VMware ACE 2.5, ACE EN-000042-00 User manual

  • Hello! I am an AI chatbot trained to assist you with the VMware ACE 2.5 User manual. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
ACE Management Server
Administrator’s Manual
VMware ACE 2.5
VMware, Inc.
3401 Hillview Ave.
Palo Alto, CA 94304
www.vmware.com
2 VMware, Inc.
ACE Management Server Administrator’s Manual
You can find the most up-to-date technical documentation on the VMware Web site at:
http://www.vmware.com/support/
The VMware Web site also provides the latest product updates.
If you have comments about this documentation, submit your feedback to:
docfeedback@vmware.com
© 2007, 2008 VMware, Inc. All rights reserved. Protected by one or more U.S. Patent Nos. 6,397,242,
6,496,847, 6,704,925, 6,711,672, 6,725,289, 6,735,601, 6,785,886, 6,789,156, 6,795,966, 6,880,022,
6,944,699, 6,961,806, 6,961,941, 7,069,413, 7,082,598, 7,089,377, 7,111,086, 7,111,145, 7,117,481,
7,149,843, 7,155,558, 7,222,221, 7,260,815, 7,260,820, 7,269,683, 7,275,136, 7,277,998, 7,277,999,
7,278,030, 7,281,102, 7,290,253, 7,356,679, 7,409,487, 7,412,492, 7,412,702, and 7,424,710; patents
pending.
VMware, the VMware “boxes” logo and design, Virtual SMP, and VMotion are registered trademarks or
trademarks of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names
mentioned herein may be trademarks of their respective companies.
ACE Management Server Administrator’s Manual
Item: EN-000042-00
VMware, Inc. 3
Contents
AboutThisBook 7
1 Introduction 9
FeaturesofACEManagementServer 9
SystemRequirements 11
RequiredHardware 11
SupportedOperatingSystems 11
SupportedExternalDatabases 12
SupportedProxies 12
RequiredWebBrowsers 12
Licensing 12
2 PlanninganACEManagementServerDeployment 13
DeploymentComponents 13
HostSystemOptions 15
WindowsHosts 15
LinuxHosts 15
ServerApplianceOption 15
DatabaseOptions 16
ActiveDirectoryAuthenticationOptions 17
PerformingCapacityPlanning 17
DatabaseThroughputandScalability 18
LDAPThroughput 18
NetworkBandwidthandPolicyUpdateFrequency 19
ACEPolicyConfiguration 20
LoadBalancers 20
SecurityFeaturesandConsiderations 20
UsingSSLCertificatesandProtocol 21
AccessingACEManagementServerfromOutsidetheCorporateFirewall 22
DeploymentPlanningWorksheet 24
ACE Management Server Administrator’s Manual
4 VMware, Inc.
3 InstallingandConfiguringACE Management Server 25
PreparingforInstallation 25
ConfigureTLSinYourBrowser 26
InstallingandUpgradingACEManagementServer 26
InstallanACEManagementServeronaWindowsHost 27
InstallACEManagementServeronaLinuxSystem 28
InstallanACEManagementServerAppliance 29
VerifyThattheApacheServiceIsStartedorRestarted 31
StartandConfigureACEManagementServer 33
LogInto
ACEManagementServer 34
4 ConfigurationOptionsforACEManagementServer 37
PrerequisitesforConfiguringtheServer 37
CreateUsersandGroupsforIntegrationwithActiveDirectory 38
SetUpanExternalDatabase 39
CreatingaSystemDSNEntryforanExternalDatabase 40
IncreasetheNumberofDatabaseConnectionsAllowed 42
EnableDatabaseConnectionPoolingonLinux 43
SetUpaConnectionBetweentheServerApplianceandanExternal
Database 43
Prepare
CustomSecurityCertificates 44
ViewthePropertiesoftheSelfSignedCertificateFile 45
StartingACEManagementServerConfiguration 45
ViewingandChangingLicensingInformation 46
UsinganExternalDatabase 46
CreatingAccessControl 47
UploadingCustomSSLCertificates 48
LoggingEvents 49
ApplyingConfigurationSettings 50
5 LoadBalancingMultipleACEManagementServerInstances 51
TypicalSetupUsingLoadBalancedACEManagementServerInstances 52
InstalltheRequiredServicesforLoadBalancing 53
