<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WCCP/WAAS - 7609 Hardware Based ACL issue in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458786#M49280</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Zach, I have sent these along to your email address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Jun 2010 16:53:03 GMT</pubDate>
    <dc:creator>j.shrewsbury</dc:creator>
    <dc:date>2010-06-22T16:53:03Z</dc:date>
    <item>
      <title>WCCP/WAAS - 7609 Hardware Based ACL issue</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458782#M49276</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying to get to the bottom of an issue we are seeing, but unfortunately are not sure where to start. We have (2) 7931's in the Main DC and (1) 7931 in the backup datacenter (BDC), and well over 20 remote sites running NM-WAE, OE574 and OE674. We had an issue over the weekend where traffic from several remote sites was redirected to our BDC due to power outage. When this occurred ldap authentication broke for these sites as well as other CIFS traffic for users that were already authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have seen this before and each time we have seen this we have noticed that the access-list on the core routers (7609) used for wccp starts matching (meaning the device is using software instead of hardware). The output below shows what we saw last time a site started experiencing issues such as, could not authenticate, could not open files, etc... We removed the site from the ACL and everything started working, of course we were no longer able to accelerate/optimize traffic going to the BDC once it was removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We saw this again this weekend. Several sites reported that they could not authenticate, when we investigated they were going to&amp;nbsp; BDC servers due to a power outage and the ACL's had started incrementing, once again we had to remove them in order for them to be able to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this time we suspect there might have been asymmetric routing occurring during the power outage, but do not have data to back that up at this time. Has anyone see this type of issue before? or can anyone confirm if asymmetric routing could cause this type of behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=================================&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;Extended IP access list WAAS_WCCP&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10 permit ip 192.168.2.0 0.0.0.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;20 permit ip any 172.25.2.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-spacerun: yes; font-family: Calibri; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---- cut for brevity ------&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 90 permit ip 10.1.64.0 0.0.0.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;100 permit ip any 10.1.64.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;110 permit ip 10.1.74.0 0.0.0.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;120 permit ip any 10.1.74.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;130 permit ip 10.1.130.0 0.0.0.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;140 permit ip any 10.1.130.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;150 permit ip 10.1.213.0 0.0.0.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;160 permit ip any 10.1.213.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;170 permit ip 10.1.236.0 0.0.3.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;180 permit ip any 10.1.236.0 0.0.3.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;190 permit ip 10.1.24.0 0.0.1.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;200 permit ip any 10.1.24.0 0.0.1.255 (1914211 matches)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;210 permit ip 10.1.48.0 0.0.0.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;220 permit ip any 10.1.48.0 0.0.0.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;===============================================&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2010 16:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458782#M49276</guid>
      <dc:creator>j.shrewsbury</dc:creator>
      <dc:date>2010-06-21T16:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP/WAAS - 7609 Hardware Based ACL issue</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458783#M49277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you see any indication in the WAAS logs that connections are failing due to a redirection loop?&amp;nbsp; The message in syslog.txt should look something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="margin: 0em;"&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;2009 Dec 11 16:08:17 NO-HOSTNAME kernel: %WAAS-SYS-3-900000:1.1.1.1:49114 - 2.2.2.2:22 - opt_syn_rcv: Routing Loop detected -&lt;BR /&gt;Packet has our own devid. Packet dropped.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming that WCCP is being handled in software on the the 7609, the counter incrementing in the output you provided would support that traffic isn't being seen symmetrically.&amp;nbsp; That in and of itself shouldn't cause the connections to fail (they should just be handled as pass-through), so I suspect there may be a redirection loop at your BDC site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide a topology diagram of your environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the WCCP in software issue on the 7609, can you provide the following output from IOS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; version&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip wccp&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;show ip wccp 61 service&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;show ip wccp 62 service &lt;/LI&gt;&lt;LI&gt;&lt;P&gt;show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip wccp 61&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; detail&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip wccp 62&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; detail&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;show ip wccp &lt;SERVICE&gt; internal (* NOTE: to enable this&amp;nbsp; command, add "service internal" to the&amp;nbsp; configuration first)&lt;/SERVICE&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;show tcam interface &lt;INTERFACE&gt; acl in ip (where &lt;INTERFACE&gt; is the name of each interface with WCCP enabled)&lt;/INTERFACE&gt;&lt;/INTERFACE&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; running-config&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zach&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 17:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458783#M49277</guid>
      <dc:creator>Zach Seils</dc:creator>
      <dc:date>2010-06-21T17:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP/WAAS - 7609 Hardware Based ACL issue</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458784#M49278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zach,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for responding. We do indeed see an error in the syslog.txt file showing a routing loop error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2010 Jun 20 10:59:26 waas-bdc kernel: %WAAS-SYS-3-900000: 192.168.128.134:18&lt;BR /&gt;44 - 192.168.210.217:139 - opt_syn_rcv: Routing Loop detected - Packet has our own&lt;BR /&gt; devid. Packet dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I cannot post configs/topology/command output, directly to netpro due to internal security restrictions, however I can send them directly to you if you have time to take a look? I would assume from the above that we need to be lookign at the wccp redirect configuration on the router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 19:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458784#M49278</guid>
      <dc:creator>j.shrewsbury</dc:creator>
      <dc:date>2010-06-21T19:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP/WAAS - 7609 Hardware Based ACL issue</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458785#M49279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Feel free to email me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:seils@cisco.com"&gt;seils@cisco.com&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; The commands I requested are from the router.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zach&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 10:33:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458785#M49279</guid>
      <dc:creator>Zach Seils</dc:creator>
      <dc:date>2010-06-22T10:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP/WAAS - 7609 Hardware Based ACL issue</title>
      <link>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458786#M49280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Zach, I have sent these along to your email address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 16:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/wccp-waas-7609-hardware-based-acl-issue/m-p/1458786#M49280</guid>
      <dc:creator>j.shrewsbury</dc:creator>
      <dc:date>2010-06-22T16:53:03Z</dc:date>
    </item>
  </channel>
</rss>

