Good morning,
We are having problems with multicating between our BlueCoat devices. We have 2x 8100-5 ProxySG devices sitting in a DMZ. They are sitting behind a Cisco 6513 (setup as a layer3 switch). The devices are configured to be active active, using DNS RoundRobin for load-balancing.
Our issue right now is that the devices can not communicate with each other via the multicast/broadcast communication, so they are unaware of which one is master. This is causing multiple issues with nightly process that run.
I believe that the BlueCoat side is configured properly using two VIP’s one being the master on each device. Each VIP has it’s own multicast IP of 224.x.x.x. Currently device A shows the first VIP as master, and so does device B. Same goes for the 2nd VIP, both devices showing as master.
Failover Config (from device A)
Group Address: 10.x.x.x
Multicast Address : 224.1.2.2
Local Address : 10.x.x.x
Secret : none
Advertisement Interval : 20
Priority : 254
Current State : MASTER
Flags : V(Virtual IP) M(Configured Master)
Group Address: 10.x.x.x
Multicast Address : 224.1.2.3
Local Address : 10.x.x.x
Secret : none
Advertisement Interval : 20
Priority : 100
Current State : MASTER
Flags : V(Virtual IP)
Global multicasting has been turned up on the switch, however the devices still will not communicate with each other. Short of putting in two static routes on the switch for the MAC of each VIP, I’m not sure what to do next. Logical next step would be to purchase a Physical load-balancer for that DMZ to eliminate the need for multicasting but we are hopping to use the current hardware we have in place.
Does anyone have any idea where or what to look at next?
Thanks in advance…
