7 Replies Latest reply on Nov 13, 2009 10:45 AM by JoeBidgood

    One Agent talking to two servers

    mwilke

      Is there a way, in ePO 4.5, for an agent to talk to two different ePO servers?  Here is my situation.

       

      We have a lot of "little companies" inside our big company.  About half of those companies have their very own ePO environment running virus scan, HIPS, DLP, etc

       

      We also have a centrally managed MEE environment that houses all the little companies instead of letting them manage it on their own.

       

      So when the new MEE v6.x comes out, we are seeing some road blocks in keeping this centrally managed.

       

      If Company1 has ePO environment they want to keep it that way, they already run all their own softwares and policies through there.  Now we the parent company want to roll our existing MEE environment into our own ePO environment and still have Company1 agents get updates from us and their own ePO environment at the same time.

       

      I can register their servers repository and have their agent sync to either of the two ePO environments but we really need it to be able to sync to BOTH servers every time or at least every other time.

       

      This may not be possible and if not.... we are hozed.

        • 1. Re: One Agent talking to two servers
          GWIRT

          with ePO 4.5 you an "move" machines from one server to another, but this must be done at the ePO console. Utilmately, only one ePO server can manage a client at a time.

          • 2. Re: One Agent talking to two servers
            mwilke

            I know you can configure an Agent to talk to multiple servers by ping time, hops, etc....

             

            Is there a way to configure an Agent to talk to multiple servers maybe in alternate fashion?  Like talk to server1 this sync, then talk to server 2 the next sync?  Or a way to take two servers and randomize which one it talks too?

             

            I know, i am grasping at straws here.  We have a serious issue if we cant make an agent play nicely with two servers.  =)

            • 3. Re: One Agent talking to two servers
              GWIRT

              I may have misunderstood. Are you talking about just having agents update from repositories managed by other ePO servers? I think this can be done. You essentially have to share the repository keys between all the servers and have them all use the same servers. You will also have to be careful with the replication to make sure that they don't happen at the same time and both servers replicate the same things.

               

              I have heard of people doing this but I haven't tried it myself.

              • 4. Re: One Agent talking to two servers

                How would you setup the key sharing between servers? I assume that you would export and import the Agent-Server keys between ePO servers under Server Settings>Security Keys, correct? I notice that there can be only one Master Repository key per server and this is probably due to the architecture.

                 

                I see that only one Agent-Server key is assigned to multiple agents (systems). When I import a key from another server I cannot assign it to those systems. I can make the key master though which still does not change the assignment. Does this have to be done manually on the client agent via the sitelist.xml?

                • 5. Re: One Agent talking to two servers
                  GWIRT

                  You would make it so that all the ePO servers use the same master repository key, then they could all manage the same repositories. As for communication with the ePO server (policies and tasks) you can only have an agent talk to one server at a time. You can move an agent from one server to another, but that's not a dynamic process.

                   

                  When you make an agent-to-server key master, you have to wait for the agent to update (same process as a DAT update) for it to use the new master key.

                   

                  Hope that helps.

                  • 6. Re: One Agent talking to two servers

                    That helps, thanks.

                     

                    Back to mwilke's question about two agents contacting two repositories. So in the Repository list, under the McAfee Agent policy, is there a way to have the agent contact one repository and right after that contact the other repository? I have it set already to contact the repository list by order. I have a master repository and a distributed repository in the Repository list and I want the agent to contact both in the same wakeup call. This is strictly for testing purposes only.

                    • 7. Re: One Agent talking to two servers
                      JoeBidgood

                      Assuming I'm understanding everything correctly - always a dangerous assumption - then no, this isn't possible. The agent will only move on to the next repo in the list if the previous repo fails - so, for example, if it logs in to the first repo successfully and finds that it's up to date, then it won't try the next one.

                       

                      Regards -

                       

                      Joe