search cancel

ProxySG not replying to ARP request for the Virtual IP for which failover group is not configured

book

Article ID: 224373

calendar_today

Updated On:

Products

ProxySG Software - SGOS

Issue/Introduction

On two ProxySG one Failover group is configured using Virtual IP-1.

One additional Virtual IP-2 is configured on both ProxySG, but for Virtual IP-2 failover group is not configured in any of ProxySG.

Both ProxySG has the same VPM rules and Virtual IP-1 and Virtual IP-2 are being used in the VPM rules.

As per the above-mentioned scenario when failover happens and Master ProxySG becomes backup, this will cause an issue with both ProxySG not replying to ARP request for the Virtual IP-2 for which failover group is not configured and the result will be VPM rules configured with Virtual IP-2 will not work correctly.

Cause

Only Master ProxySG will send Gratuitous  ARP for Virtual IP-1 using which failover group is configured. For Virtual IP-2 for which the failover group is not configured hence any of the ProxySG will not send Gratuitous ARP for Virtual IP-2.

Resolution

Configure a separate failover group for all Virtual IPs using the different Multicast addresses on both ProxySG.

To configure the Failover group on ProxySG refer to KB How to setup multiple ProxySGs to provide failover for redundancy