Branch IPSEC VPN Site with WCCP setup for vWAAS - Overthinking this
OK, I have a fairly large WAAS environment so I'm kicking myself for overthinking this. I have a particular branch that has an 881 router that terminates an IPSEC connection back to my main location. I have a vWAAS at this branch site, so I'm going WCCP. I got the license upgrade to enable to the WCCP feature set. Now Im confused on the WCCP setup. There is only 1 VLAN at the branch. I have the WAAS setup to do WCCP GRE.
Question is: Would I do the redirect 61,62 on the VLAN1 internface? I think I would, but Im used to dropping the 62 on the serial interface of my MPLS. I.E.:
wccp 62 is to intercept the WAN traffic, but if you put it on the LAN side, you have to catch the traffic on its way out:
ip wccp 62 redirect out
There is no need to deny telnet and ssh, those both have policies in WAAS for passthrough. Also, I prefer to put my WAAS device on its own VLAN. However, if it is going to be on VLAN 1, your access list will need:
ip access-list extended branch-waas
remark WCCP Redirect ACL
deny ip any host (WAAS IP)
deny ip host (WAAS IP) any
permit ip any any
To make sure you do not loop WCCP traffic.
Just edited to change from TCP to IP in access list.
The 2021 IT Blog Awards, hosted by Cisco, is now open for submissions. Submit your blog, vlog or podcast by Friday, December 3.
To learn what's new in this year's competition or to gain insights into the judging considerations, check out ...
Data Center and Cloud Networking News
Cisco Nexus Dashboard Open Ecosystem with Splunk
End-to-End Flow State Validation with Nexus Dashboard Insights Connectivity Analysis
Cisco Q1 NPI Announcements for Data Center and Cloud Networking
We delivered a partner enablement training session in September 2021 to share the ACI upgrade Best Practices.
The slide deck is enclosed here for wider audience in the community, it provides more details in terms of the best practices, tools and co...
What is Cisco ACI Anywhere?What are ACI connectivity options for managing Primary On-Prem DCs?What are ACI options for extending your Data center to secondary remote locations (Physical)?How ACI provides centralized network policy framework for workloads ...
Cloud Networking Community on Cisco Customer Connection
Join our community!!
As a valued Cisco Cloud Networking (former DCN) customer, you can be part of Cisco Customer Connection Program (CCP), Cisco’s global online community program. Connect ...