Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
615 Views 5 Replies Latest reply: Dec 12, 2012 9:40 AM by asabban RSS
bragot The Place at McAfee Member 38 posts since
Dec 9, 2009
Currently Being Moderated

Dec 11, 2012 6:13 PM

Which Proxy is Serving the Request

I have 2 Proxies in an HA configuration.  Couple of questions though:

 

1.  How does the director determine which proxy will handle the request?  One proxy has a priority of 99 and the other is 98.  Will 99 always handle all connections?

2.  Is there a way that I can determine which proxy handled the request?  I tried to modify the block page and placed the Proxy.IP variable in it, but it shows the virtual IP and not the physical IP of the machine which handled it.

 

Thanks!

  • eelsasser McAfee SME 842 posts since
    Mar 24, 2010
    Currently Being Moderated
    1. Dec 11, 2012 6:26 PM (in response to bragot)
    Re: Which Proxy is Serving the Request

    Does the System.HostName show the machine name on the block page?

  • asabban McAfee SME 1,354 posts since
    Nov 3, 2009
    Currently Being Moderated
    2. Dec 12, 2012 1:30 AM (in response to eelsasser)
    Re: Which Proxy is Serving the Request

    Hello,

     

    the priority defines which node is the director. The director with the highes priority will be the node which holds the virtual IP address. So all computers are talking to this node. The director intercepts all incoming packets on the configured ports before the reach the application (they are intercepted in the network driver). At this level the director forwards the packets across all scanning nodes (so all HA enabled nodes in the same area). They filter the traffic.

     

    Best,

    Andre

  • trishoar Apprentice 61 posts since
    Jan 28, 2010
    Currently Being Moderated
    3. Dec 12, 2012 5:35 AM (in response to bragot)
    Re: Which Proxy is Serving the Request

    Correct me if I'm wrong, but as I understood it there was only 1 proxy in an HA cluster, which is the Director node. All other nodes are Scaning nodes who's job it is to perform the filtering logic, the av scanning etc. They do not proxy any traffic. The access log would should only be on the Director, and System.HostName should always show the Director node. In the event of the Director failing the node with the next highest priority will be promoted to Director and start to proxy traffic. If there is more than 1 node with equal priority one will be elected as Director and keep its status until either a higher priory node appers or it dies.

     

     

    Tris

  • asabban McAfee SME 1,354 posts since
    Nov 3, 2009
    Currently Being Moderated
    5. Dec 12, 2012 9:40 AM (in response to bragot)
    Re: Which Proxy is Serving the Request

    Hello,

     

    the director knows all scanning nodes and knows how many connections they currently serve. If a new request from an unknown source IP comes in, the director forwards this traffic to the scanning nodes with the smallest number of current connections. If another request comes in from this source IP it will be forwarded to the same scanning node.

     

    If one IP is not seen for a specific time (I think 5 or 10 minutes) the director will forget about this source IP and the process starts over.

     

    If you see only one node doing the whole traffic this can have a number of reasons:

     

    - You have no port forwarding configured on the director. Even in Direct Proxy with HA a port redirect from 9090 to 9090 (or whatever port you like) is required. If there is no port redirect the network driver on the director will not redirect the traffic, but handle it locally

    - All you traffic is coming from the same source IP because there is a downstream proxy or a NATting device in place

    - The director does not know about other scanning nodes, you will need to review the HA configuration

     

    If you encounter a block page you should see the host name of the machine that blocked the request.

     

    Best,

    Andre

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points