McAfee Endpoint Encryption Hot Backup Implementation

Similar documents
Planning, Implementing and Managing SafeBoot Enterprise Systems

SYSPRO Point of Sale: Architecture

Kaseya 2. User Guide. Version 7.0. English

SQL Server Protection

Xopero Backup Build your private cloud backup environment. Getting started

IIS, FTP Server and Windows

Configuring the Active Directory Plug-in

NAS 259 Protecting Your Data with Remote Sync (Rsync)

SAM Backup and Restore Guide. SafeNet Integration Guide

Click Studios. Passwordstate. Installation Instructions

SQL Server Mirroring. Introduction. Setting up the databases for Mirroring

How To Create An Easybelle History Database On A Microsoft Powerbook (Windows)

Westek Technology Snapshot and HA iscsi Replication Suite

Configure SQL database mirroring

Configuring Failover

- 1 - SmartStor Cloud Web Admin Manual

Name Services (DNS): This is Quick rule will enable the Domain Name Services on the firewall.

ShadowControl ShadowStream

Setting up High Availability

Configuring a Windows 2003 Server for IAS

AUTOMATED DISASTER RECOVERY SOLUTION USING AZURE SITE RECOVERY FOR FILE SHARES HOSTED ON STORSIMPLE

Deploy App Orchestration 2.6 for High Availability and Disaster Recovery

OneDrive for Business from Desktop or Laptop Windows devices

Hyperoo 2.0 A (Very) Quick Start

1 of 10 1/31/2014 4:08 PM

SAM 8.0 Backup and Restore Guide. SafeNet Integration Guide

DocAve 4.1 SharePoint Disaster Recovery High Availability (SPDR HA) User Guide

Changing Your Cameleon Server IP

Active Directory Infrastructure Design Document

ScoMIS Encryption Service

Hosting Users Guide 2011

G-Lock EasyMail7. Admin Guide. Client-Server Marketing Solution for Windows. Copyright G-Lock Software. All Rights Reserved.

High Availability for VMware GSX Server

All rights reserved. Trademarks

TSM for Windows Installation Instructions: Download the latest TSM Client Using the following link:

istorage Server: High-Availability iscsi SAN for Windows Server 2008 & Hyper-V Clustering

User Guide. Version R91. English

TIGERPAW EXCHANGE INTEGRATOR SETUP GUIDE V3.6.0 August 26, 2015

Setting up Sharp MX-Color Imagers for Inbound Fax Routing to or Network Folder

Acronis Backup & Recovery 11

Searching for accepting?

SQL Server Protection Whitepaper

SETTING UP ACTIVE DIRECTORY (AD) ON WINDOWS 2008 FOR EROOM

MN-700 Base Station Configuration Guide

Pocket ESA Network Server Installation

Implementing Microsoft SQL Server 2008 Exercise Guide. Database by Design

Best Practices for Disaster Recovery with Symantec Endpoint Protection

Deploying Remote Desktop Connection Broker with High Availability Step-by-Step Guide

Networking Best Practices Guide. Version 6.5

Information Systems Services. SafeGuard Enterprise. enc. Device Encryption (DE) Installation V /11/2010

Core Protection Suite

Backup Exec Private Cloud Services. Planning and Deployment Guide

Setting Up a Backup Domain Controller

High-Availability User s Guide v2.00

XenClient Enterprise Synchronizer Migration

Pro Surveillance System 4.0. Quick Start Reference Guide

Use QNAP NAS for Backup

Daylite Server Admin Guide (Dec 09, 2011)

Kerio VPN Client. User Guide. Kerio Technologies

FaxCore Ev5 Database Migration Guide :: Microsoft SQL 2008 Edition

Keep SQL Service Running On Replica Member While Replicating Data In Realtime

Cisco SSL Encryption Utility

Introduction. Before you begin. Installing efax from our CD-ROM. Installing efax after downloading from the internet

Using Mac OS X 10.7 Filevault with Centrify DirectControl

Configuring Network Load Balancing with Cerberus FTP Server

Configuring Keystroke with KeyPay

Password Reset Server Installation Guide Windows 8 / 8.1 Windows Server 2012 / R2

FileCruiser Backup & Restoring Guide

Training Events Database (TED) Setup Guide

Working with your NTU off campus

Moving/Restoring the StarShip SQL database

POC Installation Guide for McAfee EEFF v4.1.x using McAfee epo 4.6. New Deployments Only Windows Deployment

If you have used Outlook Web Access then you will find Zarafa Webaccess very familiar.

Installation of MicroSoft Active Directory

Configure AlwaysOn Failover Cluster Instances (SQL Server) using InfoSphere Data Replication Change Data Capture (CDC) on Windows Server 2012

DigiVault Online Backup Manager. Microsoft SQL Server Backup/Restore Guide

Configuration Guide for Active Directory Integration

Load-Balanced Merak Mail Server

Full disk encryption with Sophos Safeguard Enterprise With Two-Factor authentication of Users Using SecurAccess by SecurEnvoy

SafeGuard Enterprise upgrade guide. Product version: 7

Sentral servers provide a wide range of services to school networks.

