in
IEOC CCIE Forums

IEOC - INE's Online Community

Welcome to INE's Online Community - IEOC - a place for CCIE and CCENT candidates to connect, share, and learn. Our Online Community features CCIE forums and discussions for all tracks including Routing & Switching, Voice, Security, Service Provider, Wireless,, and Storage. Through these online communities you can discuss your questions with thousands of your peers, hundreds of CCIE's and INE's own team of world renowned CCIE instructors and authors, Brian Dennis - Quintuple CCIE #2210, Brian McGahan – Triple CCIE #8593, Petr Lapukhov - Quad CCIE #16379, and Mark Snow - Dual CCIE #14073.
Latest post 04-13-2016 5:32 AM by sherif-magdy. 2 replies.
Page 1 of 1 (3 items)
Sort Posts: Previous Next
  • 04-10-2016 5:33 AM

    Task 2.6

    Hi

    i have some points regarding this task needs some clarifcation for , 

    Both R1 and R2 performing (ZPFirwalling + Nat + WCCP) ,what is the order of operation for all of these ?

    why http traffic that will get redirected out g0/1.24 on R1 don't cause a state entry for the session ? as all tcp traffic are being inspected ?

    as in the solution pass action is applied for the return traffic !!

    also for the nat i see that the redirected traffic don't subjected for translation at all ! i dont understand this behavior and the documenation is not clear about that .

    thanks in advance

     

    • Post Points: 20
  • 04-13-2016 2:43 AM In reply to

    Re: Task 2.6

    Hi,

       WCCP is first, but even without that, think about it. When you redirect the packets via WCCP, it clearly mweans the packet does NOT traverse the router but is being redirected, so it makes sense it is not NAT'ed and it is not inspected by the firewall, as the packets being redirected clearly may, in general, not be routed back through the firewall at all, so it is useless to consume resources on the router to create a translation or to create a state entry in the inspection table.

    Regards,

    Cristian.

    Cristian Matei, CCIE #23684 (SC/R&S)
    cmatei@ine.com


    InternetworkExpert Inc.
    http://www.ine.com
    Online Community: http://www.ieoc.com
    CCIE Blog: http://blog.ine.com

     

    • Post Points: 20
  • 04-13-2016 5:32 AM In reply to

    Re: Task 2.6

    thanks cristian for your reply , i would thought about it this way if the WCCP redirection service was applied on the inside interface IN direction ,but it was applied on the outside interface out direction so i thought according to order of operation it will inspected first then natted , but i will keep that in mind, WCCP always first .

    THANKS

    • Post Points: 5
Page 1 of 1 (3 items)
IEOC CCIE Forums Internetwork Expert CCIE Training
About IEOC | Terms of Use | RSS | Privacy Policy
© 2010 Internetwork Expert, Inc. All Rights Reserved