<html>
<head>
<meta content="text/html; charset=koi8-r" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<br>
-----BEGIN PGP SIGNED MESSAGE----- <br>
Hash: SHA256 <br>
<br>
The only problem I see is this:<br>
<br>
Your proxy box can't interconnect with WCCP on
transport/configuration level.<br>
<br>
27.04.16 4:01, Maile Halatuituia ΠΙΫΕΤ:<br>
<span style="white-space: pre;">> wccp2_router 10.240.0.254<br>
> wccp_version 4<br>
> wccp2_forwarding_method gre<br>
> wccp2_return_method gre<br>
> wccp2_rebuild_wait off<br>
> wccp2_assignment_method hash<br>
> wccp2_service standard 0<br>
> wccp2_service dynamic 70<br>
> wccp2_service_info 70 protocol=tcp
flags=dst_ip_hash,src_ip_alt_hash,src_port_alt_hash priority=240
ports=443,80<br>
> always_direct allow all<br>
> thanks<br>
> ________________________________________<br>
> From: squid-users
<a class="moz-txt-link-rfc2396E" href="mailto:squid-users-bounces@lists.squid-cache.org"><squid-users-bounces@lists.squid-cache.org></a> on behalf of
Yuri Voinov <a class="moz-txt-link-rfc2396E" href="mailto:yvoinov@gmail.com"><yvoinov@gmail.com></a><br>
> Sent: Wednesday, April 27, 2016 10:57 AM<br>
> To: <a class="moz-txt-link-abbreviated" href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
> Subject: Re: [squid-users] help for my intercept proxy setup<br>
><br>
> Show WCCP section of yout squid.conf please.<br>
><br>
><br>
> 27.04.16 3:05, maileh ΠΙΫΕΤ:<br>
> > Hi<br>
> > Here is my router wccp config<br>
> > In global config i enable ip wccp<br>
> > #ip wccp web-cache redirect-list WCCP_HTTP<br>
> > #ip wccp 70 redirect-list WCCP_HTTPS<br>
> > Interface facing my Clients and also Squid is in the
same subnet<br>
><br>
> > int g0/0.904<br>
> > ip wccp web-cache redirect out<br>
> > ip wccp 70 redirect out.<br>
><br>
> > Verification<br>
><br>
> > #sh ip wccp sum<br>
> > WCCP version 2 enabled, 2 services<br>
><br>
> > Service Clients Routers Assign Redirect
Bypass<br>
> > ------- ------- ------- ------ --------
------<br>
> > Default routing table (Router Id: x.x.x.x):<br>
> > web-cache 1 1 HASH GRE
GRE<br>
> > 70 1 1 HASH
GRE GRE<br>
><br>
> > #sh tunnel groups wccp<br>
> > WCCP : service group 0 in "Default", ver v2, assgnmnt:
hash-table<br>
> > intf: Tunnel2, locally sourced<br>
> > WCCP : service group 326 in "Default", ver v2,
assgnmnt: hash-table<br>
> > intf: Tunnel0, locally sourced<br>
><br>
> > #sh adjacency tunnel 0 detail<br>
> > Protocol Interface Address<br>
> > IP Tunnel0 10.240.0.30(3)<br>
> > connectionid 1<br>
> > 0 packets, 0 bytes<br>
> > epoch 0<br>
> > sourced in sev-epoch
31<br>
> > Encap length 28<br>
> >
4500000000000000FF2FC732CA861F08<br>
> >
0AF0001E0000883E01460000<br>
> > Tun endpt<br>
> > Next chain element:<br>
> > IP adj out of
GigabitEthernet0/0.904,<br>
> > addr 10.240.0.30<br>
> > #sh adjacency tunnel 2 detail<br>
> > Protocol Interface Address<br>
> > IP Tunnel2 10.240.0.30(3)<br>
> > connectionid 1<br>
> > 0 packets, 0 bytes<br>
> > epoch 0<br>
> > sourced in sev-epoch
32<br>
> > Encap length 28<br>
> >
4500000000000000FF2FC732CA861F08<br>
> >
0AF0001E0000883E00000000<br>
> > Tun endpt<br>
> > Next chain element:<br>
> > IP adj out of
GigabitEthernet0/0.904,<br>
> > addr 10.240.0.30<br>
> > #sh ip wccp web-cache detail<br>
> > WCCP Client information:<br>
> > WCCP Client ID: 10.240.0.30<br>
> > Protocol Version: 2.0<br>
> > State: Usable<br>
> > Redirection: GRE<br>
> > Packet Return: GRE<br>
> > Assignment: HASH<br>
> > Initial Hash Info:
00000000000000000000000000000000<br>
> >
00000000000000000000000000000000<br>
> > Assigned Hash Info:
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF<br>
> >
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF<br>
> > Hash Allotment: 256 (100.00%)<br>
> > Packets s/w Redirected: 0<br>
> > Connect Time: 00:08:42<br>
> > GRE Bypassed Packets<br>
> > Process: 0<br>
> > CEF: 0<br>
> > Errors: 0<br>
