Re: WCCP on 3560 Switch

From: RRC (ronnieroshan@gmail.com)
Date: Thu Sep 11 2008 - 13:19:37 ART


Ive tried a few things ~ Upgraded Cisco 3560 Switch to 12.2(44) & also done
SDM Routing Template on switch.

I_SEE_YOU and IAM_HERE packets as usual , havent got any IM_WORKING Packets
(Just Kidding)......

No traffic redirections as such ~

SW-1#show ip wccp web-cache
Global WCCP information:
    Router information:
 Router Identifier: 1.1.1.1
 Protocol Version: 2.0
    Service Identifier: web-cache
 Number of Service Group Clients: 1
 Number of Service Group Routers: 1
 Total Packets s/w Redirected: 0
   Process: 0
   CEF: 0
 Redirect access-list: -none-
 Total Packets Denied Redirect: 0
 Total Packets Unassigned: 0
 Group access-list: -none-
 Total Messages Denied to Group: 0
 Total Authentication failures: 0
 Total Bypassed Packets Received: 0
---------------------------------------------------
SW-1#show ip wccp web-cache detail
WCCP Client information:
 WCCP Client ID: 172.21.12.248
 Protocol Version: 2.0
 State: Usable
 Redirection: L2
 Packet Return: L2
 Packets Redirected: 0
 Connect Time: 00:00:31
 Assignment: MASK
 Mask SrcAddr DstAddr SrcPort DstPort
 ---- ------- ------- ------- -------
 0000: 0x00000000 0x00000526 0x0000 0x0000
 Value SrcAddr DstAddr SrcPort DstPort CE-IP
 ----- ------- ------- ------- ------- -----
 0000: 0x00000000 0x00000000 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0001: 0x00000000 0x00000002 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0002: 0x00000000 0x00000004 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0003: 0x00000000 0x00000006 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0004: 0x00000000 0x00000020 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0005: 0x00000000 0x00000022 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0006: 0x00000000 0x00000024 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 --More--   0007: 0x00000000 0x00000026 0x0000
0x0000 0xAC1502F8 (172.21.2.248)
 0008: 0x00000000 0x00000100 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0009: 0x00000000 0x00000102 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0010: 0x00000000 0x00000104 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0011: 0x00000000 0x00000106 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0012: 0x00000000 0x00000120 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0013: 0x00000000 0x00000122 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0014: 0x00000000 0x00000124 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0015: 0x00000000 0x00000126 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0016: 0x00000000 0x00000400 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0017: 0x00000000 0x00000402 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0018: 0x00000000 0x00000404 0x0000 0x0000 0xAC1502F8 (172.21.2.248)
 0019: 0x00000000 0x00000406 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0020: 0x00000000 0x00000420 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0021: 0x00000000 0x00000422 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0022: 0x00000000 0x00000424 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0023: 0x00000000 0x00000426 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0024: 0x00000000 0x00000500 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0025: 0x00000000 0x00000502 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0026: 0x00000000 0x00000504 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0027: 0x00000000 0x00000506 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0028: 0x00000000 0x00000520 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0029: 0x00000000 0x00000522 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0030: 0x00000000 0x00000524 0x0000 0x0000 0xAC1502F8 (172.21.12.248)
 0031: 0x00000000 0x00000526 0x0000 0x0000 0xAC1502F8 (172.21.12.248)

BTW This WebCache Engine doesnt Support M/C Groups.

Any help would be great.

Regards
RRC

On Tue, Sep 9, 2008 at 2:31 PM, RRC <ronnieroshan@gmail.com> wrote:

> Hello everyone,
>
> Thank You Shiran & Antonie.
>
> In this configuration, i have internal users connected to a L3 Port.
> External on a VLAN ( SVI) & Web Cache connected to SVI as well.
>
> If as Antonie pointed out , it is a must for the switch to have a routed
> port ( L3 ) on the switch on the same VLAN as the Cache Servers for it to
> work , then that should do the trick.
>
> Ive noticed that V 12.2(37) & above dont support the " ip wccp redirect out
> " command to explicitly let the switch know which interface to exit for web
> traffic.
>
> Thanks a Tonne ,
>
> Will update........
>
> RRC
>
> On Tue, Sep 9, 2008 at 2:01 PM, shiran guez <shiranp3@gmail.com> wrote:
>
>>
>>
http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/software/release/12
.2_44_se/configuration/guide/swwccp.html#wp1051427
>>
>>
>> On Tue, Sep 9, 2008 at 1:39 PM, RRC <ronnieroshan@gmail.com> wrote:
>>
>>> Hello Everyone
>>>
>>> Yes , Shiran . Ive configured the necessary config on the Cache Engine (
>>> IronPort)
>>>
>>> 1) did you configured the service group to be redirected?
>>>>
>>> No service groups used. Im using " ip wccp web-cache".
>>>
>>>
>>>> 2) did you configured on the cache engine the same?
>>>>
>>>
>>> Yes configured on Cache Engine ( IP ).
>>>
>>>> 3) what is the status of the service group?
>>>>
>>> n.a
>>>
>>>
>>>> 4) did you assign an acl to the service group on the Cisco 3560?
>>>>
>>> No acls assigned.
>>>
>>>> 5) do you see hits on that acl?
>>>> No hits as ive configured "ip wccp web-cache" minus any service groups.
>>>>
>>>>
>>>>
>>>> On Tue, Sep 9, 2008 at 1:12 PM, RRC <ronnieroshan@gmail.com> wrote:
>>>>
>>>>> Hello Everyone,
>>>>>
>>>>> Ive a deployment issue with WCCP.Im implementing WCCP on 2X Cisco 3560
>>>>> switches IOS 12.2(40) AdvanceK9. Ive enabled "ip wccp web-cache
>>>>> redirect in
>>>>> " on the L3 Ports connected to the internal n/w from where web traffic
>>>>> is
>>>>> generated. Traffic to Internet flows through a port in another VLAN.
>>>>> The
>>>>> Cache Engine is in a sep VLAN and is assigned IP in that VLAN. WCCP
>>>>> basic
>>>>> communication " I See you " and "I am here " are exchanged between the
>>>>> switch & cache engine. However no redirection traffic is flowing
>>>>> through the
>>>>> Cache engine.
>>>>>
>>>>> Could anyone throw some light on the same.
>>>>>
>>>>> Note the Interface ( External ) to the internet is connected to a 2nd
>>>>> tier
>>>>> FW which f/ws it to another FW before exiting via the Cisco router.
>>>>>
>>>>> Hope to receive respnse on the same
>>>>>
>>>>> Regards
>>>>>
>>>>> Rony
>>>>>
>>>>>
>>>>> Blogs and organic groups at http://www.ccie.net
>>>>>
>>>>> _______________________________________________________________________
>>>>> Subscription information may be found at:
>>>>> http://www.groupstudy.com/list/CCIELab.html
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>> --
>>>> Shiran Guez
>>>> MCSE CCNP NCE1 CCIE #20572
>>>> http://cciep3.blogspot.com
>>>> http://www.linkedin.com/in/cciep3
>>>>
>>>
>>>
>>
>>
>> --
>> Shiran Guez
>> MCSE CCNP NCE1 CCIE #20572
>> http://cciep3.blogspot.com
>> http://www.linkedin.com/in/cciep3

Blogs and organic groups at http://www.ccie.net



This archive was generated by hypermail 2.1.4 : Sat Oct 04 2008 - 09:26:18 ART