Showing results for 
Show  only  | Search instead for 
Did you mean: 

MOVE Policy considerations

If we have multiple clusters in ESX, will we need to create a policy for each one of the Offload Scan servers that point the clients to the right server?

I have read through the deployment guide, but it seems to be very vague on how to actually "deploy" MOVE within a virtual environment.

Any help you can provide would be great.

4 Replies
Level 13
Report Inappropriate Content
Message 2 of 5

Re: MOVE Policy considerations

Yes, the product guide doesn`t provide best practices, but you`ll want to keep the av scanning on the hypervisor. You can create groups in EPO and sort the machines based on the hypervisor they`re hosted on and assign them throgh different policies.

Re: MOVE Policy considerations

Typically you will stand up the Offload servers in pairs. A pair can probably service a lot of hypervisors. The fact that it is on/off hypervisor isn't as relevant as the switches between the hypervisors themselves.

You know you need more when the queue length increases or the average delay timer starts to be non-zero for any length of time.

I do agree that the guide is good at the mechanics of it but is sparse on what our customers SHOULD be doing.

Level 7
Report Inappropriate Content
Message 4 of 5

Re: MOVE Policy considerations

From my experience I can tell you, that you can manage quite a lot of numbers with one offload server. But what I really recommend is a load-balancer in front of two offload servers. This is the most basic setup I recommend for a production environment, especially if you have servers running with MOVE-AV.

Just to give you some more insight, here are some real life numbers:

300 VDIs

Hardware Loadbalancer with GBit-connection between MOVE client and offload server

2 offload servers with quad core cpu and 4 GB RAM

the virtual desktops and the server are in seperate networks, but the switch-backbone is GBit and the link is not even saturated to around 10%-30% (depending on the time of the day)

If the networkconnection is not the bottleneck in this configuration, you can easily add more offload servers if needed, until gbit network is completely full.

Hope this helps you

Kind regards


Re: MOVE Policy considerations

This is some great info, so thank you for the replies.

I think my next question to you CPT would be:

     What, if any, disk latency are you seeing on the VM's themselves during the scans?  If the majority of the work is done over the network, then we should be good to go.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community