Hi,
I use this on my VIPs without problem.The auto detection option means that the device checks every now and then if the internal server the VIP is mapped to is still available or not. If the server is unavailable, then the traffic will not be forwarded. The checking is done via ICMP.
To see it in action with a 'debug vip all' (internal address is 192.168.1.1, and this is for a VIP which is down currently):
## 2009-04-17 10:53:46 : ping call back 192.168.1.1, 1
## 2009-04-17 10:53:50 : ping call back 192.168.1.1, 1
## 2009-04-17 10:53:54 : ping call back 192.168.1.1, 1
## 2009-04-17 10:53:58 : ping call back 192.168.1.1, 1
## 2009-04-17 10:54:02 : ping call back 192.168.1.1, 1
## 2009-04-17 10:54:04 : Rev-VIP look-up for 192.168.1.1/1166(6) on 0.0.0.0/0(0)
## 2009-04-17 10:54:04 : No Rev-VIP found for 192.168.1.1/1166 (6)
I seem to remember that there were some issues in older versions of ScreenOS (years ago) with the auto-detection causing the VIPs to fail, but I'm not aware of a problem in the current implementation.I guess if the VIP internal host doesn't respond to ping then server auto-detection would also not be a good idea, or if there is some extra internal routing that is taking place. But if the internal server is within the subnet of the firewall and responds to ping, then I think it'll be okay.
Hope this helps.
Regards
Andy