Specifications

8
ServerRedundancy
Itisriskytohaveasinglephysicalserverforyourenterprise,evenifyoutakeregularbackups.Werecommend
youtotakestepstoexpediterecoveryfromanoutageinaccordancewithanestablishedBusinessContinuity
andDisasterRecovery(BCDR)plan.
HotBackupDatabases
IncreasetheredundancyofthesystembyreplicatingtheEndpointEncryptionObjectDirectorytoasecond
physicalserver.Adedicatedreplicationtool“ObjectDirectoryBackup”whichisoptimizedtofollowthe
changelogofanEndpointEncryptionv5ObjectDirectoryissuppliedwiththeproductsuite.
Inthiscasesetuparesilientsystemusingtwophysicalboxes,bothhostingEndpointEncryptionServersone
hostingthemasterOD
Bandtheotherhavingahotbackup.Incasethemasterserverfails,theEndpoint
EncryptionServeronthesecondbackupboxcanberestartedin“master”mode.Thenrebuildorreplacethe
affectedmachineandcreateanewmaster.
TheODBBackuputilitycanalsobeusedtomakeregularbac
kupsoftheODB,givingfurtherrecoveryoptions
incaseofadisaster.Thismethodhowever,requiresmanualinteractiontostartthefailover.
AHotBackupdocumentdiscussingthis scenarioisavailable.
Clustering
Fullyautomatedfailoversforapplicationsusuallyemployaclusterserverenvironment.AlthoughtheMcAfee
EndpointEncryptionObjectDirectoryandManagercanrunonacluster,werecommendagainstusing‘shared’
resourceswherepossible.AsperMcAfeeKB53698,WindowsClusterenvironmenthasnotbeenfullytestedat
thistimeinengineering.
LoadBalancing
GiventhebestconfigurationisusuallyasinglehighperformanceserverwithDASthentheleastoptimalwayto
performclusteringistoputtheObjectDirectoryonanetworkshare(NAS)andtheninstalltheManagement
Centerontwoserverswhichaccessthesharesimultaneously.
NOTE:Thelatterwillfunctio
n,butitwillbesignificantlydetrimentaltoserverperformance.
Youshouldnotethatifyouusespecialloadbalancingswitchestosplitnetworkload,youshouldsetthemto
alloweachclientactiveconnectiontooccurwiththesameswitchthroughoutthesyncevent(andnot
split/distributeeachpacketdu
ringasinglesync).
Makingremoteconnectionstothedatabaseisslowerthanlocalconnections,sothisdesignisoftentooslow
toworkeffectively.
IfDASisnotusedandthereareissuessuchasperformance,objectcorruption(especiallyasobjectnumbersin
theMcAfeeEndpointEncryptionObjectDire
ctoryincrease)McAfeesupportwillrecommendmovingtoDAS
andhighperformancededicatedserver.
IfaSANistheonlyoptionavailable,pleasenoteSANarrayscanprioritizetheconnectionstothephysicalbox
inwhatisknownasTierlevels.Tier1isthehighestpriority,Tier3isthelo
west.McAfeeEndpointEncryption
needsoptimaldiskaccesssowouldneedTier1prioritywithdedicatedLUNStoprovidethehighestspeed
connection.Thisisnecessaryforfullandpromptservicesynchronizationrequestsandadministration.This
avoidscorrupteddatabases,objects,clientsandslowadministrationperformance.RunningonSANisnot
recommended,bu
tifitmustbedone,thentheconnectionmustbeTier1.