AVIRA SECURITY MANAGEMENT CENTER - OPTIMIZATION FOR LARGE NETWORKS, SECURITY MANAGEMENT CENTER User Manual

HowTo
How to optimize
the Security Management Center
for large networks
August 2009
Content
1. Introduction............................................................................................................................... 2
2. Activation of the Pull Mode for the SMC Agents ......................................................... 2
3. How to define the events sent by the SMC Agent ..................................................... 3
4. Minimizing the Frontend Updates ..................................................................................... 4
5. Configuration of maximum connections of the Internet Update Manager ....... 5
6. Deactivation of the Function „Automatic Update“...................................................... 6
7. Network Structure / How to visualize the organizational structure in the
security environment .................................................................................................................. 7
8. How to use an SQL server as Event Data Base .......................................................... 7
2
1. Introduction
This document helps you to optimize the SMC for large installations (1000 or more administered computers). This document should be seen as a complement to the Security Management Center Server HowTo.
2. Activation of the Pull Mode for the SMC Agents
The SMC is using the push mode by default in order to get a direct connection to the SMC agent. But the push mode can decrease the amount of available ports in large networks. This mode requires that that the SMC server can directly reach every SMC agent. But computers which are connected to the network by NAT cannot directly be reached by the SMC server.
Additionally a direct connection between SMC server and SMC agent causes a network load which increases with the amount of administered computers.
In order to avoid a higher network load, we recommend you to use the pull mode on the SMC agent. Thereby the SMC doesn’t work in real time mode anymore but also computers which are connected via NAT can be administered. Besides the network load caused by the SMC or its agents is reduced.
3
The interval of the pull mode can be configured depending on the size and the available brandwidth of the network. The SMC agent logs on to the SMC every 60 minutes by default and looks for new commands/configurations and sends the current status of the computer.
3. How to define the events sent by the SMC Agent
You can discharge the event manager of the SMC and its data base by defining which kind of events should be sent to the SMC in the configuration of the SMC agent. We recommend you to ignore information events by default. Important events like warnings and errors are still sent to the SMC.
Loading...
+ 4 hidden pages