McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE Specifications Page 9

  • Download
  • Add to my manuals
  • Print
  • Page
    / 26
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 8
9
ServerandObjectDirectoryOptimisation
EndpointtoServerCommunication‐NetworkLoadEstimation
EndpointEncryptionnetworktrafficistheeasiesttoconsiderintermsof“synchronizationevents”.Eachtimea
systemstartsittriestoconnecttoadesignatedEEPCdatabasecommunicationserverandupdateitsprofile.It
mayalso(dependinguponconfiguration)trytoconnectperiodically.Inlargedeployments,thefirststepin
estimatingth
enetworkloadcausedbyEndpointEncryptionistoestimatethepeaknumberofconcurrent
synchronizationevents.Thisisrelatedtotheuserworkingpractices.Forexample,if2000usersswitchtheir
systemsonat9A.M,the“9A.M.”effectcanbedilutedbysettingoptionalbootsyncdelayandof
fsettimesto
spreadtheloadacross,forexampleonehour.
Oncepeakflowisestimated,doubleittogivesomesafety,thenworkonanestimateof7KBperuserpersync
(thisisaveryhighapproximationbasedontotalupdateoftheusereverytwosyncevents).AtypicalWindows
server,inourexp
erience,canaccept100connectionspersecondperserver,withadefaultmaximumwait
timeof30secondsforpendingconnections.
ThemaximumcapabilityofasingleCommunicationsServer,takingthecapacityofthenetworktobe100
Mbps(1millionbitspersec
ond)is20synchronizationsofdataasecond.AWindowsserverOScanestablish
connectionsaboutevery10ms,andcanhandleunlimitedconnections(althougheventuallyitwillrunoutof
clockcyclesandmemory).
Onceestablished,aconnectioncantakeanunlimitedamountoftimetofinish,thoughthedef
aulttimeouton
establishingaconnectionis30seconds.Iftherearemorethan100attemptedconnectionspersecond,the
queuecannotbelongerthan3,000connections.
ThedefaultsettingsoftheCommunicationServerlimitthequeueto200entries(abalancebetweentaking
connectionsandprocessingconnections).Afterthatpoin
t,theconnectionsarerefused.Thisisareasonable
“realworld”setting.Aslongastheprofileofthesystemissettoretrytheconnectionafter,forexample,four
hours,thereisnolossoffunction.Settingthequeuelengthtomorethan1500canresultinpoorperformance
fromtheserverasittriestose
rvicesomanyconnections.
Inrealtermswecansaythatasageneralmaximumcase,theEndpointEncryptionServerislimitedto100
connectionspersecond,withasustainedload.Saturationinourexperienceisreachedwhenthereismore
than1400synchronizationev
entsperminute(1200acceptedandprocessed,200queued).Achievingthisload
intherealworldrequiresamassive,badlyplannedandconfiguredpopulationofsystems.Currentcustomers
with40000+installationsrarelyexceedthe200currentconnectionpoints,mostofwhichareadministrators
performingconfigurationchanges.
Theoperatingsystemordiskcontrollercac
hesmostofEndpointEncryption’sdatabase,soeventuallythe
commonfileswillbesuppliedfromRAMratherthanacrosstheconnectiontothedatabasehost,or,fromdisk.
Usingthecompressedversionofthedatabasecanimproveperformancebyasmallamount,however,itis
usefulwhenco
rporatebackupsoftwarehasdifficultyarchivingthedatabase.
ThisroughcalculationtellsusthatweneedoneEndpointEncryptionServerper1400eventsaminute
minimum;however,experiencingthesysteminactionwillgivetruefeedback.Itisoftenthecasethatmodern
hardwareoutperformspaperestimations.
EstimatingtheSizeoftheObjectDirectory
ThebasesizeofanEndpointEncryption5.xObjectDirectoryisaround150MB.Becauseyouaddnewusers
andsystems,theODBgrowsaccordingly.Italsogrowsinsizeassystemssynchronizeanduploadaudit
information.
Page view 8
1 2 3 4 5 6 7 8 9 10 11 12 13 14 ... 25 26

Comments to this Manuals

No comments