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

MCSA Objectives. Exam : TS:Exchange Server 2007, Configuring

1Y0-250 Implementing Citrix NetScaler 10 for App and Desktop Solutions Practice Exam

Comparison of the High Availability and Grid Options

Setting up your new Live Server Account

Insight Video Net. LLC. CMS 2.0. Quick Installation Guide

Integration Set Up Guide

Privileged Access Management Upgrade Guide

Configure ActiveSync with a single Exchange server (Exchange sync for an iphone)

Creating a User Profile for Outlook 2013

MS SQL Server Backup - User Guide

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

High Availability and Disaster Recovery Solutions for Perforce

Transcription:

McAfee Endpoint Encryption Hot Backup Implementation 1

Endpoint Encryption Hot Backup Implementation Planning, Implementing and Managing SafeBoot Enterprise Systems SafeBoot Hot Backup Implementation Having a single physical server for your SafeBoot enterprise is obviously risky, and even if regular backups are taken delays can occur in user recovery or updates during a server failure. Therefore we would advise in all cases that steps be taken to expedite recovery from a failed or dead server. The following is an example how this could be achieved. This backup method uses a Main server hosting the SafeBoot Object Directory (ODB) and a second server which can take over in the case of failure of the Main server. Hot Backup Databases By replicating the SafeBoot Object Directory to a 2nd physical server you can alleviate down time in the event of a server failure to a minimum. McAfee offers an optional tool to efficiently replicate the directory. This tool SFDBBack (SafeBoot DataBase Backup Tool) can be obtained from your McAfee representative. SFDBBack is optimized to follow the change log of a SafeBoot 4 Object Directory. SFDBBack can used to make regular backups of the ODB, giving further recovery options in the event of a disaster. By following the change log Backups can be made over very short intervals keeping the spare directory synchronised with its master. SFDBBack allows you to create a very resilient system using two physical computers both hosting SafeBoot Servers, one hosting the master ODB and the 2nd having a Hot Backup which is kept offline until needed. In the event of the master server failing, the SafeBoot Server service on the 2nd backup box can be started to serve clients. You can then rebuild or replace the problem machine and create a new master. To keep integrity of the SafeBoot Enterprise, only ONE database can be in use at any one time. If two directories become live at once you run the risk of losing data when the failover process begins. The following procedure documents how to set up a reliable failover process. 2

Creating a Master / Hot Backup system Create a SafeBoot Directory, with 2 SafeBoot servers to service client requests. In this example only one server service is running at any one time (normally Server A). On Server A (the master), install the main SafeBoot Directory. Install SafeBoot Administration software on machine A Create and configure your Master Directory. Create 2 SafeBoot Servers, one for this machine s IP or DNS name and one for the 2nd backup server (using that machine s different IP or DNS name). Logout On Server B (the backup), create a directory (to be used as the Hot Backup). On machine B also install the SafeBoot Administration software choosing the same options Create an object directory (this is temporary) Logout and browse inside the SBAdmin directory within the installation directory with explorer. Remove the SBDATA directory from B, and all its contents, and replace with a copy of SBDATA folder from Server A. On Server A (the master), setup the SFDBBack tool Setup SFDBBack; add a new event to sync/copy all changed files from Server A to the Server B SBDATA directory. Now you can start the SafeBoot Server service on Server A as normal. Make an install Set and choose Servers A and B as the servers for your clients talk to. Install on a test machine. On Server B (the backup) create the server entry for Hot Backup server mode Go to Start Menu, SafeBoot Administration, SafeBoot Server, the SafeBoot Logon box appears. Go to Advanced, and highlight the entry that has the sbfiledb.dll address. Click Properties, change the description to HOT BACKUP Server or similar. You will only start this SafeBoot Server service if the main server A is down. Your system is now ready to use. 3

Normal operation (Figure 1) During normal operation the SafeBoot Server service on A (the master) will authenticate incoming client connections before sending them to the database also on Server A. Figure 1 Normal Operation Hot-Backup Operation (Figure 2) Transferring control to the backup server involves ensuring the master server is offline, and then starting the backup server to take over communications. If Server A fails: ensure that Server A service will not start itself (by disconnecting the server from the network, or powering it off) on machine B (the backup) start the SafeBoot Server Choose Hot Backup and log in. Your clients will try to authenticate with Server A as normal and fail to connect of course, next they try Server B and will sync as normal from their point of view. However they will be syncing with the Hot Backup copy of the database. 4

Figure 2 "Hot Backup" Operation Transferring back to Normal Operation To transfer back to normal mode operation, you need to stop ALL servers, copy the Object Directory from the Backup server to the Master, and then restart the Master server. To do this: log off any admin first from B stop all SafeBoot Server services copy the SBDATA folder and contents from Server B back to A, replacing any SBDATA folder there. You could set up an event in SFDBBack to be run manually which copies data from B to A to do this. bring up the SafeBoot Server service on A Clients who find B is no longer available will now authenticate with A again when they synchronize. 5