The ASA must be running minimum 7.2.1 code to be able to configure WCCP feature.
The only topology that the adaptive security appliance supports is when client and cache engine are behind the same interface of the adaptive security appliance and the cache engine can directly communicate with the client without going through the adaptive security appliance.
Router ID is chosen as the highest IP address configured on the ASA. If that happens to the DMZ interface or the outside interface IP address, then the WCCP server has to have a route to get to that Router-ID address pointing to the ASA's interface.
How wccp works
PC makes a request to a website.
ASA receives the request and re-directs it to the wccp server in an encapsulated GRE packet to avoid any modifycations to the original packet.
WCCP receives the packet and sends the response directly to the PC.
Step by Step Configuration
1. Configure an access-list containing all members of WCCP servers.
There is only one WCCP server in this example.
ASA(config)#access-list wccp-servers permit ip host 192.168.6.10 any
2. Create an access-list of the traffic that needs to be re-directed to WCCP
The access-list argument should consist of a string of no more than 64 characters (name or number) that specifies the access list. The access list should only contain network addresses. Port-specific entries are not supported.
ASA(config)#access-list wccp-traffic permit ip 192.168.6.0 255.255.255.0 any
We have three ISE nodes, AN-PRI-ISEPrimary ISE at DCall personas enabled ie. Admin, PSN & MnTAN-SEC-ISESecondary at DCall personas enabled ie. Admin, PSN & MnTDR-ISEHealth Check Node at DRonly PSN is enabled We are using ISE 2.4 with Pat...
HI, I have this weird issue. We have an ASA 5525 and an FMC managing those SFR.Current version of the ASA is 9.8(4) and the FMC has ver. 6.7.0.What happens is the there are some sites that users cannot access.When I checked the logs via ASDM, I see s...
Hi,we have a FMC ver 126.96.36.199 and FTD 5516-x both have been workingCurrently FTD is working with 4 interfaces (outside,outside2,inside,LAN-B,LAN-c). LAN-B and LAN-C are the new interfacesFor hosts the default gateway is a router that also hande MPLS connec...
Hello, When I recently became unable to print on my LAN, and I did some troubleshooting, I realized that 3 copies of the Anyconnect Socket Filter load automatically after each restart, without me having to run the Anyconnect app. It occurs...