<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WCCP Questions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180163#M1066491</link>
    <description>&lt;P&gt;Francesco,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks so much for the reply. So to clarify, the WCCP server must be on the same subnet as the Layer 3 interface of the ASA that is doing the redirection? If the WCCP server resides on a different subnet reachable by a different interface of the ASA it wont work? Even if there are valid routes in the ASA to reach it?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2017 14:59:03 GMT</pubDate>
    <dc:creator>Craddockc</dc:creator>
    <dc:date>2017-09-05T14:59:03Z</dc:date>
    <item>
      <title>WCCP Questions</title>
      <link>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3179027#M1066487</link>
      <description>&lt;P&gt;Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were trying to roll out WCCP and I had some questions that I could not find the answers to online. After reading the following article, although helpful, I did have some questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/security-documents/asa-wccp-step-by-step-configuration/ta-p/3126636#How_wccp_works" target="_blank"&gt;https://supportforums.cisco.com/t5/security-documents/asa-wccp-step-by-step-configuration/ta-p/3126636#How_wccp_works&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) The article states the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The only topology that the adaptive security appliance supports is when client and cache engine are behind the same interface of the adaptive security appliance and the cache engine can directly communicate with the client without going through the adaptive security appliance."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;does this mean that the WCCP Server and the clients have to be on the same subnet as the ASA interface doing the redirecting? Or does this mean that only the WCCP server has to be on the same subnet as the interface doing the redirecting? In this depiction, the clients, the interface and the WCCP server are all on the same subnet, but I dont have a flat subnet like this. I have multiple vlans with multiple user subnets who all need to be redirected to the same WCCP server that may exist on a different subnet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;2) The paragraph also states that the WCCP Server must have the ability to reach the clients directly without having to traverse the ASA. Does this mean that once the traffic is redirected to the WCCP Server that the return traffic from the WCCP server cannot pass through the ASA again otherwise the flow will fail?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;My client networks get defaulted routed via vlan 125 (shown below) to the Inside Interface of the ASA for default route processing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;Client Networks:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;10.132.129.0/24 (vlan 132)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;10.134.129.0/24 (vlan 134)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;10.140.129.0.24 (vlan 140)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;10.144.129.0/24 (vlan 144)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;0.0.0.0 0.0.0.0 --&amp;gt; 10.125.0.1 (Inside Interface of the ASA)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;10.125.0.9 (vlan 125 interface on switch, used as transport vlan to route to firewall)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;In this case, does the wccp server have to be on the 10.125.0.0/24 network? And does the upstream switch connecting to the firewall have to be able to route the traffic back from the wccp server to the clients without going through the inside interface of the firewall again?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;Thanks for any help you can provide.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3179027#M1066487</guid>
      <dc:creator>Craddockc</dc:creator>
      <dc:date>2020-02-21T14:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP Questions</title>
      <link>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3179211#M1066489</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On asa the&amp;nbsp;limitation is that when you redirect the traffic to wccp server the packet has to go through the same interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If packets from your hosts arrive to your asa interface called inside, the wccp server has to be reachable from the inside interface otherwise it won't work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's not necessary that hosts and wccp server reside to the same subnet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The direct communication between wccp server and hosts is necessary because when a host tries to reach a website, the traffic is redirected to wccp and wccp server initiate the communication to outside with its own ip. When the internet server replies to wccp, the information is cached and forwarded directly to the host without passing&amp;nbsp;through asa. If you don't have a direct communication it won't work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and select as validated answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2017 02:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3179211#M1066489</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-09-02T02:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP Questions</title>
      <link>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180163#M1066491</link>
      <description>&lt;P&gt;Francesco,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks so much for the reply. So to clarify, the WCCP server must be on the same subnet as the Layer 3 interface of the ASA that is doing the redirection? If the WCCP server resides on a different subnet reachable by a different interface of the ASA it wont work? Even if there are valid routes in the ASA to reach it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 14:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180163#M1066491</guid>
      <dc:creator>Craddockc</dc:creator>
      <dc:date>2017-09-05T14:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP Questions</title>
      <link>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180164#M1066492</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has to be on the &lt;U&gt;&lt;STRONG&gt;same interface YES but not matter which subnet&lt;/STRONG&gt;&lt;/U&gt;.&lt;/P&gt;
&lt;P&gt;If the server is reachable from another interface it won't work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can have let's say, your inside subnet (interconnection from ASA to your core switch) and beside the switch you will have multiple vlans.. The server WCCP can reside on any on those subnets (vlans).&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 15:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180164#M1066492</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-09-05T15:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP Questions</title>
      <link>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180198#M1066493</link>
      <description>&lt;P&gt;Francesco,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Got it! So the traffic destined to the WCCP server MUST traverse the interface thats doing the redirecting to get there. Youre right, this situation doesnt always include the WCCP server being on the same vlan as the interface being used to redirect traffic but the route to the WCCP server must be taken over the same interface. Thanks again for your responses!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 16:21:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180198#M1066493</guid>
      <dc:creator>Craddockc</dc:creator>
      <dc:date>2017-09-05T16:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP Questions</title>
      <link>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180338#M1066494</link>
      <description>You're welcome</description>
      <pubDate>Tue, 05 Sep 2017 21:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-questions/m-p/3180338#M1066494</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-09-05T21:51:12Z</dc:date>
    </item>
  </channel>
</rss>

