<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD Pre-filter blocking WCCP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-pre-filter-blocking-wccp/m-p/5272696#M1120118</link>
    <description>&lt;P&gt;I am trying to insert an internal IPS on the inside interface of our ASA.&amp;nbsp; The ASA has a few WCCP tunnels to our WSA. We have an old 7125 Firepower that has no issues with passing WCCP through this setup, but the new FTD, does. I am leaning towards the Pre-filter.&lt;/P&gt;&lt;H3&gt;GRE Tunnel Limitations&lt;/H3&gt;&lt;P class=""&gt;GRE tunnel processing is limited to IPv4 and IPv6 passenger flows. Other protocols, such as PPTP and WCCP, are not supported within the GRE tunnel.&lt;/P&gt;&lt;P class=""&gt;I ran a packet capture on FMC both sides of the firewall to the WSA and I am not seeing any packets with the firewalls IP to the WSA IP, there should be consistent packets for the handshakes between them to keep the tunnel active. The only packets I see is between the WSA and external IP's, so some traffic is coming through, but no where near the volume of traffic expected.&lt;/P&gt;&lt;P class=""&gt;What happens is when I flip to the standby ASA that is interconnected to the FTD, and open a browser, I may be able to go to some bookmarked sites, but any new site will time out.&amp;nbsp; Log on the WSA shows the transition between firewalls, a timeout period, then a connection to the standby IP of the other ASA (failover pair), then switch back when failing back.&lt;/P&gt;&lt;P class=""&gt;1.184 is the active inside IP, 1.185 is the secondary IP for the inside.&lt;/P&gt;&lt;P class=""&gt;Tue Mar 18 12:12:18 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895411 ###handleISY.svc_print_all&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 60 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 0 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 80 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 70 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 60 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 0 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 80 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 70 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 60 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 0 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 80 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 70 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:ISY received from 192.168.1.184. (156 bytes)&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:ISY: cache '192.168.94.99' is local address.&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 60 ISY accepted: RcvID=741179 MCN=17&lt;/P&gt;&lt;P class=""&gt;This is the ONLY time I see the secondary IP show up in the logs, when flipping active to standby when the active is connected to FTD.&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;The FTD has a rule, only one rule actually, allow ANY to 192.168.98.99 and trust, and the reverse from 99 to ANY and trust, with logging begin and end.&amp;nbsp; I don't think that rule even gets touched.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Mar 2025 19:52:07 GMT</pubDate>
    <dc:creator>tahscolony</dc:creator>
    <dc:date>2025-03-18T19:52:07Z</dc:date>
    <item>
      <title>FTD Pre-filter blocking WCCP</title>
      <link>https://community.cisco.com/t5/network-security/ftd-pre-filter-blocking-wccp/m-p/5272696#M1120118</link>
      <description>&lt;P&gt;I am trying to insert an internal IPS on the inside interface of our ASA.&amp;nbsp; The ASA has a few WCCP tunnels to our WSA. We have an old 7125 Firepower that has no issues with passing WCCP through this setup, but the new FTD, does. I am leaning towards the Pre-filter.&lt;/P&gt;&lt;H3&gt;GRE Tunnel Limitations&lt;/H3&gt;&lt;P class=""&gt;GRE tunnel processing is limited to IPv4 and IPv6 passenger flows. Other protocols, such as PPTP and WCCP, are not supported within the GRE tunnel.&lt;/P&gt;&lt;P class=""&gt;I ran a packet capture on FMC both sides of the firewall to the WSA and I am not seeing any packets with the firewalls IP to the WSA IP, there should be consistent packets for the handshakes between them to keep the tunnel active. The only packets I see is between the WSA and external IP's, so some traffic is coming through, but no where near the volume of traffic expected.&lt;/P&gt;&lt;P class=""&gt;What happens is when I flip to the standby ASA that is interconnected to the FTD, and open a browser, I may be able to go to some bookmarked sites, but any new site will time out.&amp;nbsp; Log on the WSA shows the transition between firewalls, a timeout period, then a connection to the standby IP of the other ASA (failover pair), then switch back when failing back.&lt;/P&gt;&lt;P class=""&gt;1.184 is the active inside IP, 1.185 is the secondary IP for the inside.&lt;/P&gt;&lt;P class=""&gt;Tue Mar 18 12:12:18 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895411 ###handleISY.svc_print_all&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 60 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 0 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 80 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:19 2025 Debug: WCCP : - : [4294967295:-1] FLOW:Postponing SG 70 RA until 22895427&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 60 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 0 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 80 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895416 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:RQ received from 192.168.1.185.(80 bytes)...&lt;BR /&gt;Tue Mar 18 12:12:23 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 70 RQ accepted&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 60 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 0 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 80 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:send_HIA called&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 70 HIA sent to 192.168.1.184. (136 bytes) -- 1 ISY(s) outstanding&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### end of send_HIA&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:### Timestamp 22895417 ### middle of Wccp2HandleUdp&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:ISY received from 192.168.1.184. (156 bytes)&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:ISY: cache '192.168.94.99' is local address.&lt;BR /&gt;Tue Mar 18 12:12:24 2025 Debug: WCCP : - : [4294967295:-1] FLOW:SG 60 ISY accepted: RcvID=741179 MCN=17&lt;/P&gt;&lt;P class=""&gt;This is the ONLY time I see the secondary IP show up in the logs, when flipping active to standby when the active is connected to FTD.&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;The FTD has a rule, only one rule actually, allow ANY to 192.168.98.99 and trust, and the reverse from 99 to ANY and trust, with logging begin and end.&amp;nbsp; I don't think that rule even gets touched.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 19:52:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-pre-filter-blocking-wccp/m-p/5272696#M1120118</guid>
      <dc:creator>tahscolony</dc:creator>
      <dc:date>2025-03-18T19:52:07Z</dc:date>
    </item>
  </channel>
</rss>

