VMware ACE EN-000042-00 User manual

Category
Servers
Type
User manual

This manual is also suitable for

ACE Management Server
Administrator’s Manual
VMware ACE 2.5
VMware, Inc.
3401 Hillview Ave.
Palo Alto, CA 94304
www.vmware.com
2 VMware, Inc.
ACE Management Server Administrator’s Manual
You can find the most up-to-date technical documentation on the VMware Web site at:
http://www.vmware.com/support/
The VMware Web site also provides the latest product updates.
If you have comments about this documentation, submit your feedback to:
docfeedback@vmware.com
© 2007, 2008 VMware, Inc. All rights reserved. Protected by one or more U.S. Patent Nos. 6,397,242,
6,496,847, 6,704,925, 6,711,672, 6,725,289, 6,735,601, 6,785,886, 6,789,156, 6,795,966, 6,880,022,
6,944,699, 6,961,806, 6,961,941, 7,069,413, 7,082,598, 7,089,377, 7,111,086, 7,111,145, 7,117,481,
7,149,843, 7,155,558, 7,222,221, 7,260,815, 7,260,820, 7,269,683, 7,275,136, 7,277,998, 7,277,999,
7,278,030, 7,281,102, 7,290,253, 7,356,679, 7,409,487, 7,412,492, 7,412,702, and 7,424,710; patents
pending.
VMware, the VMware “boxes” logo and design, Virtual SMP, and VMotion are registered trademarks or
trademarks of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names
mentioned herein may be trademarks of their respective companies.
ACE Management Server Administrator’s Manual
Item: EN-000042-00
VMware, Inc. 3
Contents
AboutThisBook 7
1 Introduction 9
FeaturesofACEManagementServer 9
SystemRequirements 11
RequiredHardware 11
SupportedOperatingSystems 11
SupportedExternalDatabases 12
SupportedProxies 12
RequiredWebBrowsers 12
Licensing 12
2 PlanninganACEManagementServerDeployment 13
DeploymentComponents 13
HostSystemOptions 15
WindowsHosts 15
LinuxHosts 15
ServerApplianceOption 15
DatabaseOptions 16
ActiveDirectoryAuthenticationOptions 17
PerformingCapacityPlanning 17
DatabaseThroughputandScalability 18
LDAPThroughput 18
NetworkBandwidthandPolicyUpdateFrequency 19
ACEPolicyConfiguration 20
LoadBalancers 20
SecurityFeaturesandConsiderations 20
UsingSSLCertificatesandProtocol 21
AccessingACEManagementServerfromOutsidetheCorporateFirewall 22
DeploymentPlanningWorksheet 24
ACE Management Server Administrator’s Manual
4 VMware, Inc.
3 InstallingandConfiguringACE Management Server 25
PreparingforInstallation 25
ConfigureTLSinYourBrowser 26
InstallingandUpgradingACEManagementServer 26
InstallanACEManagementServeronaWindowsHost 27
InstallACEManagementServeronaLinuxSystem 28
InstallanACEManagementServerAppliance 29
VerifyThattheApacheServiceIsStartedorRestarted 31
StartandConfigureACEManagementServer 33
LogInto
ACEManagementServer 34
4 ConfigurationOptionsforACEManagementServer 37
PrerequisitesforConfiguringtheServer 37
CreateUsersandGroupsforIntegrationwithActiveDirectory 38
SetUpanExternalDatabase 39
CreatingaSystemDSNEntryforanExternalDatabase 40
IncreasetheNumberofDatabaseConnectionsAllowed 42
EnableDatabaseConnectionPoolingonLinux 43
SetUpaConnectionBetweentheServerApplianceandanExternal
Database 43
Prepare
CustomSecurityCertificates 44
ViewthePropertiesoftheSelfSignedCertificateFile 45
StartingACEManagementServerConfiguration 45
ViewingandChangingLicensingInformation 46
UsinganExternalDatabase 46
CreatingAccessControl 47
UploadingCustomSSLCertificates 48
LoggingEvents 49
ApplyingConfigurationSettings 50
5 LoadBalancingMultipleACEManagementServerInstances 51
TypicalSetupUsingLoadBalancedACEManagementServerInstances 52
InstalltheRequiredServicesforLoadBalancing 53
UsetheSameSSLCertificateonAllServers 53
CreateNewSSLCertificatesandKeysforEachServer 55
InstallingandConfiguringtheLoadBalancer 57
VerifyThatACEInstancesAreUsingtheLoadBalancer 57
