<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WCCP pass through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876792#M973322</link>
    <description>&lt;P&gt;i want to configure a WCCP in my core router and I have an ASA firewall between my Router and my cache engines and it's preventing the WCCP traffice to go though what is the solutions for this ,,, thanks for your helping &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:28:18 GMT</pubDate>
    <dc:creator>ralwarrag</dc:creator>
    <dc:date>2019-03-11T11:28:18Z</dc:date>
    <item>
      <title>WCCP pass through ASA</title>
      <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876792#M973322</link>
      <description>&lt;P&gt;i want to configure a WCCP in my core router and I have an ASA firewall between my Router and my cache engines and it's preventing the WCCP traffice to go though what is the solutions for this ,,, thanks for your helping &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876792#M973322</guid>
      <dc:creator>ralwarrag</dc:creator>
      <dc:date>2019-03-11T11:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP pass through ASA</title>
      <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876793#M973323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; You can't have a WCCP-enabled router and a Cache Engine be separated by a firewall. The firewall handles only packet traffic toward the origin web server and does not handle packet traffic sent to the client by the Cache Engine on behalf of the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the below URL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/app_ntwk_services/waas/acns/v50/configuration/local/guide/14587apB.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/waas/acns/v50/configuration/local/guide/14587apB.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yassin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2007 06:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876793#M973323</guid>
      <dc:creator>mahmoudyassin98</dc:creator>
      <dc:date>2007-10-24T06:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP pass through ASA</title>
      <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876794#M973324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also have the same issue, Client/WCCP router located on Pix inside and Bluecoat Proxy located on Pix outside, the Bluecoat proxy then connects to the Internet via a Checkpoint fw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC have confirmed that this is a bug: CSCsk84801&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Pix receives the WCCP/GRE packet from the WCCP router, it is stripping the GRE header and sending the http packet natively to the outside interface, and not forwarding the GRE packet to the Bluecoat proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WCCP/GRE behaviour has been confirmed as a definite bug and will be fixed in the next 7.2.3 interim release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, having seen Yassin's above link I have asked TAC to confirm if this scenario is supported. I can't see why a firewall can't succesfully pass WCCP packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2007 14:33:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876794#M973324</guid>
      <dc:creator>russ</dc:creator>
      <dc:date>2007-10-24T14:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP pass through ASA</title>
      <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876795#M973325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks alot for your this information &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2007 18:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876795#M973325</guid>
      <dc:creator>ralwarrag</dc:creator>
      <dc:date>2007-10-24T18:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP pass through ASA</title>
      <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876796#M973326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is an explanation from Cisco TAC regarding the issues of passing WCCP through a firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have confirmed with DE how wccp works. What happens is that the TCP session setup packets from from wccp router to the cache engine are encaps in GRE. The return packet (syn-ack) is not encapsulated in GRE. It will therefore be dropped by the firewall as we have not see the outgoing SYN (bacause it was GRE encaps'd). In order to permit asynchronous tcp connections through the pix, you will need to configure a static nailed statement. eg:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.255 norandomseq nailed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This wll cause the traffic matching the static to bypass the normal TCP packet and inspection processing. This is not ideal, but this is the only way to get this working as your customer requires. The bug fix CSCsk84801 is obviously therefore still required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case, the static rule needs to be  applied from outside to inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bug will be fixed in v8.0.3 and v7.2.3.8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2007 10:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876796#M973326</guid>
      <dc:creator>russ</dc:creator>
      <dc:date>2007-10-26T10:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP pass through ASA</title>
      <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876797#M973327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks alot for your usefull information &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2007 12:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876797#M973327</guid>
      <dc:creator>ralwarrag</dc:creator>
      <dc:date>2007-10-26T12:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: WCCP pass through ASA</title>
      <link>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876798#M973328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Russ &lt;/P&gt;&lt;P&gt;i have tried it but unfortunatly it didn't work i add static statmnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (outsidenet,dmznet) 1.1.1.1 [ip add of the router]   2.2.2.2 [ the ip address of the bluecoat] netmask 255.255.255.255 norandomseq nailed &lt;/P&gt;&lt;P&gt;and thanks alot for your helping &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Oct 2007 06:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wccp-pass-through-asa/m-p/876798#M973328</guid>
      <dc:creator>ralwarrag</dc:creator>
      <dc:date>2007-10-27T06:12:48Z</dc:date>
    </item>
  </channel>
</rss>