UsetheSameSSLCertificateonAllServers 53
CreateNewSSLCertificatesandKeysforEachServer 55
InstallingandConfiguringtheLoadBalancer 57
VerifyThatACEInstancesAreUsingtheLoadBalancer 57
VMware, Inc. 5
Contents
6 ManagingACEInstances 59
ViewingACEInstancesThattheServerManages 60
UsetheVMwareACEHelpDeskApplication 60
UsetheInstanceViewinWorkstation 61
SearchforanInstance 62
SortbyColumnHeadingandChangeColumnWidth 63
Show,Hide,andMoveColumnsintheInstanceView 64
CreateorDeleteCustomColumnsintheInstanceView 64
ViewInstanceDetails 65
Reactivate,Deactivate,
orDeleteanACEInstance 65
ChangeaCopyProtectionID 66
ResettheAuthenticationPassword 66
AddInformationforCustomColumns 67
7 TroubleshootingandMaintenance 69
TroubleshootingConfigurationProblems 69
ConnectionProblemsBetweenaLinuxACEInstanceandACEManagement
Server 69
ChangethePortAssignmentforACEManagementServer 70
DeletetheServerConfigurationFileandSetaNewAdministrator
Password 71
RestoreaBackupCopyofanSSLCertificate 72
ConfiguringMultipleACEManagementServerInstancestoUseSSL 73
DatabaseBackup 74
Appendix:DatabaseSchemaandAuditEventLogData 75
UsingDatabaseReportingTools 75
DatabaseSchema 76
QueryingtheAuditEventLogData 81
Glossary 85
Index 89
ACE Management Server Administrator’s Manual
6 VMware, Inc.
VMware, Inc. 7
Thismanual,theVMwareACEManagementServerAdministrator’sManual,provides
informationaboutinstallingandusingtheVMware
®
ACEManagementServer,which
enablesyoutomanageACEinstancesinrealtime.UsingACEManagementServeris
optional,butdoingsoprovidesthefollowingbenefits:
ManageactivationofACEpackages.
Manageauthenticationofthoseactivatedpackages.
DynamicallydeliverpolicyupdatestomanagedACEinstances.
DynamicallydeliverinstancecustomizationdataformanagedACEinstanceswith
Windowsguestoperatingsystems.
Intended Audience
Thisbookisintendedforanyonewhoneedstoinstall,upgrade,oruseACE
ManagementServertomanageACEinstances.ACEManagementServerisintended
forACEadministratorswhomustmaintainandupdateACEpoliciesusedonvirtual
machinesdeployedthroughoutanenterprise.
Document Feedback
VMwarewelcomesyoursuggestionsforimprovingourdocumentation.Ifyouhave
comments,sendyourfeedbackto:
About This Book
ACE Management Server Administrator’s Manual
8 VMware, Inc.
Technical Support and Education Resources
Thefollowingsectionsdescribethetechnicalsupportresourcesavailabletoyou.
To accessthecurrentversionsofthisbookandotherbooks,goto:
http://www.vmware.com/support/pubs
Online and Telephone Support
Useonlinesupporttosubmittechnicalsupportrequests,viewyourproductand
contractinformation,andregisteryourproducts.Goto:
http://www.vmware.com/support
Customerswithappropriatesupportcontractsshouldusetelephonesupportforthe
fastestresponseonpriority1issues.Goto:
http://www.vmware.com/support/phone_support.html
Support Offerings
FindouthowVMwaresupportofferingscanhelpmeetyourbusinessneeds.Goto:
http://www.vmware.com/support/services
VMware Professional Services
VMwareEducationServicescoursesofferextensivehandsonlabs,casestudy
examples,andcoursematerialsdesignedtobeusedasonthejobreferencetools.
Coursesareavailableonsite,intheclassroom,andliveonline.Foronsitepilot
programs andimplementationbestpractices,VMwareConsultingServicesprovides
offeringsto helpyouassess,plan,
build,andmanageyourvirtualenvironment.To
accessinformationabouteducationclasses,certificationprograms,andconsulting
services,goto:
http://www.vmware.com/services
VMware, Inc. 9
1
TheVMwareACEManagementServerenablesyoutomanageVMwareACEinstances,
todynamicallypublishpolicychangesforthoseinstances,andtotestanddeploy
packagesmoreeasily.