VMware, Inc. 5
Contents
6 ManagingACEInstances 59
ViewingACEInstancesThattheServerManages 60
UsetheVMwareACEHelpDeskApplication 60
UsetheInstanceViewinWorkstation 61
SearchforanInstance 62
SortbyColumnHeadingandChangeColumnWidth 63
Show,Hide,andMoveColumnsintheInstanceView 64
CreateorDeleteCustomColumnsintheInstanceView 64
ViewInstanceDetails 65
Reactivate,Deactivate,
orDeleteanACEInstance 65
ChangeaCopyProtectionID 66
ResettheAuthenticationPassword 66
AddInformationforCustomColumns 67
7 TroubleshootingandMaintenance 69
TroubleshootingConfigurationProblems 69
ConnectionProblemsBetweenaLinuxACEInstanceandACEManagement
Server 69
ChangethePortAssignmentforACEManagementServer 70
DeletetheServerConfigurationFileandSetaNewAdministrator
Password 71
RestoreaBackupCopyofanSSLCertificate 72
ConfiguringMultipleACEManagementServerInstancestoUseSSL 73
DatabaseBackup 74
Appendix:DatabaseSchemaandAuditEventLogData 75
UsingDatabaseReportingTools 75
DatabaseSchema 76
QueryingtheAuditEventLogData 81
Glossary 85
Index 89
ACE Management Server Administrator’s Manual
6 VMware, Inc.
VMware, Inc. 7
Thismanual,theVMwareACEManagementServerAdministrator’sManual,provides
informationaboutinstallingandusingtheVMware
®
ACEManagementServer,which
enablesyoutomanageACEinstancesinrealtime.UsingACEManagementServeris
optional,butdoingsoprovidesthefollowingbenefits:
ManageactivationofACEpackages.
Manageauthenticationofthoseactivatedpackages.
DynamicallydeliverpolicyupdatestomanagedACEinstances.
DynamicallydeliverinstancecustomizationdataformanagedACEinstanceswith
Windowsguestoperatingsystems.
Intended Audience
Thisbookisintendedforanyonewhoneedstoinstall,upgrade,oruseACE
ManagementServertomanageACEinstances.ACEManagementServerisintended
forACEadministratorswhomustmaintainandupdateACEpoliciesusedonvirtual
machinesdeployedthroughoutanenterprise.
Document Feedback
VMwarewelcomesyoursuggestionsforimprovingourdocumentation.Ifyouhave
comments,sendyourfeedbackto:
About This Book
ACE Management Server Administrator’s Manual
8 VMware, Inc.
Technical Support and Education Resources
Thefollowingsectionsdescribethetechnicalsupportresourcesavailabletoyou.
To accessthecurrentversionsofthisbookandotherbooks,goto:
http://www.vmware.com/support/pubs
Online and Telephone Support
Useonlinesupporttosubmittechnicalsupportrequests,viewyourproductand
contractinformation,andregisteryourproducts.Goto:
http://www.vmware.com/support
Customerswithappropriatesupportcontractsshouldusetelephonesupportforthe
fastestresponseonpriority1issues.Goto:
http://www.vmware.com/support/phone_support.html
Support Offerings
FindouthowVMwaresupportofferingscanhelpmeetyourbusinessneeds.Goto:
http://www.vmware.com/support/services
VMware Professional Services
VMwareEducationServicescoursesofferextensivehandsonlabs,casestudy
examples,andcoursematerialsdesignedtobeusedasonthejobreferencetools.
Coursesareavailableonsite,intheclassroom,andliveonline.Foronsitepilot
programs andimplementationbestpractices,VMwareConsultingServicesprovides
offeringsto helpyouassess,plan,
build,andmanageyourvirtualenvironment.To
accessinformationabouteducationclasses,certificationprograms,andconsulting
services,goto:
http://www.vmware.com/services
VMware, Inc. 9
1
TheVMwareACEManagementServerenablesyoutomanageVMwareACEinstances,
todynamicallypublishpolicychangesforthoseinstances,andtotestanddeploy
packagesmoreeasily.
Thischapterincludesthefollowingtopics:
“FeaturesofACEManagementServeronpage 9
“SystemRequirements”onpage 11
Features of ACE Management Server
ACEManagementServeroffersscalabilityandreliability:
Youcanincreasecapacitybyaddingnetworkresourcessuchasloadbalancersand
extraserverhardware.
