Duke5A Posted March 22, 2017 Posted March 22, 2017 Is anyone familiar with WCCP for redirecting web traffic to proxies? I was wondering how one goes about stopping the switch from routing web traffic to the outside in the event the proxy goes down and is no longer registered with the switch. I had this happen on the guest wireless today and discovered students were getting unfiltered Internet access. Thanks.
Duke5A Posted March 27, 2017 Author Posted March 27, 2017 According to WCCP tutorial at https://docs.diladele.com/tutorials/web_filter_https_squid_cisco_wccp/index.html and specifically further notes at https://docs.diladele.com/tutorials/web_filter_https_squid_cisco_wccp/conclusion.html this can be done by blocking outbound access for anything but your squid farm. See more at https://supportforums.cisco.com/document/98161/asa-wccp-fail-close The proxy and clients are in two different VLANs and this is being done on a 6506E series chassis. Without any blocking it works great. When I implement an ACL to block outgoing web traffic on the client VLAN it stops working. I've tried multiple configurations with different ACL setups and it never seems to work. What I did was instead I went up to the firewall and blocked outgoing web traffic on the client VLAN from there. Seems to be working as intended now.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now