<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall with NetFlow and WCCP (Cisco WSA) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-with-netflow-and-wccp-cisco-wsa/m-p/3371760#M961321</link>
    <description>&lt;P&gt;I believe one problem with this setup is that the WSA sends the responds directly to the host and not to the ASA. If the ASA does not see the entire session it can't send netflow reports on that traffic.&lt;/P&gt;
&lt;P&gt;If the WSA can't use the cache for answering it will send out the request with its own IP and that traffic goes properly through the ASA and it is properly reported by netflow.&lt;/P&gt;
&lt;P&gt;One possible solution would be to activate netflow on other downstream devices, unfortunately WSA doesn't support netflow as far as I know.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116046-config-wccp-asa-00.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116046-config-wccp-asa-00.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCzv64580/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCzv64580/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Bogdan&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2018 09:45:15 GMT</pubDate>
    <dc:creator>Bogdan Nita</dc:creator>
    <dc:date>2018-04-24T09:45:15Z</dc:date>
    <item>
      <title>Firewall with NetFlow and WCCP (Cisco WSA)</title>
      <link>https://community.cisco.com/t5/network-security/firewall-with-netflow-and-wccp-cisco-wsa/m-p/3371023#M961320</link>
      <description>&lt;P&gt;I need some assitance with using NetFlow in combination with WCCP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a firewall enabled with WCCP and NetFlow exporting the flow to a NetFlow analyzer. The issue at hand is that all traffic that is redirected by the WCCP rule, shows as the IP from the Cisco WSA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to get more accurate data, in stead of the NetFlow result showing the WSA generating traffic?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-with-netflow-and-wccp-cisco-wsa/m-p/3371023#M961320</guid>
      <dc:creator>wijngaarden.m</dc:creator>
      <dc:date>2020-02-21T15:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall with NetFlow and WCCP (Cisco WSA)</title>
      <link>https://community.cisco.com/t5/network-security/firewall-with-netflow-and-wccp-cisco-wsa/m-p/3371760#M961321</link>
      <description>&lt;P&gt;I believe one problem with this setup is that the WSA sends the responds directly to the host and not to the ASA. If the ASA does not see the entire session it can't send netflow reports on that traffic.&lt;/P&gt;
&lt;P&gt;If the WSA can't use the cache for answering it will send out the request with its own IP and that traffic goes properly through the ASA and it is properly reported by netflow.&lt;/P&gt;
&lt;P&gt;One possible solution would be to activate netflow on other downstream devices, unfortunately WSA doesn't support netflow as far as I know.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116046-config-wccp-asa-00.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116046-config-wccp-asa-00.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCzv64580/?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCzv64580/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Bogdan&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 09:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-with-netflow-and-wccp-cisco-wsa/m-p/3371760#M961321</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2018-04-24T09:45:15Z</dc:date>
    </item>
  </channel>
</rss>