Fortestingenvironments,thedefaultembeddedbackingstoreprovidesasimple
andefficientdatabasesolution.ToscaleACEManagementServerforproduction
deployments,youcanconfigureanduseanexternalrelationaldatabase
managementsystem(RDBMS).
InWindows,multithreadedprocesseshandleserverrequests.InLinux,multiple
processeshandleserverrequests.Ifoneprocessfails,anothertakesover.
ACEManagementServeroffersActiveDirectoryintegration:
YoucanuseActiveDirectorytoauthenticateusersofACEinstances.
YoudonotneedaschemachangeforyourexistingActiveDirectory.
LDAPisusedtoaccessActiveDirectory.
Introduction
1
ACE Management Server Administrator’s Manual
10 VMware, Inc.
InformationaboutWindowsdomainuseraccountstatesisprovidedinclearand
usefulmessages.Reasonsforloginfailuresarepresentedas“lockedout”or
“passwordexpired.”
ACEManagementServeractsasanActiveDirectorypasswordchangeproxy.
YoucanusetheinstancecustomizationfeatureinACEwithyourownestablished
namingconventionstoassociateuserswithmachines.
Securityfeaturesincludethefollowing:
EncryptedcommunicationsbetweenserverandclientstraveloverHTTPStraffic.
Passwordsarestoredsecurelyinhashedforminthebackingstore.
FlexibledatabaseoptionsallowuseofanembeddeddatabaseorexternalRDBMS
tostoreACEinstancedataandpolicies.
ACEManagementServeriseasytoinstallandconfigure.Clienttrafficcanbeproxied
byeasilyavailableproducts.Theserveruseseasilyavailablesoftwarecomponents:
ApacheWebserver2.0
ThedefaultSQLitedatabasestore
Theserversetupusesindustrystandardprotocols:
HTTPSandLDAP
XMLRPCformessageencapsulation
ACEManagementServeroffersextensibilityandavailability:
YoucancreateandusemorethanoneACEManagementServer.Whenyouuse
morethanoneserver,youcansettheserversupsothattheysharethesame
databaseforloadbalancingorincreasedfaulttolerance.
AWindowsACEManagementServercanbeonthesamesystemasWorkstation.
YoucandesignateasingleACEManagementServername,suchas
https://ace.policyserver.company.com,anduseDNSlookuptotranslate
thehostnametoanaddress.TheaddressiscachedifaDNSserverisnotavailable.
Additionally,youcanusedifferentACEManagementServerinstancesifusers
travelbetweenofficesin
differentgeographiclocations.
N
OTEYourservernamemustbeeitherthemachinenameinEnglishorthe
IP address.Internationalcharactersarenotsupported.
VMware, Inc. 11
Chapter 1 Introduction
System Requirements
ThefollowingsectionsdescribetheACEManagementServersystemrequirements.
Required Hardware
Aminimumofan800MHzcompatiblex86andx8664architectureprocessor
Compatibleprocessorsinclude:
Celeron,PentiumII,PentiumIII,Pentium4,PentiumM(includingcomputerswith
Centrinomobiletechnology),Xeon(includingPrestonia),AMD,Athlon,
Athlon MP,AthlonXP,Duron,Opteron,AMD64Opteron,andAthlon64
ExperimentalsupportforIntelIA32eCPU
40MBoffreespaceisrequiredforbasicinstallation.VMwarerecommendsatleast
10GBoffreediskspace.
An8bitdisplayadapterisrequired.
Forlocalareanetworking,anyEthernetcontrollerthattheoperatingsystem
supportsissufficient.
Supported Operating Systems
FollowingarethesupportedoperatingsystemsforACEManagementServer:
WindowsServer2003WebEditionSP1andSP2,WindowsServer2003Standard
EditionSP1andSP2,WindowsServer2003EnterpriseEditionSP1andSP2
(includes64bitandR2editions)
WindowsXPProfessional(includes64biteditions)
Windows2000ServerServicePack4andWindows2000AdvancedServerService
Pack 4
RedHatEnterpriseLinuxAdvancedServer4.0withUpdate 4.
