McAfee GUARD DOG 2 Guía de instalación Pagina 6

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 25
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 5
2
McAfee
®
IntruShield
®
IPS System IntruShield Best Practices
Special Topics: Best Practices Pre-installation considerations
1
Pre-installation considerations
Hours and even days can be saved during the IntruShield installation and tuning process
if you are fully prepared. The IntruShield Troubleshooting Guide spells out the list of
tasks that you should complete before you schedule your IntruShield Manager software
installation.
Hardware requirements
The larger your deployment, the more high-end your Manager server should be. Many
IntruShield issues result from an underpowered Manager server.
For example, to manage 40 or more sensors, we recommend going beyond the
hardware recommended in the release notes. The following is a recommended
minimum hardware configuration:
Manager server with embedded MySQL database
4GB RAM
2 x 3.2 Pentium processors
80 GB hard disk space (or greater)
Determining your database size
The amount of space your database will require is governed by many factors, most of
which are unique per deployment. They boil down to how much data you want to retain
in the database and for how long.
Things to consider when planning are:
Aggregate alert and packet log volume from all sensors—Many sensors equals
higher alert volume and will require additional storage capacity. Note that an alert is
roughly 200 bytes on average, while a packet lot is approximately 450 bytes.
Lifetime of alert and packet log data: How long before you archive and then delete
an alert? Maintaining your data for a long period of time (e.g., one year) will require
additional storage capacity to accommodate both old and new data.
As a best practice, McAfee recommends archiving and deleting old alert data regularly
and attempting to keep your active database to about 40GB.
Note
The IntruShield Troubleshooting Guide is a new document as of release 3.1; however,
most of the techniques described in the document apply to all versions of IntruShield.
Note
You will experience better performance in your configuration and data forensic tasks
by connecting to the Manager from a browser on a client machine. Performance may
be slow if you connect to the Manager using a browser on the server machine itself.
Note
You can find capacity planning information in the Manager Administrator’s Guide,
Appendix B.
Vista de pagina 5
1 2 3 4 5 6 7 8 9 10 11 ... 24 25

Comentarios a estos manuales

Sin comentarios