cancel
Showing results for 
Search instead for 
Did you mean: 

McAfee Web gateway sending all traffic to different web gateway Clusters.

You have two cluster web gateway in same network eachcluster has two web gateway. And two Virtual IP.

Here your problem was current running McAfee web Gateway (INProduction) is sending traffic to standalone McAfee Web Gateway.

we have MWG1 172.16.1.51 and MWG2

172.16.1.52 which is clustered to IP 172.16.1.50, ( This Web gateway in production )

* We have another 2  MWG3 IP 172.16.1.101 and MWG4

IP 172.16.1.102 Cluster IP 172.16.1.100 (stand alone Servers Still Under Implementation)

* All the 4 WW servers are in same subnet.

Problem is production webgateway is sending traffic to stand alone servers like MWG3 IP 172.16.1.101 and MWG4  IP 172.16.1.102

Regards,

Sabin Karthikeyan.

0 Kudos
4 Replies
McAfee Employee

Re: McAfee Web gateway sending all traffic to different web gateway Clusters.

Following problem:

As all your servers are in the same subnet, the can see eachother. I suspect that all have Proxy HA enabled!? What will happen is, they will cluster together as a single large HA cluster.

Solution:

In case this is not wanted, here is the setting:

On the shell go to 

cd /etc/sysconfig

vi mfend

as last line add he highlighted section and use the same value for all appliances to be in one HA-cluster (I used the VRRP Router ID in my case):

### BEGIN AUTOGENERATED CONFIG

MFEND_MANAGEMENT='10.150.163.20'

MFEND_MODE='haproxy'

MFEND_ROLE='director'

MFEND_REDIRECT[0]='http 9090 vlan:none 9090'

### END AUTOGENERATED CONFIG

MFEND_LBID='51'

Michael

0 Kudos
asabban
Level 17

Re: McAfee Web gateway sending all traffic to different web gateway Clusters.

After that change a reboot is required.

Best,

Andre

0 Kudos
RayP
Level 7

Re: McAfee Web gateway sending all traffic to different web gateway Clusters.

Hi Michael and Andre,

Do I have to change the MFEND on both clusters or can i leave one cluster default and change at the other cluster the mfend file?

Regards,

Ray

0 Kudos
asabban
Level 17

Re: McAfee Web gateway sending all traffic to different web gateway Clusters.

Hi,

you can leave one default. Important is that both clusters have a different ID.

Best,

Andre

0 Kudos