43-2
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter 43 Configuring Web Cache Services Using WCCP
Licensing Requirements for WCCP
The following WCCPv2 features are not supported for the ASA:
• Multiple routers in a service group.
• Multicast WCCP.
• The Layer 2 redirect method.
• WCCP source address spoofing.
• WAAS devices.
WCCP Interaction With Other Features
In the ASA implementation of WCCP, the protocol interacts with other configurable features according
to the following:
• Cut-through proxy will not work in combination with WCCP.
• An ingress access list entry always takes higher priority over WCCP. For example, if an access list
does not permit a client to communicate with a server, then traffic is not redirected to a cache engine.
Both ingress interface access lists and egress interface access lists are applied.
• TCP intercept, authorization, URL filtering, inspect engines, and IPS features are not applied to a
redirected flow of traffic.
• When a cache engine cannot service a request and a packet is returned, or when a cache miss
happens on a cache engine and it requests data from a web server, then the contents of the traffic
flow is subject to all the other configured features of the ASA.
• If you have two WCCP services and they use two different redirection ACLs that overlap and match
the same packets (with a deny or a permit action), the packets behave according to the first
service-group found and installed rules. The packets are not passed thorugh all service-groups.
Failover Guidelines
Supports Active/Active and Active/Standby failover. WCCP redirect tables are not replicated to standby
units. After a failover, packets are not redirected until the tables are rebuilt. Sessions redirected before
failover are probably reset by the web server.
Firewall Mode Guidelines
Supported in routed and transparent firewall modes.
Context Mode Guidelines
Supported in single mode and multiple context mode.
Additional Guidelines
The ASA selects the highest IP address configured on any interface as the WCCP router ID. This address
is used to establish a GRE tunnel with the cache engine.
Licensing Requirements for WCCP
Table 43-1 shows the licensing requirements for WCCP.
Table 43-1 Licensing Requirements