2.5

Table Of Contents
ACE Management Server Administrator’s Manual
20 VMware, Inc.
ACE Policy Configuration
TheconfigurationofACEpoliciescanaffectperformance.Youcanincreasetheamount
ofdatathatistransferredbetweenACEManagementServerandACEPlayerbyusing
oneofthefollowingmethods:
HostpoliciesEnablinghostpolicies(suchashostnetworkquarantine)requiresthat
ahostsidedaemonretrievesthehostpoliciesfromtheACEManagementServ er.
ComplexnetworkquarantinepoliciesIfthesetofrulesthatmakesupyour
networkquarantineisverylarge,thetransferoftheserulesfromtheACE
ManagementServertotheclientscanaffectthescalability.
ThenumbersshowninTable 23andTable 24areestimatesofrequired
bandwidthgiven
averagesizerulesetsfornetworkquarantine.Youcanviewthe
sizeofyourpolicysetbyexaminingtheACEfiledirectoryandcountingthesize
ofthe.vmplfile.Anaveragepolicysetis15KBorless.
Load Balancers
TheACEManagementServerclientserverprotocolisbuiltontopoftheHTTPS
protocol.YoucanuseHTTPloadbalancingsoftwareandhardwaresolutionstoscale
anACEManagementServerdeploymentbeyondthecapacityofasingleserver(orfor
highavailabilitydeployments).
ACEManagementServerscalesinalinear
fashionwhenanenterprisegradeHTTPS
loadbalancerisused.SeeChapter 5,“LoadBalancingMultipleACEManagement
ServerInstances,”onpage 51.
Security Features and Considerations
Bydefault,ACEManagementServerusestheSecureSocketsLayer(SSL)protocolto
provideencryptedandsecurecommunications.
Followingisanoverviewofsecurityfeaturesandrecommendationsonhowto
configuretheACEManagementServertoavoidsecurityproblems:
TraffictoandfromclientsisprotectedbyHTTPSBydefault,ACEManagement
ServercreatesaselfsignedcertificatewhenyouinstallittouseforHTTPStraffic.
Thesecertificatesaresecure,butyoucanalsoconfigureACEManagementServer
touseyourowncertificateandkeypairs.
TrafficfromACEManagementServertoActiveDirectoryisencryptedIfthe
serverisintegratedwithanActive Directoryservice,itcommunicateswiththeservice
throughanSSLprotectedlink.LDAPtraf ficisencryptedattheapplicationlayer.
CredentialsareprotectedbyusingtheKerberosprot ocoltoauthenticatecredentials.