Thischapterincludesthefollowingtopics:
“FeaturesofACEManagementServeronpage 9
“SystemRequirements”onpage 11
Features of ACE Management Server
ACEManagementServeroffersscalabilityandreliability:
Youcanincreasecapacitybyaddingnetworkresourcessuchasloadbalancersand
extraserverhardware.
Fortestingenvironments,thedefaultembeddedbackingstoreprovidesasimple
andefficientdatabasesolution.ToscaleACEManagementServerforproduction
deployments,youcanconfigureanduseanexternalrelationaldatabase
managementsystem(RDBMS).
InWindows,multithreadedprocesseshandleserverrequests.InLinux,multiple
processeshandleserverrequests.Ifoneprocessfails,anothertakesover.
ACEManagementServeroffersActiveDirectoryintegration:
YoucanuseActiveDirectorytoauthenticateusersofACEinstances.
YoudonotneedaschemachangeforyourexistingActiveDirectory.
LDAPisusedtoaccessActiveDirectory.
Introduction
1
ACE Management Server Administrator’s Manual
10 VMware, Inc.
InformationaboutWindowsdomainuseraccountstatesisprovidedinclearand
usefulmessages.Reasonsforloginfailuresarepresentedas“lockedout”or
“passwordexpired.”
ACEManagementServeractsasanActiveDirectorypasswordchangeproxy.
YoucanusetheinstancecustomizationfeatureinACEwithyourownestablished
namingconventionstoassociateuserswithmachines.
Securityfeaturesincludethefollowing:
EncryptedcommunicationsbetweenserverandclientstraveloverHTTPStraffic.
Passwordsarestoredsecurelyinhashedforminthebackingstore.
FlexibledatabaseoptionsallowuseofanembeddeddatabaseorexternalRDBMS
tostoreACEinstancedataandpolicies.
ACEManagementServeriseasytoinstallandconfigure.Clienttrafficcanbeproxied
byeasilyavailableproducts.Theserveruseseasilyavailablesoftwarecomponents:
ApacheWebserver2.0
ThedefaultSQLitedatabasestore
Theserversetupusesindustrystandardprotocols:
HTTPSandLDAP
XMLRPCformessageencapsulation
ACEManagementServeroffersextensibilityandavailability:
YoucancreateandusemorethanoneACEManagementServer.Whenyouuse
morethanoneserver,youcansettheserversupsothattheysharethesame
databaseforloadbalancingorincreasedfaulttolerance.
AWindowsACEManagementServercanbeonthesamesystemasWorkstation.
YoucandesignateasingleACEManagementServername,suchas
https://ace.policyserver.company.com,anduseDNSlookuptotranslate
thehostnametoanaddress.TheaddressiscachedifaDNSserverisnotavailable.
Additionally,youcanusedifferentACEManagementServerinstancesifusers
travelbetweenofficesin
differentgeographiclocations.
N
OTEYourservernamemustbeeitherthemachinenameinEnglishorthe
IP address.Internationalcharactersarenotsupported.
VMware, Inc. 11
Chapter 1 Introduction
System Requirements
ThefollowingsectionsdescribetheACEManagementServersystemrequirements.
Required Hardware
Aminimumofan800MHzcompatiblex86andx8664architectureprocessor
Compatibleprocessorsinclude:
Celeron,PentiumII,PentiumIII,Pentium4,PentiumM(includingcomputerswith
Centrinomobiletechnology),Xeon(includingPrestonia),AMD,Athlon,
Athlon MP,AthlonXP,Duron,Opteron,AMD64Opteron,andAthlon64
ExperimentalsupportforIntelIA32eCPU
40MBoffreespaceisrequiredforbasicinstallation.VMwarerecommendsatleast
10GBoffreediskspace.
An8bitdisplayadapterisrequired.
Forlocalareanetworking,anyEthernetcontrollerthattheoperatingsystem
supportsissufficient.
