Multi-ESM Behavior or Load Balancer

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Multi-ESM Behavior or Load Balancer

 

Multi-ESM behavior and the use of load balancer are mutually exclusive. If you choose to use a load balancer, be sure to set all ESM Servers to "Disabled" in ESM Console's Settings > ESM > Multi-ESM tab. This setting does not disable the ESM Servers as whole; ESM Servers set to "Disabled" on this screen continue to operate as normal except that they do not participate in the Multi-ESM algorithm.

 

If you fail to set the ESM Servers to "Disabled" in a load-balancer configuration, the consequece will be that endpoints learn about the serves as part of their regular heartbeat cycle and then might (depending on network topology) try to connect directly to an ESM Server instead of through your load balancer.

 

The Multi-ESM Algorithm

 

On each heartbeat, each endpoint:

  • Retrieves the list of ESM Servers;
  • Sorts the list of known ESM Servers configured "internal" IP addresses by hop count;
  • Tries to connect to the lowest; if no connection, the next lowest....; if all attempts fail:
  • Sorts the list of known ESM Servers configured "external" IP address by hop count;
  • Tries to connect to the lowest; if no connection, the next lowest....; if all attempts fail:
  • Tries to connect to the ESM Server to which it was configured at install time.

 

Traps Multi-ESM Algorithm.png

Deployment without Load Balancer

  • All ESM Servers take traffic;
  • Endpoints lear the list of ESM Servers in server heartbeart;
  • Endoints connect to the ESM Server that is both topologically closest and "Enabled" in the ESM console;
  • More than one ESM Server direct its endpoints to the same forensic folder.

 

Deployment with Load Balancer

  • All ESM Servers take traffic;
  • Endpoints are configured to point to the load balancer VIP on port TCP 2125, and not to individual ESM Servers;
  • Endpoints connect through load balancer to an ESM server based on Load Balancer algorithm configuration such as Round robin, least connections, and so on;
  • All ESM Server should be set to "Disabled" in the ESM Console's Multi-ESM screen.

Screen Shot 2017-04-27 at 8.21.39 PM.png

 

 Willian

 

 

 

 

0 REPLIES 0
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!