SUSELinuxEnterpriseServer9ServicePack3
ACE Management Server Administrator’s Manual
12 VMware, Inc.
Supported External Databases
AnSQLitedatabaseengineisembeddedintheACEManagementServer.Althoughthis
databaseisadequatefortestingpurposes,useoneofthefollowingexternaldatabases
inproductionenvironments:
WindowsbasedserversMicrosoftSQLServer2000orhigher;
Oracle Database 10g
IfyouuseaMicrosoftSQLServerdatabase,thedatabasemustbehostedona
systemthatusesthesamelocaleasthesystemthathostsACEManagementServer.
Forexample,ifACEManagementServerisinstalledonaJapanese
system,the
databaseservermustalsobeinstalledonaJapanesesystemandmustuseJapanese
collation.
LinuxbasedserversPostgreSQL7.4orhigher;RedHatEnterpriseLinux
AdvancedServer4.5orhigher.
Supported Proxies
YoucandeployACEManagementServerwiththefollowingHTTPSproxysolutions:
ApacheProxyUsingmod_proxy
ZeusTechnologyLoadBalancerAcommerciallyavailableloadbalancerand
trafficmanagementsolution
Required Web Browsers
ThebrowserbasedACEManagementServerSetupapplicationandtheVMwareACE
HelpDeskapplicationrequireoneofthefollowingWebbrowsers:
MozillaFirefox1.52orhigher
InternetExplorer6.0orhigher
Licensing
YoumustconfiguretheserverandentertheserialnumberintheserversetupWeb
application.Ifyoudonot,youcannotconnecttotheserverinWorkstation.
Yourserialnumberisontheregistrationcardinyourpackage.Ifyoupurchased
VMwareACEonline,theserialnumberissentby
email.WorkstationandACE
instancescannotconnecttoanACEManagementServerwithanexpiredornonexistent
license.
VMware, Inc. 13
2
ThischapterprovidesguidelinesfordeployingVMwareACEManagementServer
instances,includingcapacityplanningandbestpractices.Thischapterincludesthe
followingtopics:
“DeploymentComponents”onpage 13
“PerformingCapacityPlanning”onpage 17
“SecurityFeaturesandConsiderations”onpage 20
“A c c e s s i n g ACEManagementServerfromOutsidetheCorporateFirewall”on
page 22
“DeploymentPlanningWorksheet”onpage 24
Deployment Components
AtypicalACEManagementServerdeploymenthasthefollowingcomponents:
OneormoreACEManagementServerinstancesConfiguringmultipleservers
tousethesamedatabaseincreasesthenumberofACEclientsyoucanmanageand
guaranteeshighavailability.
DatabaseserverForproductiondeployments,VMwarerecommendsOracle
Database 10gorMSSQLforACEManagementServerinstalledonaWindows
host,andPostgresforACEManagementServerinstalledonaLinuxhost.
(Optional)ActiveDirectorydomaincontrollerToenabletheACEManagement
ServerActiveDirectoryintegration,youmustconfigureACEManagementServer
tocommunicatewithyourdomaincontroller.
Planning an ACE
Management Server
Deployment
2
ACE Management Server Administrator’s Manual
14 VMware, Inc.
(Optional)HTTPloadbalancerUsealoadbalancertohelpscalethecapacityof
yourACEManagementServerdeployment.
(Optional)HTTPproxyIfclientswillaccessACEManagementServerfrom
outsidethecorporatefirewall,VMwarerecommendsusinganHTTPSproxyinthe
DMZ.YoucanuseACEManagementServerwithApacheProxyandZeus
TechnologyLoadBalancer.
ForanexampleofanACEManagementServerdeployment,seeFigure 21.
Figure 2-1. Comprehensive ACE Management Server Deployment
ACEManagementServeroffersconvenienceandflexibilityinitssetupoptions.
YoucaninstalltheserveronWindowsorLinuxhosts.Fortestingpurposes,youcan
downloadandruntheserverasavirtualappliance.ACEManagementServerincludes
itsownsecuritycertificatesandembeddeddatabase,butyoucanuse
anexternal
databaseandusecertificatesfromacertificateauthorityifyouprefer.Youcanalso
configureACEManagementServertouseActiveDirectoryforauthentication.