Supported Operating Systems
FollowingarethesupportedoperatingsystemsforACEManagementServer:
WindowsServer2003WebEditionSP1andSP2,WindowsServer2003Standard
EditionSP1andSP2,WindowsServer2003EnterpriseEditionSP1andSP2
(includes64bitandR2editions)
WindowsXPProfessional(includes64biteditions)
Windows2000ServerServicePack4andWindows2000AdvancedServerService
Pack 4
RedHatEnterpriseLinuxAdvancedServer4.0withUpdate 4.
SUSELinuxEnterpriseServer9ServicePack3
ACE Management Server Administrator’s Manual
12 VMware, Inc.
Supported External Databases
AnSQLitedatabaseengineisembeddedintheACEManagementServer.Althoughthis
databaseisadequatefortestingpurposes,useoneofthefollowingexternaldatabases
inproductionenvironments:
WindowsbasedserversMicrosoftSQLServer2000orhigher;
Oracle Database 10g
IfyouuseaMicrosoftSQLServerdatabase,thedatabasemustbehostedona
systemthatusesthesamelocaleasthesystemthathostsACEManagementServer.
Forexample,ifACEManagementServerisinstalledonaJapanese
system,the
databaseservermustalsobeinstalledonaJapanesesystemandmustuseJapanese
collation.
LinuxbasedserversPostgreSQL7.4orhigher;RedHatEnterpriseLinux
AdvancedServer4.5orhigher.
Supported Proxies
YoucandeployACEManagementServerwiththefollowingHTTPSproxysolutions:
ApacheProxyUsingmod_proxy
ZeusTechnologyLoadBalancerAcommerciallyavailableloadbalancerand
trafficmanagementsolution
Required Web Browsers
ThebrowserbasedACEManagementServerSetupapplicationandtheVMwareACE
HelpDeskapplicationrequireoneofthefollowingWebbrowsers:
MozillaFirefox1.52orhigher
InternetExplorer6.0orhigher
Licensing
YoumustconfiguretheserverandentertheserialnumberintheserversetupWeb
application.Ifyoudonot,youcannotconnecttotheserverinWorkstation.
Yourserialnumberisontheregistrationcardinyourpackage.Ifyoupurchased
VMwareACEonline,theserialnumberissentby
email.WorkstationandACE
instancescannotconnecttoanACEManagementServerwithanexpiredornonexistent
license.
VMware, Inc. 13
2
ThischapterprovidesguidelinesfordeployingVMwareACEManagementServer
instances,includingcapacityplanningandbestpractices.Thischapterincludesthe
followingtopics:
“DeploymentComponents”onpage 13
“PerformingCapacityPlanning”onpage 17
“SecurityFeaturesandConsiderations”onpage 20
“A c c e s s i n g ACEManagementServerfromOutsidetheCorporateFirewall”on
page 22
“DeploymentPlanningWorksheet”onpage 24
Deployment Components
AtypicalACEManagementServerdeploymenthasthefollowingcomponents:
OneormoreACEManagementServerinstancesConfiguringmultipleservers
tousethesamedatabaseincreasesthenumberofACEclientsyoucanmanageand
guaranteeshighavailability.
DatabaseserverForproductiondeployments,VMwarerecommendsOracle
Database 10gorMSSQLforACEManagementServerinstalledonaWindows
host,andPostgresforACEManagementServerinstalledonaLinuxhost.
(Optional)ActiveDirectorydomaincontrollerToenabletheACEManagement
ServerActiveDirectoryintegration,youmustconfigureACEManagementServer
tocommunicatewithyourdomaincontroller.
Planning an ACE
Management Server
Deployment
2
ACE Management Server Administrator’s Manual
14 VMware, Inc.
(Optional)HTTPloadbalancerUsealoadbalancertohelpscalethecapacityof
yourACEManagementServerdeployment.
(Optional)HTTPproxyIfclientswillaccessACEManagementServerfrom
outsidethecorporatefirewall,VMwarerecommendsusinganHTTPSproxyinthe
DMZ.YoucanuseACEManagementServerwithApacheProxyandZeus
TechnologyLoadBalancer.
ForanexampleofanACEManagementServerdeployment,seeFigure 21.
Figure 2-1. Comprehensive ACE Management Server Deployment
ACEManagementServeroffersconvenienceandflexibilityinitssetupoptions.
