<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using WCCP to redirect traffic to a Palo Alto Web Proxy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364223#M1124220</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If we want to use WCCP on a FTD firewall to redirect web traffic to a Palo Alto Web Proxy, is that possible?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know that Palo Alto doesn't support WCCP but since it would be a Cisco device doing the re-direction, does the receiving device need to support WCCP as well?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jan 2026 12:15:02 GMT</pubDate>
    <dc:creator>Chess Norris</dc:creator>
    <dc:date>2026-01-22T12:15:02Z</dc:date>
    <item>
      <title>Using WCCP to redirect traffic to a Palo Alto Web Proxy</title>
      <link>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364223#M1124220</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If we want to use WCCP on a FTD firewall to redirect web traffic to a Palo Alto Web Proxy, is that possible?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know that Palo Alto doesn't support WCCP but since it would be a Cisco device doing the re-direction, does the receiving device need to support WCCP as well?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 12:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364223#M1124220</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2026-01-22T12:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using WCCP to redirect traffic to a Palo Alto Web Proxy</title>
      <link>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364227#M1124222</link>
      <description>&lt;P&gt;As per i know both the devices need to support WCCP.&lt;/P&gt;
&lt;P&gt;what is the use case here, May be you can try PBR to re-route the traffic&lt;/P&gt;
&lt;DIV class="Y3BBE" data-sfc-cp="" data-hveid="CAEIBxAA" data-complete="true" data-processed="true"&gt;Since you cannot use WCCP, you should use one of the following standard methods to send traffic from your Cisco FTD to the Palo Alto proxy.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="Y3BBE" data-sfc-cp="" data-hveid="CAEIBxAA" data-complete="true" data-processed="true"&gt;&lt;SPAN class="T286Pc" data-sfc-cp="" data-complete="true"&gt;Policy-Based Routing (PBR):&amp;nbsp; Configure a PBR rule on the Cisco FTD (or an upstream router) to match web traffic (ports 80/443) and change the next-hop to the Palo Alto's interface IP. This is the most common substitute for WCCP as it does not require protocol negotiation.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;or you can use PAC or WPAD file if you like to Proxy explicitly&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 12:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364227#M1124222</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-01-22T12:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Using WCCP to redirect traffic to a Palo Alto Web Proxy</title>
      <link>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364229#M1124223</link>
      <description>&lt;P&gt;Thank you. Yes, in that case I guess we need to use PBR which should work.&lt;/P&gt;
&lt;P&gt;We have not decided yet if we should go for a transparent or explicit proxy solution. I guess there are advantages and disadvantages with both.&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 12:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364229#M1124223</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2026-01-22T12:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Using WCCP to redirect traffic to a Palo Alto Web Proxy</title>
      <link>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364232#M1124224</link>
      <description>&lt;P&gt;Sure always Pros and cons of every deployment, this is based on requirement of business.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 12:32:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364232#M1124224</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-01-22T12:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Using WCCP to redirect traffic to a Palo Alto Web Proxy</title>
      <link>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364729#M1124238</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256705"&gt;@Chess Norris&lt;/a&gt;&amp;nbsp;As for palo's proxy (transparent vs. explicit proxy), for transparent you need SSL/TLS decryption, just to keep that in mind.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Instead of doing PBR on the FTD, I would put Palo in-line (south or north) to FTD. In both cases, if all web traffic is inspected by Palo, on FTD I would configure prefiler policy for web traffic, to avoid double trouble / aka FTD will not perform any inspections above layer 4.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jan 2026 10:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5364729#M1124238</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-25T10:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Using WCCP to redirect traffic to a Palo Alto Web Proxy</title>
      <link>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5365054#M1124253</link>
      <description>&lt;P&gt;Thank you for the feedback. Much appreciated.&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jan 2026 10:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-wccp-to-redirect-traffic-to-a-palo-alto-web-proxy/m-p/5365054#M1124253</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2026-01-25T10:25:14Z</dc:date>
    </item>
  </channel>
</rss>

