McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE Specifiche Pagina 8

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 26
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 7
8
ServerRedundancy
Itisriskytohaveasinglephysicalserverforyourenterprise,evenifyoutakeregularbackups.Werecommend
youtotakestepstoexpediterecoveryfromanoutageinaccordancewithanestablishedBusinessContinuity
andDisasterRecovery(BCDR)plan.
HotBackupDatabases
IncreasetheredundancyofthesystembyreplicatingtheEndpointEncryptionObjectDirectorytoasecond
physicalserver.Adedicatedreplicationtool“ObjectDirectoryBackup”whichisoptimizedtofollowthe
changelogofanEndpointEncryptionv5ObjectDirectoryissuppliedwiththeproductsuite.
Inthiscasesetuparesilientsystemusingtwophysicalboxes,bothhostingEndpointEncryptionServersone
hostingthemasterOD
Bandtheotherhavingahotbackup.Incasethemasterserverfails,theEndpoint
EncryptionServeronthesecondbackupboxcanberestartedin“master”mode.Thenrebuildorreplacethe
affectedmachineandcreateanewmaster.
TheODBBackuputilitycanalsobeusedtomakeregularbac
kupsoftheODB,givingfurtherrecoveryoptions
incaseofadisaster.Thismethodhowever,requiresmanualinteractiontostartthefailover.
AHotBackupdocumentdiscussingthis scenarioisavailable.
Clustering
Fullyautomatedfailoversforapplicationsusuallyemployaclusterserverenvironment.AlthoughtheMcAfee
EndpointEncryptionObjectDirectoryandManagercanrunonacluster,werecommendagainstusing‘shared’
resourceswherepossible.AsperMcAfeeKB53698,WindowsClusterenvironmenthasnotbeenfullytestedat
thistimeinengineering.
LoadBalancing
GiventhebestconfigurationisusuallyasinglehighperformanceserverwithDASthentheleastoptimalwayto
performclusteringistoputtheObjectDirectoryonanetworkshare(NAS)andtheninstalltheManagement
Centerontwoserverswhichaccessthesharesimultaneously.
NOTE:Thelatterwillfunctio
n,butitwillbesignificantlydetrimentaltoserverperformance.
Youshouldnotethatifyouusespecialloadbalancingswitchestosplitnetworkload,youshouldsetthemto
alloweachclientactiveconnectiontooccurwiththesameswitchthroughoutthesyncevent(andnot
split/distributeeachpacketdu
ringasinglesync).
Makingremoteconnectionstothedatabaseisslowerthanlocalconnections,sothisdesignisoftentooslow
toworkeffectively.
IfDASisnotusedandthereareissuessuchasperformance,objectcorruption(especiallyasobjectnumbersin
theMcAfeeEndpointEncryptionObjectDire
ctoryincrease)McAfeesupportwillrecommendmovingtoDAS
andhighperformancededicatedserver.
IfaSANistheonlyoptionavailable,pleasenoteSANarrayscanprioritizetheconnectionstothephysicalbox
inwhatisknownasTierlevels.Tier1isthehighestpriority,Tier3isthelo
west.McAfeeEndpointEncryption
needsoptimaldiskaccesssowouldneedTier1prioritywithdedicatedLUNStoprovidethehighestspeed
connection.Thisisnecessaryforfullandpromptservicesynchronizationrequestsandadministration.This
avoidscorrupteddatabases,objects,clientsandslowadministrationperformance.RunningonSANisnot
recommended,bu
tifitmustbedone,thentheconnectionmustbeTier1.
Vedere la pagina 7
1 2 3 4 5 6 7 8 9 10 11 12 13 ... 25 26

Commenti su questo manuale

Nessun commento