WCCP on ASA & traffic between physical interfaces on ASA

WCCP on ASA & traffic between physical interfaces on ASA

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
WCCP on ASA & traffic between physical interfaces on ASA apsolar 02-13-2007
Posted by on February 13, 2007, 3:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I am trying to get WCCP working on the ASA for WAAS implementation.
Here is a simple snapshot of my config:
Eth 0/0 : Outside (to internet)
Eth 0/1 : Vlan1 (20.20.0.0/16) (trunk port to remote office LAN)
Eth 0/1.211 : Vlan211 (20.21.10.0/24)
Eth 0/1.212 : Vlan212 (20.21.20.0/24)
Eth 0/1.220 : Vlan220 (20.22.0.0/16)
Eth 0/2 : WAAS (20.21.30.0/24)


I have the site to site tunnel working. I can ping the WAAS device
from the other end of the tunnel but I cannot ping it from the
20.20.0.0/16 network. I have enabled traffic between interfaces on
same security level as WAAS and LAN have same security.

I get this error message:
3 Feb 12 2007 17:54:05 305006 20.20.10.101 portmap translation
creation failed for icmp src WAAS:20.21.30.230 dst LAN:20.20.10.101
(type 8, code 0)

How can I fix this?

My second question is regarding WCCP on ASA. Here is the WCCP part of
the config I have:
wccp 61 redirect-list WCCP_To_LAN
wccp 62 redirect-list WCCP_To_WAN
wccp interface outside 62 redirect in
wccp interface LAN 61 redirect in
access-list WCCP_To_LAN extended permit ip any 20.20.0.0 255.252.0.0
access-list WCCP_To_WAN extended permit ip 20.20.0.0 255.252.0.0 any
I am not seeing any packets being redirected to the WAE. I once
changed the access lists to 'any any' and I saw some packets but I
couldn't ping or telnet to the remote site. Could it be a loop? Is
there any way to exclude traffic to avoid loop?

Thanks
Ankit


Pure Networks
Posted by on February 14, 2007, 5:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
common guys.
someone here can definitely help me.



Similar ThreadsPosted
GRE traffic over PIX IPSEC VPN June 6, 2005, 5:55 pm
forcing traffic over the vpn May 28, 2008, 11:52 pm
What traffic is pumped through the VPN? November 3, 2007, 7:03 pm
Route all traffic through Cisco VPN October 13, 2005, 6:25 pm
VPN clients catches ALL network traffic... February 28, 2005, 9:21 pm
Please Help : IPsec VPN Tunnel Established, but no Traffic April 1, 2005, 9:47 pm
Route all traffic through Netgear FVS318v3 VPN September 28, 2005, 5:38 pm
Can establish IPSec Tunnel but no traffic through it March 9, 2006, 5:52 pm
cisco vpn connection to vpn concentrator 3000 not passing web traffic August 21, 2006, 11:44 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map