ACE Management Server
(one or more)
Active Directory
domain controlle
r
(optional)
database
server
proxy for ACE Management Server
service through corporate firewall
(optional)
WSAE client
(within
corporate
network)
load
balancer
(optional)
ACE Player client
(outside corporate network)
ACE Player client
(within
corporate
network)
LDAP
Kerberos
ODBC
HTTPS
HTTPS
HTTPS
HTTPSHTTPS
VMware, Inc. 15
Chapter 2 Planning an ACE Management Server Deployment
Host System Options
YoucaninstallACEManagementServeronaWindowshost,aLinuxhost,orasa
virtualappliance.IfyousetupmultipleACEManagementServerinstances,theymust
allbethesametype.
Windows Hosts
IfyouplantointegratewithActiveDirectory,VMwarerecommendsthatyouinstall
ACEManagementServeronaWindowshost.
TheWindowsACEManagementServerusestheWinLDAPlibrarybundledwithyour
WindowsoperatingsystemtointegratewithActiveDirectory.Internaltestingresults
indicatethattheWindowsimplementationprovidesbetterperformance
thanLinux.
Linux Hosts
YoucaninstallACEManagementServeronaLinuxhostanduseActiveDirectoryfor
authentication,eventhoughperformanceisslowerthanonWindowshosts.Ifyouplan
touseaLinuxhostinproductionenvironments,usetheLinuxinstallerratherthanthe
ACEManagementServerappliance.Ifyoudonot
havethesupportedLinuxoperating
systemsinstalledonaphysicalserver,youcancreateavirtualmachine,installa
supportedLinuxoperatingsystem,andinstallACEManagementServerinthevirtual
machine.
Server Appliance Option
TheACEManagementServerapplianceisaselfcontained,preinstalled,and
preconfiguredACEManagementServerpackagedwithasmallLinuxoperating
systeminavirtualmachine.Theapplianceisconvenientandquicktosetupinatesting
environmentbutisnotrecommendedforproductionenvironments.
Bydefault,theapplianceattempts
toconfigureitsnetworkbyusingDHCP.Ifyoudo
notwanttouseDHCP,youcanusethebrowserbasedACEManagementServerSetup
applicationtoconfigurethenetworksettings.Youcanusethesameinterfacetoupdate
theappliancewhenupdatesbecomeavailable.
Youmusthaveaccesstoa
Webbrowser(Mozilla1.52orhigherorInternetExplorer6.0
orhigher)tochangenetworksettingsorobtainupdatesfortheappliance.
ACE Management Server Administrator’s Manual
16 VMware, Inc.
Database Options
ACEManagementServeroffersthefollowingdatabaseoptions:
EmbeddedSQLitedatabaseThedefaultmodeofACEManagementServer
workswithanembeddedSQLite3databaseengine.TheSQLitedatabaseengineis
initializedduringserverinstallationandrequiresnospecialconfiguration.
The embeddeddatabasesupportsuptoseveralgigabytesofdata.
TheSQLitedatabaseisfilebasedandisnot
designedtobeeffectivelysharedacross
multipleprocesses.Ifyouusethirdpartytoolstoaccessthedatabaseforaread
operation,therefore,youcannotdependontransactionalisolationofthepending
writeoperationsoftheACEManagementServer.
Theembeddeddatabaseisadequatefortestingpurposes,butVMware
recommendsthat
youuseanexternaldatabaseinproductionenvironments.
SupportedexternaldatabaseInproductionenvironments,useasupported
externaldatabaseasabackingstoreforACEManagementServer,throughODBC
connectivity.Supportedexternaldatabaseenginesarethefollowing:
OnWindows,MicrosoftSQLServer(SQLServer2000orSQLServer2005)and
OracleDatabase10g
OnLinux,PostgreSQL7.4orhigher
UsinganexternaldatabasewithACEManagementServeroffersthefollowing
benefits:
OnlinebackupsothatyoudonothavetoshutdownACEManagementServer
tobackupthedatabase.
Enhancedsecuritymodel.Youcanfinetunepermissionstoaccesssensitive
data.TheSQLitedatabaseengineprovidesfilesystembasedsecurity.
Performancefinetuning.
Abilitytouseexternaldatabasemanagementandreportingtools.
AbilitytouseloadbalancerswithmultipleACEManagementServer
instances.YoumustuseanexternalRDBMSasthebackingstore,becausethe
SQLitedatabaseisnotdesignedtobeeffectivelysharedacrossmultiple
processes.
N
OTEIfACEManagementServerisdeployedintheDMZ,useanexternal
databaselocatedinsideyourcorporatenetworkbehindafirewall.
