cancel
Showing results for 
Search instead for 
Did you mean: 

McAfee MOVE MP - Client Assignment Based on Tags

Jump to solution

Greetings,

I'm in the process of setting up McAfee MOVE MP 3.6.1 and I'm at the point where I'm creating Client OSS Assignment Policies. Let me break down what I'm trying to do...

We have two Datacenters... DC1 and DC2.

EPO is in DC1.

We have an SVA in DC1 and 2 OSS's in DC1.

We've installed the DataCenter Connector, which automatically tags our VMs with two tags "VM" and "dc_vm_auto".

I've also created a tag called DC1 which is by subnet.

My original thinking was that, since I want to assign all the VMs in DC1 to one of the two OSS's, I could just add the tags "VM" and "DC1" into the Client Tag section of the policy, and that would work. But more and more, I'm thinking this is an OR thing, and not an AND thing. Meaning, it would send clients who have EITHER of those tags to the OSS's, which would send all the VM's (including ones from DC2, which is undesirable) and all the ones with the DC1 tag, which is all the VMs and Physicals in DC1, which is also undesirable.

How would I accomplish this for both DC1 and DC2 to ensure only VMs in those DCs are going to OSS's in those DCs?

Thanks,

Mark

1 Solution

Accepted Solutions
Troja
Level 14
Report Inappropriate Content
Message 4 of 4

Re: McAfee MOVE MP - Client Assignment Based on Tags

Jump to solution

Hi ,

we did this at a customer. You have to configure a query where you query the Systems which are located on specific VMWare hosts. Based on this query you can add a Server Task to TAG the endpoints e.g. with DC1 or DC2.

Now you have all you Need.

Hope this helps,

Cheers

3 Replies
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: McAfee MOVE MP - Client Assignment Based on Tags

Jump to solution

I could not understand your scenario but what i could understand is something like this -

- You have some Client and OSS system in DC1.

- You have some client and OSS systems in DC2.

and You want to assign tags which tells that DC1 Clients talk to DC1 OSS and DC2 clients talk to DC2 OSS. Is this correct ?

Re: McAfee MOVE MP - Client Assignment Based on Tags

Jump to solution

Basically yes... We want all the VM clients in one datacenter to only to talk to the OSS's in the SAME DC.

-Mark

Troja
Level 14
Report Inappropriate Content
Message 4 of 4

Re: McAfee MOVE MP - Client Assignment Based on Tags

Jump to solution

Hi ,

we did this at a customer. You have to configure a query where you query the Systems which are located on specific VMWare hosts. Based on this query you can add a Server Task to TAG the endpoints e.g. with DC1 or DC2.

Now you have all you Need.

Hope this helps,

Cheers