04-14-2018 08:05 AM - edited 03-12-2019 05:12 AM
we are planning to provide Websecurity to Anyconnect users using Cisco-WSA.
Could you tell us which is the better way?
I'm assuming we can advertise default route to anyconnect users and give following command
"ip route inside 0.0.0.0 0.0.0.0 <Coreswitch_IP> tunneled"
So Once the traffic hits the inside core switch the traffic will take a U-turn, will head back to internet and will be caught by the WCCP running on the inside interface of the ASA.
is there any other option to try with?
04-14-2018 08:31 AM
Hi,
What you have suggested seems fine by me, other than that you could of course explicitly configure the proxy in the users' web browser.
04-14-2018 08:41 AM
04-14-2018 08:47 AM
Yes, only traffic originating from an AnyConnect connection should use that configured static route with the tunneled keyword appended.
For reference:
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide