We found that if the proxy configuration is using tcp-tunnel for Google Talk connections, the ProxySG appliance encountered a high client worker issue reaching the maximum capacity of the box.
edit "GoogleTalk" ;mode add all 10.1.0.0/16 443 intercept add all 172.16.0.0/16 443 intercept add all 184.108.40.206/16 443 intercept add all 220.127.116.11/16 443 intercept attribute use-adn disable attribute adn-optimize disable exit
Another method to identify this issue is by examining the TCP connections table through https://<proxy-ip>:8082/TCP/Connections, and seeing if the top connections (tunnels) are in Google Talk IP ranges. For example:
To resolve the issue, reduce the TCP-keepalive-timeout value from 7200 to 120 seconds. This will help the ProxySG detect the tunnel status, which may had been closed by the server already and therefore the ProxySG can close it as well.
#(config)tcp-ip tcp-keepalive-timeout 120
Imported Document ID: 000009672
Subscribing will provide email updates when this Article is updated. Login is required.