Jump to content

Recommended Posts

Posted
Is anyone familiar with WCCP for redirecting web traffic to proxies? I was wondering how one goes about stopping the switch from routing web traffic to the outside in the event the proxy goes down and is no longer registered with the switch. I had this happen on the guest wireless today and discovered students were getting unfiltered Internet access. Thanks.
Posted
According to WCCP tutorial at https://docs.diladele.com/tutorials/web_filter_https_squid_cisco_wccp/index.html and specifically further notes at https://docs.diladele.com/tutorials/web_filter_https_squid_cisco_wccp/conclusion.html this can be done by blocking outbound access for anything but your squid farm.

 

See more at https://supportforums.cisco.com/document/98161/asa-wccp-fail-close

 

The proxy and clients are in two different VLANs and this is being done on a 6506E series chassis. Without any blocking it works great. When I implement an ACL to block outgoing web traffic on the client VLAN it stops working. I've tried multiple configurations with different ACL setups and it never seems to work. What I did was instead I went up to the firewall and blocked outgoing web traffic on the client VLAN from there. Seems to be working as intended now.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...