[squid-users] WCCPv2 strangeness

From: Jason Taylor <j@dont-contact.us>
Date: Mon, 04 Dec 2006 17:31:52 -0500

Hello list-people,

I am experiencing some strangeness with WCCPv2 on squid 2.6.
My hunch is that the problem is likely on the cisco side.
I have tried this with squid 2.6-stable5 as well as the latest version
(20061204) which is supposed to allow for multi-router wccp2 configs.
At the moment, I can't even get one connection from one proxy to one
router working.

A tcpdump on the workstation trying to load a webpage shows normal tcp
session establisment (syn -->, <--syn-ack, ack-->, push -->) for the
first 4 packets.

However, a tcpdump on the GRE interface of the squid shows only the
first packet (SYN).
A tcpdump on the eth2 (where squid is listening) shows the SYN-ACK
packet being sent back to the workstation.

So where things seem to go wonky is for the third packet (ACK). It
never makes it to the squid. But this packet is sent by the workstation.

Since the squid never receives the ACK, it retransmits the SYN-ACK
several times.

My understanding of what is normal in a wccp environment is that *all*
traffic originating from the workstation is redirected to the proxy, so
a tcpdump of the gRE itnerface should be seeing the SYN, the ACK and the
PSH packets that originated from the workstation.

So what could be happening here? Any ideas?

/Jason
Received on Mon Dec 04 2006 - 15:32:00 MST

This archive was generated by hypermail pre-2.1.9 : Mon Jan 01 2007 - 12:00:01 MST