<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WCCP redirect question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738144#M496313</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is a correct statement for WCCP on an ASA firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the URL for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_wccp.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_wccp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA only supports both client and cache engine when they are connected from behind the same interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Oct 2011 02:42:18 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-10-07T02:42:18Z</dc:date>
    <item>
      <title>WCCP redirect question</title>
      <link>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738143#M496311</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm working on a WCCP issue with TAC and the TAC engineer told me that WCCP redirect only works if the redirected traffic (the permit ACL), the web-cache server, and the redirect interface are all on the same subnet.&amp;nbsp; After looking into this it seems like that is not the case, otherwise you'd need a different IronPort WSA for every different subnet, no?&amp;nbsp; Can anyone clarify what the actual requirements are?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738143#M496311</guid>
      <dc:creator>jnommensen</dc:creator>
      <dc:date>2019-03-11T21:35:02Z</dc:date>
    </item>
    <item>
      <title>WCCP redirect question</title>
      <link>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738144#M496313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is a correct statement for WCCP on an ASA firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the URL for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_wccp.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_wccp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA only supports both client and cache engine when they are connected from behind the same interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Oct 2011 02:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738144#M496313</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-10-07T02:42:18Z</dc:date>
    </item>
    <item>
      <title>WCCP redirect question</title>
      <link>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738145#M496315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep, I saw that.&amp;nbsp; But does that require that the entire redirect list be on the same subnet as clients and engine?&amp;nbsp; The customer says WCCP is working at a different site and that site's redirect list included several different subnets and are also on different subnets than the cache server.&amp;nbsp; Also in that case the clients and engine can communicate without going through the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Oct 2011 03:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738145#M496315</guid>
      <dc:creator>jnommensen</dc:creator>
      <dc:date>2011-10-07T03:26:39Z</dc:date>
    </item>
    <item>
      <title>WCCP redirect question</title>
      <link>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738146#M496316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, it doesn't need to be in the same subnet, as long as all those subnets when it reaches the ASA is connected to the same ASA interface as the cache-engine. You can have as many subnets as you like, however, it can only arrive on the same ASA interface as the cache engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eg:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Supported&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;10.10.10.0/24, 20.20.20.0/24, 30.30.30.0/24 are the clients, and connects to the ASA inside interface, and cache engine is also connected to the ASA inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Not Supported:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;10.10.10.0/24 - client, ASA inside interface, cache engine - ASA inside interface&lt;/P&gt;&lt;P&gt;20.20.20.0/24 - client, ASA DMZ-1 interface&lt;/P&gt;&lt;P&gt;30.30.30.0/24 - client, ASA DMZ-2 interface&lt;/P&gt;&lt;P&gt;In this case, only 10.10.10.0/24 is supported, the other 2 subnets aren't supported.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Oct 2011 03:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-redirect-question/m-p/1738146#M496316</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-10-07T03:43:56Z</dc:date>
    </item>
  </channel>
</rss>

