The connection between the Enforce Server console and the Cloud Service Gateway (CSG) disconnects every 1-2 minutes when EDM profiles are published to the CSG.
As a result of the disconnects, incidents cannot be delivered to the Enforce Server. Incidents will be queued at the CSG until delivery can be completed.
Release : 15.x
Component : DLP Enforce, utilizing Cloud Services
When the Enforce Server replicates EDM profiles to the Cloud Detection Service, the CSG returns a zero window buffer for an extended period of time.
The F5 is configured to reset the connection when zero window buffers are observed for 20 seconds (Overview of the TCP profile (11.x) (f5.com)).
Recommendation:
Based on Broadcom’s understanding of the F5, we do not recommend placing the F5 in between the Enforce Server and the CSG for the following reasons