Mi laboratorio WCCP
Websense + Cisco = Proxy transparente
P1 192.168.1.34
Cisco 192.168.1.89 (cisco:petroken)
Cisco 192.168.1.89 (cisco:petroken)
IP de testing cliente: 192.168.1.170 255.255.255.0 (puerta de enlace: 192.168.1.89)
enable
config t
ip wccp version 2
ip wccp 0
ip wccp 5
ip wccp 20
ip wccp 70
no ip wccp web-cache
ip access-list standard TST
permit ip any any
ip access-list extended R_TST
permit ip host 192.168.1.34 any
permit ip host 192.168.1.89 any
ip wccp 0 redirect-list R_TST group-list TST
ip wccp 5 redirect-list R_TST group-list TST
ip wccp 20 redirect-list R_TST group-list TST
ip wccp 70 redirect-list R_TST group-list TST
interface GigabitEthernet0/0
ip wccp 0 redirect in
ip wccp 5 redirect in
ip wccp 20 redirect in
ip wccp 70 redirect in
exit
interface GigabitEthernet0/1
ip wccp 0 redirect out
ip wccp 5 redirect out
ip wccp 20 redirect out
ip wccp 70 redirect out
ip wccp redirect exclude in
exit
exit
config t
ip wccp version 2
ip wccp 0
ip wccp 5
ip wccp 20
ip wccp 70
no ip wccp web-cache
ip access-list standard TST
permit ip any any
ip access-list extended R_TST
permit ip host 192.168.1.34 any
permit ip host 192.168.1.89 any
ip wccp 0 redirect-list R_TST group-list TST
ip wccp 5 redirect-list R_TST group-list TST
ip wccp 20 redirect-list R_TST group-list TST
ip wccp 70 redirect-list R_TST group-list TST
interface GigabitEthernet0/0
ip wccp 0 redirect in
ip wccp 5 redirect in
ip wccp 20 redirect in
ip wccp 70 redirect in
exit
interface GigabitEthernet0/1
ip wccp 0 redirect out
ip wccp 5 redirect out
ip wccp 20 redirect out
ip wccp 70 redirect out
ip wccp redirect exclude in
exit
exit
Del lado del WCG
My Proxy > Basic > Feature > WCCP (Enable y Apply) y reiniciar (Restart)
Configure > Networking > WCCP
Service Group Name Service Group ID/Reverse ID Protocol Ports Network Interface Forward Method Assignment Method Return Method Weight Status
www 0/NULL TCP 80 eth0 L2 MASK L2 0 Enabled
https 70/NULL TCP 443 eth0 L2 MASK L2 0 Enabled
ftp 5/NULL TCP 21 eth0 L2 MASK L2 0 Enabled
My Proxy > Basic > Feature > WCCP (Enable y Apply) y reiniciar (Restart)
Configure > Networking > WCCP
Service Group Name Service Group ID/Reverse ID Protocol Ports Network Interface Forward Method Assignment Method Return Method Weight Status
www 0/NULL TCP 80 eth0 L2 MASK L2 0 Enabled
https 70/NULL TCP 443 eth0 L2 MASK L2 0 Enabled
ftp 5/NULL TCP 21 eth0 L2 MASK L2 0 Enabled
Todo estaría bien, pero no veo registros del lado del router:
wccp#show ip wccp
Global WCCP information:
Router information:
Router Identifier: 192.168.247.89
Protocol Version: 2.0
Global WCCP information:
Router information:
Router Identifier: 192.168.247.89
Protocol Version: 2.0
Service Identifier: 0
Number of Service Group Clients: 0
Number of Service Group Routers: 0
Total Packets s/w Redirected: 0
Process: 0
CEF: 0
Service mode: Open
Service Access-list: -none-
Total Packets Dropped Closed: 0
Redirect Access-list: R_TST
Total Packets Denied Redirect: 0
Total Packets Unassigned: 7
Group Access-list: TST
Total Messages Denied to Group: 1154
Total Authentication failures: 0
Total GRE Bypassed Packets Received: 0
Number of Service Group Clients: 0
Number of Service Group Routers: 0
Total Packets s/w Redirected: 0
Process:
CEF:
Service mode: Open
Service Access-list: -none-
Total Packets Dropped Closed: 0
Redirect Access-list: R_TST
Total Packets Denied Redirect: 0
Total Packets Unassigned: 7
Group Access-list: TST
Total Messages Denied to Group: 1154
Total Authentication failures: 0
Total GRE Bypassed Packets Received: 0
Service Identifier: 5
Number of Service Group Clients: 0
Number of Service Group Clients: 0
wccp#sh ip wccp 0 view
WCCP Routers Informed of:
-none-
WCCP Routers Informed of:
-none-
WCCP Clients Visible:
-none-
-none-
WCCP Clients NOT Visible:
-none-
-none-
wccp#sh ip wccp 0 detail
No information is available for the service.
No information is available for the service.
wccp#
Tampoco del lado de las estadisticas de Websense:
WCCP Statistics
|