ProxySG & Advanced Secure Gateway

 View Only
  • 1.  ProxySG & CAS Integration

    Posted Jan 14, 2021 03:01 PM
    Edited by Sulman Mushtaq Mushtaq Hussain Apr 25, 2021 09:40 AM
    Hi everyone, we have one ProxySG appliance running 6.10.11.15 and  have CAS appliances running the version 2.3. We would like to integrate ProxySG with both CAS appliances in load balancing fashion, so that we don't run into latency issue or slowness for users.

    What is the best way to integrate ProxySG with both CAS to achieve the highest level of throughput and to avoid any slowness or performance degradation for the users?

    Looking forward for your valuable feedback. Thanks

    ------------------------------
    Symantec Enthusiast
    ------------------------------


  • 2.  RE: ProxySG & CAS Integration

    Posted Jan 15, 2021 02:54 PM
    Hello,

    Did you take a look at ICAP service group ? should be what you want : https://knowledge.broadcom.com/external/article/165590/how-to-configure-load-balancing-weightin.html

    Best regards,
    Furil


  • 3.  RE: ProxySG & CAS Integration

    Posted Feb 12, 2021 05:20 PM
    Hi Symantec Enthusiast,

    To enable load balancing, you need to group the relevant Content Analysis appliances together in a service group. A service group is a named set of ICAP services, which is configured on the ProxySG.

    An ICAP service group is automatically created when you add one or more Content Analysis appliances to the ProxySG. For example, the proxyav service group includes all response modification services configured on the ProxySG.

    To load balance, each service in the service group must be assigned a weight. This weight value specified determines the number of requests that will be directed to each Content Analysis in the service group.

    Tip: Because both of your CAS appliances are the same hardware model, it is recommended to assign them equal weights (so that they are used equally by the proxy).

    Note: An ICAP response load balancing policy is essentially the same as a standard ICAP response policy; the only difference is that you specify the service group as the response service object instead of the service.

    Here are links to the relevant documentation:

    "Load Balance Multiple Content Analysis Appliances":
    https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/content-analysis/3-0/sg-introduction/load_balancing.html

    "Specify Weight within an ICAP Service Group":
    https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/content-analysis/3-0/sg-introduction/load_balancing/specify_weight.html

    "Create Load Balancing Policy":
    https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/content-analysis/3-0/sg-introduction/load_balancing/load_balancing_policy.html

    Hope this helps!
    ---Sherri

    ------------------------------
    Technical Trainer and Consultant
    NetX Information Systems
    ------------------------------