cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1684
Views
0
Helpful
1
Replies

WAAS WCCP from fortinet

Fatoumata Sow
Level 1
Level 1

hello,

I need your help, we want to configure WCCP on WAE but the customer have a fortinet  firewall in agencies.

Has anyone had to do this type of setup ?

what are the  WCCP services 61 and 62? did I need to configure also to Fortinet?

Thanks for your help.

1 Reply 1

Daniel Arrondo Ostiz
Cisco Employee
Cisco Employee

Hi Fatoumata,

The WCCP service is a number specified in the protocol to define what kind of traffic is going to be matched, so, it's not relevant for a firewall.

To allow WCCP traffic to go through a firewall (assuming it's located between the WAE and the router), you just need to allow UDP port 2048 in both directions.

If what you need to do is allowing the optimized traffic to go through the FW (which would happen if you have the FW between the router and the WAN link), then, you would need to enable some kind of WAAS inspection on the Fortinet firewall to allow the modifications that WAAS does on the TCP packets (adding a TCP option in the SYN and SYN/ACK packets and a sequence number shift after the TCP handshake). Unfortunately, I don't know how this can be done because I'm not familiar with that firewall.

Regards

Daniel