McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE Specifications

Browse online or download Specifications for Servers McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE. McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE Specifications User Manual

  • Download
  • Add to my manuals
  • Print

Summary of Contents

Page 1 - McAfee®EndpointEncryption

1McAfee®EndpointEncryptionEnterpriseBestPracticesGuideNovember2009

Page 2

10AnObjectDirectorywith5000usersand5000systemscouldbeexpectedtogrowasfollows:TypicalGrowthof5000user/machineObjectDirectory

Page 3 - Contents

11GlobalDeploymentsThesingleserverapproachworkswellaslongastheendpointscanmakeandsustainaTCP/IPconnectiontotheserver.Depend

Page 4

12OptimisationActionsOverviewMcAfeegenerallyrecommendsthefollowingactions(mostofwhicharedescribedinmoredetaillater):•Optimizeh

Page 5 - Introduction

13NameIndexing(DBCFG.INI)Nameindexingshouldbeenabledonalldatabasesespeciallythosewithover1000endpointsorusers.Itwillbenoticeab

Page 6 - SolutionArchitecture

14LifeTime=86400Thetime(inseconds)forwhichtheindexwillbeusedbeforeitisautomaticallyre‐createdifsomebodylogsontothedatabase.T

Page 7 - ServerConfiguration

15TCP/IPKeepAliveTimeReductionReducethissettingonallEEPCserversfromtwohours(thedefault)tofiveminutes.Theserverwillrequireares

Page 8 - LoadBalancing

161. OpenRegedit.2. GotoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Filesystem.3. Intherightpane,lookfortheDwordnamedNtfsMf

Page 9

17 WindowsPerformanceBydefaulttheWindowsperformancesettingsaresetto‘Applications’.However,testingshoulddefinethebestsetting.

Page 10 - VirtualServers

18ObjectDirectoryPhysicalLocationConsiderationshouldbemadetothelocationoftheObjectDirectory.ThedefaultfinalfolderfortheEndpoi

Page 11 - OptimisationActions

19ObjectDirectoryMaintenanceMaintenanceIntroductionTokeepthedatabasecleanandhealthy,maintenanceisrequiredonaregularbasis.Thisma

Page 12

2Copyright©2009McAfee,Inc.AllRightsReserved.Nopartofthispublicationmaybereproduced,transmitted,transcribed,storedinaretrieval

Page 13 - DBCFG.INI

20ToexportandthenclearALLuserauditsusethiscommand:SBADMCL–Command:DumpUserAudit–Adminuser:Admin–Adminpwd:mypassword–File:c:\dump\Dum

Page 14 - Groupsizes

21OrphanedObjectsTobeginacleanup,thedatabasestartswithwhatareknownas“Orphaned”objects.TheseareobjectsthatexistintheObjectDi

Page 15 - Procedure

22DumpMachineDescriptionIfobjectsseemtohangtheManagerwhenopened,thenattempttodumpthemachinedescriptiontofindwhichobjectsarea

Page 16 - Anti‐VirusScanner

23UserObjects‐GeneralPerformanceTipsEEPCcansupportthousandsofuserspergroupandpermachine.Thatsaid,forperformanceandsecurityre

Page 17 - ConnectionSpeed

24GeneralAdviceDefaultProductsettings(formaximumcompatibility).InstallingtheEndpointEncryptionManager(EEM)usingthedefaultsettings

Page 18 - SBSERVER.INI

25oftheothergroupsshouldnotbeusedunlessthereisaspecificreason.Theseusuallyinclude“EEPC52OPTION:”orsimilaratthestartofthena

Page 19 - ObjectDirectoryMaintenance

26• Whenusingsmartcardreadersandtokens,avoidassigningmanyoralloftheReaderorTokenfilegroupstogether.Whilsttheycanbeusedto

Page 20 - DeletedItemsCleanup

3ContentsINTRODUCTION 5PURPOSEOFTHISGUIDE 5RELEVANTPRODUCTS 5SOLUTIONARCHITECTURE 6DESIGNPHILOSOPHY 6SERVERCONFIGURATION 7BASIC

Page 21 - CleanupCommands

4OBJECTDIRECTORYMAINTENANCE 19MAINTENANCEINTRODUCTION 19ENVIRONMENT 19AUDITMAINTENANCE 19EXTRACTINGANDCLEARINGAUDITFROMTHEDATABASE

Page 22 - DumpMachineDescription

5IntroductionPurposeofthisGuideWhenplanningalargerolloutofEndpointEncryptionv5,itisimportanttounderstandtheprocessofscalingt

Page 23

6SolutionArchitectureDesignPhilosophyMcAfeeEndpointEncryptionisaclient/serverapplicationdesignedtobeimplementedwithasimple,single

Page 24 - GeneralAdvice

7ServerConfigurationBasicServerRequirementsTheEndpointEncryptionCommunicationsServerprocessrunsunderMicrosoftWindows2000/2003.Cur

Page 25 - Thingstoavoid

8ServerRedundancyItisriskytohaveasinglephysicalserverforyourenterprise,evenifyoutakeregularbackups.Werecommendyoutotakeste

Page 26

9ServerandObjectDirectoryOptimisationEndpointtoServerCommunication‐NetworkLoadEstimationEndpointEncryptionnetworktrafficistheea

Comments to this Manuals

No comments