CEF is enabled ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;2. the WAE interface should be in NAT inside and the redirect ACL include the private inside range ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks for any advice.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Aug 2010 05:26:06 GMT</pubDate>
    <dc:creator>charindso</dc:creator>
    <dc:date>2010-08-18T05:26:06Z</dc:date>
    <item>
      <title>NAT and WCCP in Branch Office</title>
      <link>https://community.cisco.com/t5/application-networking/nat-and-wccp-in-branch-office/m-p/1502461#M48770</link>
      <description>&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I have been looking for information relating to the configuration of WCCP in relation to standard client side NAT of private addresses. NAT order of operations gives some indication of how it works but I am wondering if there is any recommended guidelines to insure NAT and WCCP function correctly with the desired outcome being both non NAT and NATed traffic is accelerated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I have attached a diagram for reference.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;In Scenerio 1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Redirection is WCCP GRE/IP Forwarding, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;The WAE is on its own subnet. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;A redirection list only redirects traffic between the DC and the BO public range (including NAT global) on the WAN interface (in and out). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Internal Public non-Nat'ed traffic shows up in the connection statistics optimized but the NAT global addresses show up on the DC WAE as "PT no Peer"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;In Scenerio 2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Redirection out of the WAN interface is moved to (in) the LAN interface of the router and the redirect ACL is expanded to include ANY-DC, DC-ANY ( including the private 172.x.x.x/xx range)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;This breaks NAT. I assume&amp;nbsp; because wccp occurs before NAT (inside-outside).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;From the information I have found I guess&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;1. Redirection should be oubound in one direction (WAN interface) if IP CEF is enabled ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;2. the WAE interface should be in NAT inside and the redirect ACL include the private inside range ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks for any advice.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2010 05:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/nat-and-wccp-in-branch-office/m-p/1502461#M48770</guid>
      <dc:creator>charindso</dc:creator>
      <dc:date>2010-08-18T05:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: NAT and WCCP in Branch Office</title>
      <link>https://community.cisco.com/t5/application-networking/nat-and-wccp-in-branch-office/m-p/1502462#M48771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I was trying to look for an answer to your question and this is the best I found to help you address your issue. I am not sure whether this will resovle your problem but defining proper order of IOS commands will certainly help here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For general reference, the usual Cisco IOS Software order of operation on software-based platforms is noted below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside to outside:&lt;BR /&gt;1. decryption&lt;BR /&gt;2. input ACL&lt;BR /&gt;3. inspect&lt;BR /&gt;4. routing&lt;BR /&gt;5. WCCP&lt;BR /&gt;6. Network Address Translation (NAT) inside to outside&lt;BR /&gt;7. crypto (check map and mark for encryption)&lt;BR /&gt;8. output ACL&lt;BR /&gt;9. inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside to inside:&lt;BR /&gt;1. decryption&lt;BR /&gt;2. input ACL&lt;BR /&gt;3. inspect&lt;BR /&gt;4. NAT outside to inside&lt;BR /&gt;5. WCCP&lt;BR /&gt;6. routing&lt;BR /&gt;7. crypto (check map and mark for encryption)&lt;BR /&gt;8. output ACL&lt;BR /&gt;9. inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you follow the NAT'ing rule above, it should work with NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS: If this addresses the issue, please mark it as &lt;STRONG&gt;Answered.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Aug 2010 19:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/nat-and-wccp-in-branch-office/m-p/1502462#M48771</guid>
      <dc:creator>Bhavin Yadav</dc:creator>
      <dc:date>2010-08-27T19:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT and WCCP in Branch Office</title>
      <link>https://community.cisco.com/t5/application-networking/nat-and-wccp-in-branch-office/m-p/1502463#M48772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Bhavin for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had looked at the NAT order of operation which does give some indication of how the config should be. If wccp occurs before NAT then configuring&amp;nbsp; redirection on the LAN side interface and configuring the WAE interface as NAT inside may work. I will test further but thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 11:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/nat-and-wccp-in-branch-office/m-p/1502463#M48772</guid>
      <dc:creator>charindso</dc:creator>
      <dc:date>2010-09-01T11:40:33Z</dc:date>
    </item>
  </channel>
</rss>