VMware, Inc. 17
Chapter 2 Planning an ACE Management Server Deployment
Active Directory Authentication Options
ActiveDirectoryintegrationprovidesthefollowingbenefits:
PermitsjoininganoperatingsystemthatisrunninganACEinstancetothedomain
remotely.
Providessearchfunctionssoyoucanquicklyfindaparticularindividualorgroup.
EnablesyoutouseActiveDirectoryUsersandGroupstoconfigurerolebased
accesstothefeaturesofACEManagementServer.
Performing Capacity Planning
ACEManagementServerenablesyoutomanageACEinstancesandpoliciesinreal
time.ThenumberofclientsthatasingleACEManagementServercanservedepends
onseveralkeyfactors:
Databasethroughputandscalability
LDAPthroughput(ifyouareusingActiveDirectory)
Networkbandwidthavailableforincomingclientrequests
ACEpolicyconfiguration
Loadbalancersforverylargedeployments(morethan5,000clients)
Table 21listsrecommendationsforthenumberofclientssupportedbasedonthe
hardwareyouareusing.Thefiguresforrecommendedclientsreservesomeserver
processingpowersothatinteractiveclientsreceiveresponsesinatimelyfashionand
theserversatisfies
increasesindemand.
Table 2-1. Number of Clients Supported
Hardware Recommended Clients
2GHzAMD2wayserver(Opteron280,4GBRAM) 6,000
2GHzIntel2waydesktopmachine(4GBRAM) 4,000
ACE Management Server Administrator’s Manual
18 VMware, Inc.
Database Throughput and Scalability
Forproductiondeployments,VMwarerecommendsthatyouuseOracle,MSSQL,or
Postgresasyourdatabaseplatform.
Morethan95percentofthestoragespacethatanACEManagementServerrequiresis
usedtologeventinformation,whichisanaudittrailofalltransactionsperformed
throughACEManagementServer.Table 2
2listsrecommendeddatabasesizesbased
onthenumberofclientsbeingserved.
Thefiguresinthetablearebasedona90daydatabasearchivalperiod.Backupthe
databaserecordsevery90daysandkeepeventlogsfor90days.YoucanconfigureACE
ManagementServertopurgeevent
logsevery90days.
Theauthenticationeventgeneratesmostofthedatabecauseaneventisgenerated
everytimesomeoneattemptstoauthenticatetoACEManagementServer.Youcan
configureACEManagementServertologlesseventinformation.See“LoggingEvents”
onpage 49.
LDAP Throughput
ACEManagementServercancommunicatewithyourActiveDirectorydomain
controllertoauthenticateusercredentials.Yourdomaincontrollerinfrastructure
handlestheLDAPtrafficrequiredtosupportthenumberofclientsthatyouanticipate.
IntegratingwithActiveDirectorythroughLDAPisimplementeddifferentlyinthe
WindowsACEManagementServerthaninthe
LinuxbasedACEManagementServer.
TheWindowsACEManagementServerusestheWinLDAPlibrarybundledwithyour
Windowsoperatingsystem.TheLinuxACEManagementServerusesathirdparty
KerberosLibraryandOpenSSL.VMwareinternaltestingresultsindicatethatthe
WindowsimplementationprovidesbetterperformancethanLinux.
Table 2-2. Database Storage Recommendations
Number of Clients Recommended Database Size
100 50Mb
1,000 500Mb
10,000 5,000Mb
VMware, Inc. 19
Chapter 2 Planning an ACE Management Server Deployment
Network Bandwidth and Policy Update Frequency
TheamountofnetworkbandwidththatACEManagementServerandACEinstances
requiredependsonthefrequencyofpolicyupdatesthatyouconfigure.Table 23shows
theamountofbandwidthneededwhenyouuseapolicyupdatefrequencyvalueof
10 minutes.
VMwarerecommendsthatforlargedeployments(morethan5,000clients),
you
increasethetimebetweenpolicyupdatesbyclientsbecausethisreducestheamountof
requiredbandwidth.
Table 24showsthebandwidthneededwhenthepolicyupdatefrequencyvalueisset
to30minutes.
Theamountofnetworkbandwidthrequiredcanalsobehigherifyourpolicysetisvery
complex.
VMware
recommendsthatyouhaveaseparatenetworklinkbetweenACE
ManagementServerandyourdatabaseserver,sothattrafficcomingandgoingfrom
ACEManagementServertoitsclientsdoesnotinterferewiththetraffictoandfrom
yourdatabaseserver.
