[c-nsp] Cisco WCCP and Squid on Linux

Mark Tinka mtinka at africaonline.co.sz
Mon Jun 27 07:10:56 EDT 2005


On Monday 27 June 2005 05:42, Dave Weis wrote:

> Yes, it's a very simple network, 1 Cisco router, 1
> Squid server, and 1 3Com total control chassis.

Whats OS are you running Squid on? Linux? FreeBSD? 
e.t.c.?

With WCCP, especially on a general purpose UNIX-like OS, 
enabling interception caching is not as easy as flipping 
on a switch - a lot of things have to be working 
together for it to work (and they are several).

> It looks like ip_gre

If running Linux, have you tried using the ip_wccp.c 
module located at:

http://www.squid-cache.org/WCCP-support/Linux/ip_wccp.c

as Linux's GRE driver doesn't know what to do with the 
GRE packet that comes from the router? 

FreeBSD 4.8 and above doesn't have this problem, as it 
has GRE and WCCP support in the kernel that will work 
well with IOS's GRE.

> No. We have two sites that we are trying to make this
> work on, one has just the setup above, the other has a
> web server also. When we first tried to set it up we
> broke all inbound access, so we are starting with the
> simple config.

To not_break inbound access, you'll probably need to 
attach an ACL to your WCCP setup so local web servers 
(at least those running on port 80), and of course, the 
Squid box itself, don't get redirected via WCCP, for 
obvious reasons.

It would be easier for us to help if we knew what OS + 
version/kernel you were running Squid on.

Mark.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 827 bytes
Desc: not available
Url : https://puck.nether.net/pipermail/cisco-nsp/attachments/20050627/6b9ac7da/attachment.bin


More information about the cisco-nsp mailing list