Can the built-in ProxySG failover feature redirect traffic from one network segment to another if a switch/firewall fails?
search cancel

Can the built-in ProxySG failover feature redirect traffic from one network segment to another if a switch/firewall fails?

book

Article ID: 165492

calendar_today

Updated On:

Products

ProxySG Software - SGOS Advanced Secure Gateway Software - ASG Advanced Secure Gateway Software - ASG ISG Proxy

Issue/Introduction

Can the built-in ProxySG failover feature redirect traffic from one network segment to another if a switch/firewall fails?

 

Resolution

The ProxySG appliance cannot redirect traffic from one network segment to another when a switch/firewall fails as failover relies on the ability of two or more proxies to be able to send and receive multicast traffic between each other. In the event that the ‘Master’ proxy does not respond to this traffic, the ‘Secondary’ proxy takes over. This means that the Master must no longer be functional, or is no longer able to communicate with the Secondary proxy.

If the two proxies are handling two different network segments, then assuming a device upstream from the proxy fails, this will not hamper the ability of the two proxies to be able to communicate the multicast traffic, which means there will be no proxy failover occurring. As a result, the traffic will still be sent to the Master proxy even if there is an outage upstream.