The Endpoint Server keeps a persistent connection to the Endpoint Agent. When there is too much traffic between the Endpoint Agents and the Endpoint Server, the Aggregator process on the Endpoint Server gets overwhelmed and communication failures can occur. The more traffic between the Endpoint Agent and Endpoint Server, the fewer Endpoint Agents the Endpoint Server can handle.
The traffic is created by many different types of messages. Some of these include:
Pushing policies to the agents. When policies are pushed out, they are pushed to all the agents at the same time. This is for a short time, but if the Aggregator is near saturation, this can be an issue.
When Policies are Pushed out to the Endpoint Agent
Large numbers of incidents. If policies are too vague and create large numbers of incidents, this will cause a large number of messages to be created. Too many incidents are hard to remediate, so best to tune policies for fewer incidents.
Retaining Original Message. All incidents will send the original message, this will increase the message size being sent to the Endpoint Server. Retaining Original Message on Endpoint Incident
IDM/EDM Policies - Indexed documents are evaluated on the Server, therefore all messages being evaluated will be sent to the server. Recommend to create a short circuit for any IDM/EDM policy using a Data Identifier or keyword.
Issues with running Endpoint that includes EDM/IDM policies
eDAR - Discover scan requests on the Endpoint are sent to every Endpoint Agent, even if filters are in place to limit the number of agents. In that case, the request for the scan comes, the Endpoint Agent evaluates the request, sees that it is not included, and sends a completed message back to the server.
Also, Discover scans scan a large number of files, so the number of incidents may be greater than with Endpoint Prevent.
eDAR with IDM/EDM. For the reasons listed above, eDAR with Indexed Documents will cause all scanned files to be sent to the server. A short circuit is required for this case.
Endpoint Server on VMWare - VMWare ESX 4.0 is supported on DLP 11.0 and above. However, the Endpoint Server can handle half as many Endpoint Agents on VMWare as on Hardware. See system requirements guide for more information.
|