RE: [squid-users] Transparent WCCP/GRE HTTPS issue

From: Jason Gauthier <jgauthier@dont-contact.us>
Date: Sat, 8 Dec 2007 13:38:31 -0500

>
> * client -> proxy goes via WCCPv2 and GRE;
> * proxy -> client if they're on the same subnet goes straight back to
> the
> client and not via the ASA itself;
>
> Different interface:
>
> * client -> proxy goes via WCCPv2 and GRE;
> * proxy -> client needs to go via the ASA, but with a spoofed source
> address
> (ie, the "pretend" internet http server address), and the ASA is
> unhappy
> with this.
>
> I can't be sure without owning a PIX/ASA.
>

Well,

  To aid in troubleshooting I removed all instances except for 1. I
have one GRE tunnel, only one interface being redirected on the ASA.
Very simple now! :) My HTTPS issue still exists.

Client, Proxy, ASA.. all on the same interface. Going to run some
tcpdumps and try and determine why.
Any more tips welcomed!
Received on Sat Dec 08 2007 - 11:38:47 MST

This archive was generated by hypermail pre-2.1.9 : Tue Jan 01 2008 - 12:00:01 MST