<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WCCP Load balancing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707328#M194492</link>
    <description>&lt;P&gt;I've setup WCCP to redirect to 2 BlueCoat SGs using an access list that includes both proxies. &amp;nbsp;All 3 hosts, ASA gateway and 2 proxies are in the same VLAN. &amp;nbsp;I'm thinking this might be an issue with GRE and the routing ID, so I've modified the access list on the inside interface facing the proxies to allow GRE to the router ID of the ASA, which is a DMZ interface. &amp;nbsp;The default route on the proxies is pointing to an SVI on a switch in the same VLAN as the proxy interfaces and inside interface of the firewall. &amp;nbsp;However, I tried adding a route on the proxy to point to the ASA inside interface when trying to reach the router ID network, but no luck. &amp;nbsp;I ran a packet capture and see the ASA initiating GRE communication to the proxy, but never see anything in the return direction related to GRE. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see WCCP redirect hits&amp;nbsp;&lt;/P&gt;&lt;P&gt;MTAASA1(config)# sh wccp 70&lt;/P&gt;&lt;P&gt;Global WCCP information:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Router information:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Router Identifier: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.208.1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Protocol Version: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Service Identifier: 70&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Number of Cache Engines: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Number of routers: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Packets Redirected: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2901&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Redirect access-list: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;wccp-traffic&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Connections Denied Redirect: &amp;nbsp; 11&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Packets Unassigned: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;155&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Group access-list: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; wccp-servers&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Messages Denied to Group: &amp;nbsp; &amp;nbsp; &amp;nbsp;328&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Authentication failures: &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Bypassed Packets Received: &amp;nbsp; &amp;nbsp; 372&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list wccp-servers line 1 extended permit ip object-group BlueCoat_Servers any 0x7948c20d&lt;BR /&gt;&amp;nbsp;access-list wccp-servers line 1 extended permit ip host 10.14.6.8 any (hitcnt=84) 0x4e3c82a4&lt;BR /&gt;&amp;nbsp;access-list wccp-servers line 1 extended permit ip host 10.14.6.9 any (hitcnt=85) 0x959ad46f&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WCCP config:&lt;/P&gt;&lt;P&gt;wccp 0 redirect-list wccp-traffic group-list wccp-servers&lt;BR /&gt;wccp 70 redirect-list wccp-traffic group-list wccp-servers&lt;BR /&gt;wccp interface INSIDE 0 redirect in&lt;BR /&gt;wccp interface INSIDE 70 redirect in&lt;/P&gt;&lt;P&gt;access-list wccp-servers extended permit ip object-group BlueCoat_Servers any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:15:07 GMT</pubDate>
    <dc:creator>WILLIAM STEGMAN</dc:creator>
    <dc:date>2019-03-12T06:15:07Z</dc:date>
    <item>
      <title>WCCP Load balancing</title>
      <link>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707328#M194492</link>
      <description>&lt;P&gt;I've setup WCCP to redirect to 2 BlueCoat SGs using an access list that includes both proxies. &amp;nbsp;All 3 hosts, ASA gateway and 2 proxies are in the same VLAN. &amp;nbsp;I'm thinking this might be an issue with GRE and the routing ID, so I've modified the access list on the inside interface facing the proxies to allow GRE to the router ID of the ASA, which is a DMZ interface. &amp;nbsp;The default route on the proxies is pointing to an SVI on a switch in the same VLAN as the proxy interfaces and inside interface of the firewall. &amp;nbsp;However, I tried adding a route on the proxy to point to the ASA inside interface when trying to reach the router ID network, but no luck. &amp;nbsp;I ran a packet capture and see the ASA initiating GRE communication to the proxy, but never see anything in the return direction related to GRE. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see WCCP redirect hits&amp;nbsp;&lt;/P&gt;&lt;P&gt;MTAASA1(config)# sh wccp 70&lt;/P&gt;&lt;P&gt;Global WCCP information:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Router information:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Router Identifier: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.208.1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Protocol Version: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Service Identifier: 70&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Number of Cache Engines: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Number of routers: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Packets Redirected: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2901&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Redirect access-list: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;wccp-traffic&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Connections Denied Redirect: &amp;nbsp; 11&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Packets Unassigned: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;155&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Group access-list: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; wccp-servers&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Messages Denied to Group: &amp;nbsp; &amp;nbsp; &amp;nbsp;328&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Authentication failures: &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total