Hi Symantec Enthusiast,
To enable load balancing, you need to group the relevant Content Analysis appliances together in a service group. A service group is a named set of ICAP services, which is configured on the ProxySG.
An ICAP service group is automatically created when you add one or more Content Analysis appliances to the ProxySG. For example, the proxyav service group includes all response modification services configured on the ProxySG.
To load balance, each service in the service group must be assigned a weight. This weight value specified determines the number of requests that will be directed to each Content Analysis in the service group.
Tip: Because both of your CAS appliances are the same hardware model, it is recommended to assign them equal weights (so that they are used equally by the proxy).
Note: An ICAP response load balancing policy is essentially the same as a standard ICAP response policy; the only difference is that you specify the service group as the response service object instead of the service.
Here are links to the relevant documentation:
"Load Balance Multiple Content Analysis Appliances":
https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/content-analysis/3-0/sg-introduction/load_balancing.html"Specify Weight within an ICAP Service Group":
https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/content-analysis/3-0/sg-introduction/load_balancing/specify_weight.html"Create Load Balancing Policy":
https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/content-analysis/3-0/sg-introduction/load_balancing/load_balancing_policy.htmlHope this helps!
---Sherri
------------------------------
Technical Trainer and Consultant
NetX Information Systems
------------------------------
Original Message:
Sent: 01-14-2021 03:01 PM
From: sulman mushaq
Subject: ProxySG & CAS Integration
Hi everyone, we have one ProxySG S400-20 appliance running 6.7.4.15 and have 2 CAS S400-20 appliances running the version 3.0.2. We would like to integrate ProxySG with both CAS appliances in load balancing fashion, meaning ProxySG will send some traffic to one CAS and some traffic to other CAS so that we don't run into latency issue or slowness for users. On each CAS appliance we have setup 2 scanning profiles, so in total we have 4 scanning profiles on both appliance.
What is the best way to integrate ProxySG with both CAS to achieve the highest level of throughput and to avoid any slowness or performance degradation for the users?
Looking forward for your valuable feedback. Thanks
------------------------------
Symantec Enthusiast
------------------------------