cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
570
Views
0
Helpful
1
Replies

SD-WAN DIA + 3rd party appliance WCCP.

Heriberto Diaz
Level 1
Level 1

I facing a situation when the client navigate and all the traffic comming is forwading to the switch core and then to firewall and this is forwarding to appliance ForcePoint "WCCP" to apply a NAT and back the flow to the firewall again by other port to finally out to internet.

 

Now we are planning to migrate to SD-WAN the site with DIA, and reading the documents cisco about DIA Deployment, I found that DIA apply a NAT on VPN 0, so that a inconvenient because the appliance "WCCP" need to receive the traffic with the source IP of the client pc due that Forcepoint needs to apply the NAT.

 

Does anyone know a workaround to work with appliance WCCP?

 

Regards.

1 Reply 1

Hi

 We have similar scenario in a Customer network. They actually does not have WCCP but they have firewall and the design is done by adding the firewall before the cEdge. The traffic comes from internal network up to the Core, goes to Firewall, and is sent to cEdge.

 In your topology, you can achive the same scenario.