Data Loss Prevention

 View Only
  • 1.  Symantec Data Loss Prevention high availability options

    Posted Apr 29, 2013 07:51 AM

    Dear colleagues,

    Does anyone knows what recommendations does Symantec give for building high available solution for Symantec Data Loss Prevention?

    Looking for different options to make the full DLP with all modules included to be available at any time. Solutions for different modules could be different (e.g. I can install the same Endpoint detection server on other [virtual] sefver, set up the same agent configuration and secure endpoint detection server).

    I'd apprectiate links to any official Symantec documentation that describes how to solve the problem.



  • 2.  RE: Symantec Data Loss Prevention high availability options

    Broadcom Employee
    Posted Apr 29, 2013 08:32 AM

    You can use Symantec's VCS product to make a cluster of your Oracle and DLP Services.

    You can refer to this thread:

    https://www-secure.symantec.com/connect/forums/load-balance-enforce-server

     



  • 3.  RE: Symantec Data Loss Prevention high availability options

    Posted Apr 30, 2013 08:51 AM

    Thank you!

    The link you provided contains information on Enforce + Oracle. What about other DLP components? Network Monitor? Data Insight? Other detection servers? Does Symantec has high availability recommendations for those?



  • 4.  RE: Symantec Data Loss Prevention high availability options

    Posted May 16, 2013 03:52 AM

    Guys, do you have suggestions for all DLP components?



  • 5.  RE: Symantec Data Loss Prevention high availability options

    Broadcom Employee
    Posted May 16, 2013 04:46 AM

    basically it is required to backup enforce and DB , as all the contents,incident, polcies are here. Hence detections servers are not that importanant, you just need to install and point to enforce server.



  • 6.  RE: Symantec Data Loss Prevention high availability options

    Posted May 16, 2013 04:06 PM

    Be careful!

    Unless DLP has gotten some serious upgrades/enhancements, all you can do is a cold standby.  Cutover would require manual intervention.

    The Enforce server and the detection servers don't have a concept of "mutliple" Enforce servers.  If you point two or more Enforce servers at a detection server, your system is likely to behave badly.

    Likewise, the Enforce server has no concept that another Enforce server could be using the database. If two Enforce servers access the same database, I shudder to think what would happen.

    JGT