YoucaninstalltheserveronWindowsorLinuxhosts.Fortestingpurposes,youcan
downloadandruntheserverasavirtualappliance.ACEManagementServerincludes
itsownsecuritycertificatesandembeddeddatabase,butyoucanuse
anexternal
databaseandusecertificatesfromacertificateauthorityifyouprefer.Youcanalso
configureACEManagementServertouseActiveDirectoryforauthentication.
ACE Management Server
(one or more)
Active Directory
domain controlle
r
(optional)
database
server
proxy for ACE Management Server
service through corporate firewall
(optional)
WSAE client
(within
corporate
network)
load
balancer
(optional)
ACE Player client
(outside corporate network)
ACE Player client
(within
corporate
network)
LDAP
Kerberos
ODBC
HTTPS
HTTPS
HTTPS
HTTPSHTTPS
VMware, Inc. 15
Chapter 2 Planning an ACE Management Server Deployment
Host System Options
YoucaninstallACEManagementServeronaWindowshost,aLinuxhost,orasa
virtualappliance.IfyousetupmultipleACEManagementServerinstances,theymust
allbethesametype.
Windows Hosts
IfyouplantointegratewithActiveDirectory,VMwarerecommendsthatyouinstall
ACEManagementServeronaWindowshost.
TheWindowsACEManagementServerusestheWinLDAPlibrarybundledwithyour
WindowsoperatingsystemtointegratewithActiveDirectory.Internaltestingresults
indicatethattheWindowsimplementationprovidesbetterperformance
thanLinux.
Linux Hosts
YoucaninstallACEManagementServeronaLinuxhostanduseActiveDirectoryfor
authentication,eventhoughperformanceisslowerthanonWindowshosts.Ifyouplan
touseaLinuxhostinproductionenvironments,usetheLinuxinstallerratherthanthe
ACEManagementServerappliance.Ifyoudonot
havethesupportedLinuxoperating
systemsinstalledonaphysicalserver,youcancreateavirtualmachine,installa
supportedLinuxoperatingsystem,andinstallACEManagementServerinthevirtual
machine.
Server Appliance Option
TheACEManagementServerapplianceisaselfcontained,preinstalled,and
preconfiguredACEManagementServerpackagedwithasmallLinuxoperating
systeminavirtualmachine.Theapplianceisconvenientandquicktosetupinatesting
environmentbutisnotrecommendedforproductionenvironments.
Bydefault,theapplianceattempts
toconfigureitsnetworkbyusingDHCP.Ifyoudo
notwanttouseDHCP,youcanusethebrowserbasedACEManagementServerSetup
applicationtoconfigurethenetworksettings.Youcanusethesameinterfacetoupdate
theappliancewhenupdatesbecomeavailable.
Youmusthaveaccesstoa
Webbrowser(Mozilla1.52orhigherorInternetExplorer6.0
orhigher)tochangenetworksettingsorobtainupdatesfortheappliance.
ACE Management Server Administrator’s Manual
16 VMware, Inc.
Database Options
ACEManagementServeroffersthefollowingdatabaseoptions:
EmbeddedSQLitedatabaseThedefaultmodeofACEManagementServer
workswithanembeddedSQLite3databaseengine.TheSQLitedatabaseengineis
initializedduringserverinstallationandrequiresnospecialconfiguration.
The embeddeddatabasesupportsuptoseveralgigabytesofdata.
TheSQLitedatabaseisfilebasedandisnot
designedtobeeffectivelysharedacross
multipleprocesses.Ifyouusethirdpartytoolstoaccessthedatabaseforaread
operation,therefore,youcannotdependontransactionalisolationofthepending
writeoperationsoftheACEManagementServer.
Theembeddeddatabaseisadequatefortestingpurposes,butVMware
recommendsthat
youuseanexternaldatabaseinproductionenvironments.
SupportedexternaldatabaseInproductionenvironments,useasupported
externaldatabaseasabackingstoreforACEManagementServer,throughODBC
connectivity.Supportedexternaldatabaseenginesarethefollowing:
OnWindows,MicrosoftSQLServer(SQLServer2000orSQLServer2005)and
OracleDatabase10g
OnLinux,PostgreSQL7.4orhigher
UsinganexternaldatabasewithACEManagementServeroffersthefollowing
benefits:
OnlinebackupsothatyoudonothavetoshutdownACEManagementServer
tobackupthedatabase.
