cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
928
Views
0
Helpful
6
Replies

WSAv in explicit mode and IP Spoofing (no WCCP)

When we use the IP Spoofing functionality in explicit mode with an IP address not being the client address, but from some other range.

And of course routing that address back to the WSAv and we don't use a WCCP router.

Do we need to configure that ip address somewhere in the interfaces? Or is that automagically done when ip spoofing is enabled?

1 Accepted Solution

Accepted Solutions

Ok now i understand your requirement :

check below guide how this can be done :

https://www.youtube.com/watch?v=LDVW9uFdj7s

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

when you configure explicit mode you only see WSA IP address not client IP address.

you like to forwardf client IP - X-Forwarded-For

UI, Security Services -> Web Proxy -> generate headers-> x-forwarded for   - this should be set to "send".

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

That is not what I want to achieve. I want to use a different IP address so that a traffic shaper can recognize this traffic and assign a specific shaping profile to this traffic.

I want to use a different IP address  - explain more

WSA have P1 and P2 interface - One inside and One outside, when the connection going out it used WSA outside interface IP and request the content ? what you trying to do here ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

What I'm trying to achieve here is that traffic from a specific set of clients, going through the proxy and to a specified number of destinations (hostnames) is limited in the bandwidth they can consume.

Bandwidth limitations in our setup is done by a traffic shaper just before the internet connection. They can apply a different shaping class based on source ip or destination ip. The destination ip's changes too much and is not under our control, therefore I try to have a solution based on source IP. 

So want I want to do is:

  • create an identification profile using the client ip addresses and a custom URL category matching to concerned hostnames.
  • create an IP Spoofing profile in which I use a new ip address.
  • create a Routing Policy using the above created identification profile and IP Spoofing profile.
  • configure the routing such that the configured spoofed address is routed to the WSAv
  • In our setup we have 4 active WSAv's which are loadbalanced by a Radware loadbalancer. Traffic from the clients can reach any of those 4 WSAv's.
  • We have a SMA for defining the global setup (Routing policy & Identification Profile), each WSAv has its own IP Spoofing profile (sharing the same name on all WSA's).

Ok now i understand your requirement :

check below guide how this can be done :

https://www.youtube.com/watch?v=LDVW9uFdj7s

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks for sharing the link to the guide. That will help.

Henk