Cisco Systems WCCP v1 Cisco with cache on separate interface

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
WCCP v1 Cisco with cache on separate interface kartik 03-24-06
Posted by kartik on March 24, 2006, 6:59 pm
Please log in for more thread options
Hello all.

My Cisco router has 3 interfaces. Fe0/0 is the incoming interface with
all the web traffic from the clients. Fe0/1 is connected to the
internet backhaul and Fe0/2 connects to the cache engine farm.

I enabled wccpv1 (since my cache supports only that) on the cisco
router and configured the ip wccp redirect out command in the Fe0/1
interface which is the path to the internet.

I see that the response(I_See_You) from the cisco to the Here_I_Am
messages from the cache server uses the source interface of Fe0/2
(since that is the closest interface to the cache farm LAN, I suppose).
!!!

Doing an show ip wccp web-cache detail shows the WebCache ID as
0.0.0.0....

Interestingly redirection is occuring on the cisco router when I try to
browse (as indicated by the counters in the same command) but it is not
working... is this because the gre tunnel is using a source interface
of 0.0.0.0 ???

ANy ideas on how I can get the router to use the correct webcache ip
address??

thanks,
-Kartik


Posted by kartik on March 27, 2006, 7:04 pm
Please log in for more thread options
I found that this is a cisco IOS bug with wccpv1. Its just a display
bug.

The router is seeing the cache (show ip wccp detail). However my PIX
firewall in between the router and the cache seems to be dropping the
spoofed SYN ACK packet sent by the cache to the client. On digging
further I see the cisco router redirecting the HTTP SYN packet for the
internet website (from my client pc) to the cache. The Cache responds
with a SYNACK with the source IP address "spoofed" to reflect the ip
address of the actual webserver. However the PIX does not seem to
forward it out the outside interface back to the router. Doing a debug
ip packet on the DMZ interface of the PIX shows the packet entering the
PIX.

ANy help would be appreciated !!

thanks.
-Kartik


Similar ThreadsPosted
WCCP v1 Cisco with cache on separate interface March 24, 2006, 6:59 pm
WCCP - Cache engine - URL filter - how it all works? November 23, 2006, 1:35 pm
Cisco 3750 and WCCP or PBR October 11, 2006, 7:07 pm
Help with Cisco ASA w/CSC-SSM and WCCP Configuration.. August 31, 2009, 7:09 pm
Cisco 1700 and DNS cache July 18, 2005, 8:35 pm
Cache hits are low on a Cisco Content Engine December 30, 2005, 1:03 pm
Putting Linux on Cisco 550 Cache Engine August 9, 2006, 3:41 pm
Cisco 3750 Mac address cache size June 5, 2008, 1:40 pm
Cisco Unity Express and Cisco CME GUI - separate admin accounts? April 12, 2006, 10:33 pm
WAE- WCCP April 26, 2008, 12:13 am
WAAS w/ WCCP not working December 23, 2008, 10:05 am
passing wccp traffic via firewall May 25, 2006, 11:04 am
WCCP on ASA & traffic between physical interfaces on ASA February 13, 2007, 3:10 pm
vlan and arp cache June 23, 2009, 9:18 pm
%IP-4-ZERO_ADDR: Zero MAC address for xxx.yyy.zzz.66 in ARP cache November 27, 2006, 2:58 am
Residential Cabling Guide

Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Learn More