Enhancedsecuritymodel.Youcanfinetunepermissionstoaccesssensitive
data.TheSQLitedatabaseengineprovidesfilesystembasedsecurity.
Performancefinetuning.
Abilitytouseexternaldatabasemanagementandreportingtools.
AbilitytouseloadbalancerswithmultipleACEManagementServer
instances.YoumustuseanexternalRDBMSasthebackingstore,becausethe
SQLitedatabaseisnotdesignedtobeeffectivelysharedacrossmultiple
processes.
N
OTEIfACEManagementServerisdeployedintheDMZ,useanexternal
databaselocatedinsideyourcorporatenetworkbehindafirewall.
VMware, Inc. 17
Chapter 2 Planning an ACE Management Server Deployment
Active Directory Authentication Options
ActiveDirectoryintegrationprovidesthefollowingbenefits:
PermitsjoininganoperatingsystemthatisrunninganACEinstancetothedomain
remotely.
Providessearchfunctionssoyoucanquicklyfindaparticularindividualorgroup.
EnablesyoutouseActiveDirectoryUsersandGroupstoconfigurerolebased
accesstothefeaturesofACEManagementServer.
Performing Capacity Planning
ACEManagementServerenablesyoutomanageACEinstancesandpoliciesinreal
time.ThenumberofclientsthatasingleACEManagementServercanservedepends
onseveralkeyfactors:
Databasethroughputandscalability
LDAPthroughput(ifyouareusingActiveDirectory)
Networkbandwidthavailableforincomingclientrequests
ACEpolicyconfiguration
Loadbalancersforverylargedeployments(morethan5,000clients)
Table 21listsrecommendationsforthenumberofclientssupportedbasedonthe
hardwareyouareusing.Thefiguresforrecommendedclientsreservesomeserver
processingpowersothatinteractiveclientsreceiveresponsesinatimelyfashionand
theserversatisfies
increasesindemand.
Table 2-1. Number of Clients Supported
Hardware Recommended Clients
2GHzAMD2wayserver(Opteron280,4GBRAM) 6,000
2GHzIntel2waydesktopmachine(4GBRAM) 4,000
ACE Management Server Administrator’s Manual
18 VMware, Inc.
Database Throughput and Scalability
Forproductiondeployments,VMwarerecommendsthatyouuseOracle,MSSQL,or
Postgresasyourdatabaseplatform.
Morethan95percentofthestoragespacethatanACEManagementServerrequiresis
usedtologeventinformation,whichisanaudittrailofalltransactionsperformed
throughACEManagementServer.Table 2
2listsrecommendeddatabasesizesbased
onthenumberofclientsbeingserved.
Thefiguresinthetablearebasedona90daydatabasearchivalperiod.Backupthe
databaserecordsevery90daysandkeepeventlogsfor90days.YoucanconfigureACE
ManagementServertopurgeevent
logsevery90days.
Theauthenticationeventgeneratesmostofthedatabecauseaneventisgenerated
everytimesomeoneattemptstoauthenticatetoACEManagementServer.Youcan
configureACEManagementServertologlesseventinformation.See“LoggingEvents”
onpage 49.
LDAP Throughput
ACEManagementServercancommunicatewithyourActiveDirectorydomain
controllertoauthenticateusercredentials.Yourdomaincontrollerinfrastructure
handlestheLDAPtrafficrequiredtosupportthenumberofclientsthatyouanticipate.
IntegratingwithActiveDirectorythroughLDAPisimplementeddifferentlyinthe
WindowsACEManagementServerthaninthe
LinuxbasedACEManagementServer.
TheWindowsACEManagementServerusestheWinLDAPlibrarybundledwithyour
Windowsoperatingsystem.TheLinuxACEManagementServerusesathirdparty
KerberosLibraryandOpenSSL.VMwareinternaltestingresultsindicatethatthe
WindowsimplementationprovidesbetterperformancethanLinux.