Table 2-3. Network Bandwidth Required with a Policy Update Frequency of 10 Minutes
Number of Clients Bandwidth Required
100 0.125Mb/sec.
1,000 1.25Mb/sec.
10,000 12.5Mb/sec.
Table 2-4. Network Bandwidth Required with a Policy Update Frequency of 30 Minutes
Number of Clients Bandwidth Required
100 0.04Mb/sec.
1,000 0.4Mb/sec.
10,000 4Mb/sec.
ACE Management Server Administrator’s Manual
20 VMware, Inc.
ACE Policy Configuration
TheconfigurationofACEpoliciescanaffectperformance.Youcanincreasetheamount
ofdatathatistransferredbetweenACEManagementServerandACEPlayerbyusing
oneofthefollowingmethods:
HostpoliciesEnablinghostpolicies(suchashostnetworkquarantine)requiresthat
ahostsidedaemonretrievesthehostpoliciesfromtheACEManagementServ er.
ComplexnetworkquarantinepoliciesIfthesetofrulesthatmakesupyour
networkquarantineisverylarge,thetransferoftheserulesfromtheACE
ManagementServertotheclientscanaffectthescalability.
ThenumbersshowninTable 23andTable 24areestimatesofrequired
bandwidthgiven
averagesizerulesetsfornetworkquarantine.Youcanviewthe
sizeofyourpolicysetbyexaminingtheACEfiledirectoryandcountingthesize
ofthe.vmplfile.Anaveragepolicysetis15KBorless.
Load Balancers
TheACEManagementServerclientserverprotocolisbuiltontopoftheHTTPS
protocol.YoucanuseHTTPloadbalancingsoftwareandhardwaresolutionstoscale
anACEManagementServerdeploymentbeyondthecapacityofasingleserver(orfor
highavailabilitydeployments).
ACEManagementServerscalesinalinear
fashionwhenanenterprisegradeHTTPS
loadbalancerisused.SeeChapter 5,“LoadBalancingMultipleACEManagement
ServerInstances,”onpage 51.
Security Features and Considerations
Bydefault,ACEManagementServerusestheSecureSocketsLayer(SSL)protocolto
provideencryptedandsecurecommunications.
Followingisanoverviewofsecurityfeaturesandrecommendationsonhowto
configuretheACEManagementServertoavoidsecurityproblems:
TraffictoandfromclientsisprotectedbyHTTPSBydefault,ACEManagement
ServercreatesaselfsignedcertificatewhenyouinstallittouseforHTTPStraffic.
Thesecertificatesaresecure,butyoucanalsoconfigureACEManagementServer
touseyourowncertificateandkeypairs.
TrafficfromACEManagementServertoActiveDirectoryisencryptedIfthe
serverisintegratedwithanActive Directoryservice,itcommunicateswiththeservice
throughanSSLprotectedlink.LDAPtraf ficisencryptedattheapplicationlayer.
CredentialsareprotectedbyusingtheKerberosprot ocoltoauthenticatecredentials.
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40
  • Page 41 41
  • Page 42 42
  • Page 43 43
  • Page 44 44
  • Page 45 45
  • Page 46 46
  • Page 47 47
  • Page 48 48
  • Page 49 49
  • Page 50 50
  • Page 51 51
  • Page 52 52
  • Page 53 53
  • Page 54 54
  • Page 55 55
  • Page 56 56
  • Page 57 57
  • Page 58 58
  • Page 59 59
  • Page 60 60
  • Page 61 61
  • Page 62 62
  • Page 63 63
  • Page 64 64
  • Page 65 65
  • Page 66 66
  • Page 67 67
  • Page 68 68
  • Page 69 69
  • Page 70 70
  • Page 71 71
  • Page 72 72
  • Page 73 73
  • Page 74 74
  • Page 75 75
  • Page 76 76
  • Page 77 77
  • Page 78 78
  • Page 79 79
  • Page 80 80
  • Page 81 81
  • Page 82 82
  • Page 83 83
  • Page 84 84
  • Page 85 85
  • Page 86 86
  • Page 87 87
  • Page 88 88
  • Page 89 89
  • Page 90 90

VMware ACE EN-000042-00 User manual

Category
Servers
Type
User manual
This manual is also suitable for

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI