Hello,
After analysis this is even worse .... the thing about CAS and proxy could ping each other, it is only if ping is initiated from CAS, 1st packet take around 1000ms then the response time is normal. When issue happen again and ping is initialized from proxy it says "host is down"... According to pcap when proxy would like to update its arp table the CAS never reply (you see the request on CAS interface) but if it is the contrary then issue is solved... This issue has been escalated to engineering team.
Apparently static arp is possible on the ISG but not sure if it can on application level I will check that later. Still this is only a workaround here.
Regarding your dedicated interface for CAS, do you have your CAS in the same subnet than your proxy application or completely different ?
for me, LAG5 (for proxy application : vlan 10 internal, vlan 20 external
2:3 (CAS), vlan 20
As interface sharing was possible, I even tried to move vlan 20 from LAG5 to 2:3 and create a new dedicated vlan for external connection on proxy side, but the connection does totally no longer work. I wanted to keep inter-application connection inside the ISG but seems like I will have to try set it on a totally separated subnet...
I will check again the release note for proxy application OS.
Anyway thanks for the quick feedback :)
Original Message:
Sent: Aug 12, 2024 05:35 PM
From: rockchick
Subject: ISG - Connection proxySG VA to CAS VA (same ISG)
Yep we discovered that too about VLAN trunking and had to give our CASs their own interface. It sucks and i agree that the documentation is misleading but it does mean that CAS then works.
What is the ICAP issue? Are you getting users being blocked with ICAP errors? ICAP threads maxed out? CAS CPU through the roof? Which AV engine(s) are you using? Are you ICAP scanning everything or do you have a bypass list?