> > If you can see all seems to be established between the
router and<br>
> squid box<br>
> > but no PACKET has been redirected.<br>
> > For my IOS<br>
> > ROM: System Bootstrap, Version 15.0(1r)M15, RELEASE
SOFTWARE (fc1)<br>
><br>
> > It's been over two weeks now and i seems to looking
everywhere but no<br>
> luck.<br>
> > Also here is my iptables rules for you info whch run on
ubuntu 14.04 with<br>
> > squid<br>
><br>
> > # squid -v<br>
> > Squid Cache: Version 3.5.16<br>
> > Service Name: squid<br>
> >
Intercept/WCCPv2/LibreSSL/CRTD/(A)UFS/DISKD/ROCK/eCAP/64/GCC
Production<br>
> > configure options: '--prefix=/usr/local'
'--enable-translation'<br>
> > '--enable-external-acl-helpers=none'<br>
> '--enable-storeio=ufs,aufs,diskd,rock'<br>
> > '--enable-removal-policies=lru,heap' '--enable-wccp2'<br>
> > '--enable-follow-x-forwarded-for'
'--enable-cache-digests'<br>
> > '--enable-auth-negotiate=none' '--disable-auth-digest'<br>
> '--disable-auth-ntlm'<br>
> > '--disable-url-rewrite-helpers'
'--enable-storeid-rewrite-helpers=file'<br>
> > '--enable-log-daemon-helpers=file'
'--with-openssl=/usr/local'<br>
> > '--enable-ssl' '--enable-ssl-crtd' '--enable-zph-qos'
'--enable-snmp'<br>
> > '--enable-inline' '--with-dl'<br>
> '--with-build-environment=POSIX_V6_LP64_OFF64'<br>
> > 'CFLAGS=-O3 -m64 -pipe' 'CXXFLAGS=-O3 -m64 -pipe'<br>
> > 'LIBOPENSSL_CFLAGS=-I/usr/local/include'<br>
> > 'PKG_CONFIG_PATH=/usr/local/lib/pkgconfig'<br>
> '--disable-strict-error-checking'<br>
><br>
>
'--enable-build-info=Intercept/WCCPv2/LibreSSL/CRTD/(A)UFS/DISKD/ROCK/eCAP/64/GCC<br>
> > Production'<br>
> > IPtables Rules for redirection to squid ports<br>
> > -A PREROUTING -i wccp0 -p tcp -m tcp --dport 80 -j
REDIRECT --to-ports<br>
> 3127<br>
> > -A PREROUTING -i wccp0 -p tcp -m tcp --dport 443 -j
REDIRECT<br>
> --to-ports 3129<br>
> > -A POSTROUTING -j MASQUERADE<br>
><br>
><br>
> > Appreciate you kind asistance ....<br>
> > hanks in advance<br>
> > Maile<br>
><br>
><br>
><br>
> > --<br>
> > View this message in context:<br>
>
<a class="moz-txt-link-freetext" href="http://squid-web-proxy-cache.1019090.n4.nabble.com/help-for-my-intercept-proxy-setup-tp4677279.html">http://squid-web-proxy-cache.1019090.n4.nabble.com/help-for-my-intercept-proxy-setup-tp4677279.html</a><br>
> > Sent from the Squid - Users mailing list archive at
Nabble.com.<br>
> > _______________________________________________<br>
> > squid-users mailing list<br>
> > <a class="moz-txt-link-abbreviated" href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
> > <a class="moz-txt-link-freetext" href="http://lists.squid-cache.org/listinfo/squid-users">http://lists.squid-cache.org/listinfo/squid-users</a><br>
><br>
><br>
> Confidentiality Notice: This email (including any attachment)
is intended for internal use only. Any unauthorized use,
dissemination or copying of the content is prohibited. If you are
not the intended recipient and have received this e-mail in error,
please notify the sender by email and delete this email and any
attachment.<br>
> Confidentiality Notice: This email (including any attachment)
is intended for internal use only. Any unauthorized use,
dissemination or copying of the content is prohibited. If you are
not the intended recipient and have received this e-mail in error,
please notify the sender by email and delete this email and any
attachment.</span><br>
<br>
-----BEGIN PGP SIGNATURE-----
<br>
Version: GnuPG v2
<br>
<br>
iQEcBAEBCAAGBQJXH+bGAAoJENNXIZxhPexGs38IAK2ZRk2qXFIERPJgIudlhifu
<br>
BBY1CHHTQA7PQVctlPC/ed7HIYc33uNocWjWAwVXcVr0ER8UGqAw75ERfA+yfYkL
<br>
B/WU8+PIPX+Jm476Mh9y4Vd0GnK0jkANbuY5Fr6iWZJdIT6VXKWkIGKGjyZmERVc
<br>
1K9D60QNT5ndGxv7yJG55e0jaksP1+l71cLkSBvxhSwKYLKyV4QWSKvoGbrvwgSA
<br>
y5De3wiQIDJA7JLsox6HC3hfKCF3CqFGa/ccl6uvkK7vFl9BM5NXUg0TuGF1hrEQ
<br>
MJPIgvk3WFSBB3hPN33l+17oOhUsTnemLN2SykNwNmHYBsJUy2P1qy/8b50TMUE=
<br>
=9kyx
<br>
-----END PGP SIGNATURE-----
<br>
<br>
</body>
</html>