cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2069
Views
0
Helpful
1
Replies

Redirecting traffic to Proxy from ASA

Hi Gurus,

I have ASA 5505 with base license. I like to install proxy server in my network.

I configured below commands to forward my traffic to proxy server from my ASA.


access-list p-client extended permit tcp 10.91.40.0 255.255.255.0 any eq www
access-list p-server extended permit ip host 10.91.40.17 any               // 10.91.40.17 proxy server

wccp web-cache redirect-list p-client group-list p-server

wccp interface inside web-cache redirect in

wccp web-cache

After configuring i taken output as shown below.

CLOVE-HYD-ASA-5505# sh wccp web-cache

Global WCCP information:
    Router information:
        Router Identifier:                   -not yet determined-
        Protocol Version:                    2.0

    Service Identifier: web-cache
        Number of Cache Engines:             0
        Number of routers:                   0
        Total Packets Redirected:            0
        Redirect access-list:                p-client
        Total Connections Denied Redirect:   0
        Total Packets Unassigned:            0
        Group access-list:                   p-server
        Total Messages Denied to Group:      0
        Total Authentication failures:       0
        Total Bypassed Packets Received:     0
CLOVE-HYD-ASA-5505#


CLOVE-HYD-ASA-5505# sh wccp interfaces

WCCP interface configuration:
    Vlan1
        Output services: 0
        Input services:  1
        Mcast services:  0
        Exclude In:      FALSE
CLOVE-HYD-ASA-5505#

For your information, my proxy is squid server.

And help me, If there is any configuration that i need to configure.

And if possible send me the configuration guide to setup SQUID server. ( Actually it was set up by the 3rd party vendor)

Regards,

MJR

1 Reply 1

mirober2
Cisco Employee
Cisco Employee

Hi MJR,

This may not be related to your problem, but as a first step you should change your redirect-list to be the following instead:

access-list p-client extended permit ip 10.91.40.0 255.255.255.0 any

The ASA does not support the use of ports in the WCCP redirect-list.

The minimum Squid config required for the ASA to recognize the cache engine is:

wccp2_router
wccp2_forwarding_method 1
wccp2_return_method 1
wccp2_assignment_method hash
wccp2_service standard 0

The Squid Cache Wiki has some configuration examples to reference:

http://wiki.squid-cache.org/FrontPage

There are some Cisco-specific examples that you can find by searching around the web.

Hope that helps.

-Mike

Review Cisco Networking for a $25 gift card