Bypassed Packets Received: &amp;nbsp; &amp;nbsp; 372&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list wccp-servers line 1 extended permit ip object-group BlueCoat_Servers any 0x7948c20d&lt;BR /&gt;&amp;nbsp;access-list wccp-servers line 1 extended permit ip host 10.14.6.8 any (hitcnt=84) 0x4e3c82a4&lt;BR /&gt;&amp;nbsp;access-list wccp-servers line 1 extended permit ip host 10.14.6.9 any (hitcnt=85) 0x959ad46f&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WCCP config:&lt;/P&gt;&lt;P&gt;wccp 0 redirect-list wccp-traffic group-list wccp-servers&lt;BR /&gt;wccp 70 redirect-list wccp-traffic group-list wccp-servers&lt;BR /&gt;wccp interface INSIDE 0 redirect in&lt;BR /&gt;wccp interface INSIDE 70 redirect in&lt;/P&gt;&lt;P&gt;access-list wccp-servers extended permit ip object-group BlueCoat_Servers any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:15:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707328#M194492</guid>
      <dc:creator>WILLIAM STEGMAN</dc:creator>
      <dc:date>2019-03-12T06:15:07Z</dc:date>
    </item>
    <item>
      <title>I'm pretty sure you're</title>
      <link>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707329#M194496</link>
      <description>&lt;P&gt;I'm pretty sure you're looping because the traffic from the BlueCoats is being redirected back to them.&lt;/P&gt;&lt;P&gt;The redirect ACL should look like this:&lt;/P&gt;&lt;P&gt;access-list WCCP_Redirect extended deny ip any4 object-group MyInternalNetworks&lt;BR /&gt;access-list WCCP_Redirect extended deny ip host 172.16.15.10 any4&lt;BR /&gt;access-list WCCP_Redirect extended deny ip host 172.16.15.11 any4&lt;BR /&gt;access-list WCCP_Redirect extended permit ip object-group MyInternalNetworks any4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Line 1 keeps inbound traffic from being WCCPd, it is probably redundant.&lt;/P&gt;&lt;P&gt;Line 2 and 3 keep traffic from my WSA's from being WCCP&lt;/P&gt;&lt;P&gt;Line 4 allows outbound traffic to be WCCPd.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;right now you're only allowing your bluecoats outbound traffic to be WCCPd and not WCCPing any of your clients traffic at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 19:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707329#M194496</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2015-07-10T19:29:55Z</dc:date>
    </item>
    <item>
      <title> Ken, I think I'm following</title>
      <link>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707330#M194501</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ken, I think I'm following your suggestions, I just hadn't included the config that attests to that in my first post. &amp;nbsp;I'm denying my proxies from being redirected, and am redirecting one client for testing purposes, 10.15.150.1. &amp;nbsp;I added a deny any to 10.15.150.1 in the wccp-traffic acl, but it doesn't get any hits and I see the same results. &amp;nbsp;&lt;/P&gt;&lt;P&gt;MTAASA1(config)# sh access-li wccp-traffic&lt;BR /&gt;access-list wccp-traffic; 4 elements; name hash: 0xb7b6044d&lt;BR /&gt;access-list wccp-traffic line 1 extended deny ip object-group BlueCoat-WCCP_Inside_Exclude any 0xe3c512e5&lt;BR /&gt;&amp;nbsp; access-list wccp-traffic line 1 extended deny ip host 10.14.6.8 any (hitcnt=4) 0x7333b881&lt;BR /&gt;&amp;nbsp; access-list wccp-traffic line 1 extended deny ip host 10.14.6.9 any (hitcnt=2) 0x6eff2f4b&lt;BR /&gt;access-list wccp-traffic line 2 extended deny ip any host 10.15.150.1 (hitcnt=0) 0x706233ae&lt;BR /&gt;access-list wccp-traffic line 3 extended permit ip object-group BlueCoat-WCCP_Inside any 0x84c41e04&lt;BR /&gt;&amp;nbsp; access-list wccp-traffic line 3 extended permit ip host 10.15.150.1 any (hitcnt=9936) 0xa3e20aeb&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2015 07:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707330#M194501</guid>
      <dc:creator>WILLIAM STEGMAN</dc:creator>
      <dc:date>2015-07-12T07:59:00Z</dc:date>
    </item>
    <item>
      <title>Not sure this belongs in the</title>
      <link>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707331#M194504</link>
      <description>&lt;P&gt;Not sure this belongs in the Cisco Web Security forums as this pertains to the Cisco Ironport product, as well as Cisco Cloud Web Security.&amp;nbsp; This will probably get more attention in Firewall forums as the Firewall team supports WCCP on the FW.&lt;/P&gt;&lt;P&gt;But many things can go wrong at this point.&amp;nbsp; It'd probably be best if you started with a packet capture on your Blue Coat to see what it is doing.&lt;/P&gt;&lt;P&gt;In the packet capture, you should be looking for 2 things:&lt;/P&gt;&lt;P&gt;-TCP 3 way handshake (source IP client, destination IP web server) + HTTP request method/response&lt;/P&gt;&lt;P&gt;-TCP 3 way handshake (Blue COAT IP, destination IP webserver) + HTTP request method/response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2015 07:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707331#M194504</guid>
      <dc:creator>Vance Kwan</dc:creator>
      <dc:date>2015-07-12T07:59:01Z</dc:date>
    </item>
    <item>
      <title>Thanks Vance.  I've moved</title>
      <link>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707332#M194507</link>
      <description>&lt;P&gt;Thanks Vance. &amp;nbsp;I've moved this to the firewall group. &amp;nbsp;I've run some packet captures, and it looks to me like there might be a GRE issue. &amp;nbsp;I only see one side of the conversation, and although GRE is connectionless, I'm thinking I should still see some GRE traffic sourcing from both endpoints. &amp;nbsp;I do see back and forth traffic between ASA and proxy on UDP port 2048, which appears to the a common proxy port. &amp;nbsp;I don't see any HTTP traffic in the capture from the test users.&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 15:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-load-balancing/m-p/2707332#M194507</guid>
      <dc:creator>WILLIAM STEGMAN</dc:creator>
      <dc:date>2015-07-13T15:03:19Z</dc:date>
    </item>
  </channel>
</rss>

