2 Replies Latest reply on Jul 21, 2015 7:25 AM by clath13

    Seeing traffic from webgateways in ProxyHA to 255.255.255.255

    clath13

      Good morning,

      So my IDS is unhappy.  It keeps seeing traffic from the 2 web gateways I have in ProxyHA mode to 255.255.255.255 using the protocol 253 which, according to IANA, is a protocol used for testing.  So the Source is one of my Web Gateways and the Destination is 255.255.255.255 using Protocol 253.  I'm talking LOTS of traffic - 150k+ alerts since last week.  I've perused the Best Practices guide for ProxyHA but can't find any reference to this traffic just the multicast packet to 224.0.0.18.  It appears the traffic to 255.255.255.255 occurs around the same time as the traffic to 224.0.0.18.  I found a post - Re: McAfee Web Gateway 7 - broadcast - that discusses it but doesn't really say how to stop it.  I have a bond0 interface with a static IP configured, the 1st interface that makes up the bond has its IP configured as static (same IP as the bond) and the other as obtain automatically (DHCP).   Should both interfaces be set to DHCP with just the bond interface configured statically?  Or does this have nothing to do with the traffic I'm seeing?

      Thanks,

      Claire