Table 2-2. Database Storage Recommendations
Number of Clients Recommended Database Size
100 50Mb
1,000 500Mb
10,000 5,000Mb
VMware, Inc. 19
Chapter 2 Planning an ACE Management Server Deployment
Network Bandwidth and Policy Update Frequency
TheamountofnetworkbandwidththatACEManagementServerandACEinstances
requiredependsonthefrequencyofpolicyupdatesthatyouconfigure.Table 23shows
theamountofbandwidthneededwhenyouuseapolicyupdatefrequencyvalueof
10 minutes.
VMwarerecommendsthatforlargedeployments(morethan5,000clients),
you
increasethetimebetweenpolicyupdatesbyclientsbecausethisreducestheamountof
requiredbandwidth.
Table 24showsthebandwidthneededwhenthepolicyupdatefrequencyvalueisset
to30minutes.
Theamountofnetworkbandwidthrequiredcanalsobehigherifyourpolicysetisvery
complex.
VMware
recommendsthatyouhaveaseparatenetworklinkbetweenACE
ManagementServerandyourdatabaseserver,sothattrafficcomingandgoingfrom
ACEManagementServertoitsclientsdoesnotinterferewiththetraffictoandfrom
yourdatabaseserver.
Table 2-3. Network Bandwidth Required with a Policy Update Frequency of 10 Minutes
Number of Clients Bandwidth Required
100 0.125Mb/sec.
1,000 1.25Mb/sec.
10,000 12.5Mb/sec.
Table 2-4. Network Bandwidth Required with a Policy Update Frequency of 30 Minutes
Number of Clients Bandwidth Required
100 0.04Mb/sec.
1,000 0.4Mb/sec.
10,000 4Mb/sec.
ACE Management Server Administrator’s Manual
20 VMware, Inc.
ACE Policy Configuration
TheconfigurationofACEpoliciescanaffectperformance.Youcanincreasetheamount
ofdatathatistransferredbetweenACEManagementServerandACEPlayerbyusing
oneofthefollowingmethods:
HostpoliciesEnablinghostpolicies(suchashostnetworkquarantine)requiresthat
ahostsidedaemonretrievesthehostpoliciesfromtheACEManagementServ er.
ComplexnetworkquarantinepoliciesIfthesetofrulesthatmakesupyour
networkquarantineisverylarge,thetransferoftheserulesfromtheACE
ManagementServertotheclientscanaffectthescalability.
ThenumbersshowninTable 23andTable 24areestimatesofrequired
bandwidthgiven
averagesizerulesetsfornetworkquarantine.Youcanviewthe
sizeofyourpolicysetbyexaminingtheACEfiledirectoryandcountingthesize
ofthe.vmplfile.Anaveragepolicysetis15KBorless.
Load Balancers
TheACEManagementServerclientserverprotocolisbuiltontopoftheHTTPS
protocol.YoucanuseHTTPloadbalancingsoftwareandhardwaresolutionstoscale
anACEManagementServerdeploymentbeyondthecapacityofasingleserver(orfor
highavailabilitydeployments).
ACEManagementServerscalesinalinear
fashionwhenanenterprisegradeHTTPS
loadbalancerisused.SeeChapter 5,“LoadBalancingMultipleACEManagement
ServerInstances,”onpage 51.
Security Features and Considerations
Bydefault,ACEManagementServerusestheSecureSocketsLayer(SSL)protocolto
provideencryptedandsecurecommunications.
Followingisanoverviewofsecurityfeaturesandrecommendationsonhowto
configuretheACEManagementServertoavoidsecurityproblems:
TraffictoandfromclientsisprotectedbyHTTPSBydefault,ACEManagement
ServercreatesaselfsignedcertificatewhenyouinstallittouseforHTTPStraffic.
Thesecertificatesaresecure,butyoucanalsoconfigureACEManagementServer
touseyourowncertificateandkeypairs.
TrafficfromACEManagementServertoActiveDirectoryisencryptedIfthe
serverisintegratedwithanActive Directoryservice,itcommunicateswiththeservice
throughanSSLprotectedlink.LDAPtraf ficisencryptedattheapplicationlayer.
CredentialsareprotectedbyusingtheKerberosprot ocoltoauthenticatecredentials.
/