I have a customer who has set up an 2 x ISA servers with load balancing. The outside ports connect to 2 x D Link switches (un- managed). The inside connects to a single Cisco 2950 we manage.
DLink1 Dlink2 | |
--------------- | | ISA1 ISA2 | |
-------------- | Cisco 2950
The customer has configured an outside and inside virtual Ip address. Traffic from an outside source can send to the virtual IP ok. When configuring the virtual Ip address on the inside the ISA's cannot receive traffic.
The reason I think this is an issue to do with the 2950 is as follows:
A host has to arp for the virtual MAC address for the ISA's virtual IP address. As the virtual MAC is not known on any port the switch has to flood traffic out all ports. This can happen a lot apparently so I am wondering if the cisco switch is throttling the traffic by default due to lots of unknown unicasts. (seeI can't understand why this would work on the D Links but not the 2950. The 2950 config is very basic, no special features have been configured.
Anyone know how I can go about proving / ruling out an issue on the2950 ?