Out-of-Path with WCCP Redundant (Active/Active) Appliances : Overview

Overview
Web Cache Communications Protocol (WCCP) supports the redirection of any TCP or UDP connections to appliances participating in WCCP Service Groups. The appliance intercepts only those packets that have been redirected to it. The appliance accelerates traffic flows that match its Route Policy; all other traffic passes through the appliance unmodified.
The two active Silver Peak appliances participating in the WCCP service group must be deployed out-of-path (Router mode). In this example, those appliances are at Site A. For the purposes of this specific example, Site B at the remote end deploys the appliance in-line (Bridge mode); there is no inherent restriction on what mode it needs to be.
WCCP at Site A
n
n
WCCP redirects all traffic that is in a WCCP Service Group shared by the appliance and router.
A service group consists of a set of WCCP-enabled routers and appliances that exchange WCCP messages. The routers send traffic to the appliances in the service group. The configuration of the service group determines how traffic is distributed to appliances in the service group.
n
To use WCCP, you must create a separate WCCP Service Group for each protocol (TCP and UDP) used in the SiteA-to-SiteB tunnel.
Network Diagram
Out-of-Path Deployment: Redundant Silver Peak Appliances peered with an L3 router using WCCP
The Silver Peak appliances optimize traffic to/from 10.110.31.0/24 and 10.110.11.0.0/24.
Summary
Each appliance’s wan0 interface connects to network
Do not connect lan0 interface of either appliance
Fail-Safe Behavior
Fail-safe behavior should always be tested before production deployment by ensuring that traffic continues to flow in each of the following cases:
1
2
3
Summary of Configuration Tasks
Physical appliance: Connect both appliances to the same available subnet via an Ethernet LAN switch. Verify connectivity, connect power, and verify LEDs.
Virtual appliance: Configure the hypervisor, with the required interfaces.
Configure an Access Control List (ACL) that redirects all traffic from the Site A subnet to the Site B subnet
Configure the WCCP Service Groups on Appliance A1
Configure the WCCP Service Groups on Appliance A2
Configure flow redirection for the Site A peers
When you create a cluster, the peers keep track of which appliance owns each flow. If the path between client and server isn’t the same in both directions, the flow is redirected to the appliance that first saw it and “owns” it.
Manually add Site A’s non-local subnets
Manually add subnets that aren’t directly connected to an appliance interface so they can be advertised.
Collecting the Necessary Information
The example makes the following assumptions:
n
n
n
Out-of-Path Deployment: Redundant Silver Peak Appliances peered with an L3 router using WCCP
mgmt0 IP Address / Mask1
LAN Next-hop IP Address (optional) 2

1
In this example, all mgmt0 IP addresses are in the same subnet. In your actual network, it’s likely that mgmt0 IP addresses are in different subnets.

2
LAN next-hop IP is only required when there are subnets for which the Silver Peak appliance does not have a configured IP address.


Please send comments or suggestions regarding user documentation to techpubs@silver-peak.com.