12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4Using <strong>McAfee</strong> DLP DiscoverManaging scan loadTask1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Classify | Discover Scan Operations | ScanOperations.• On your <strong>McAfee</strong> DLP appliance, select Classify | Discover Scan Operations | Scan Operations.2 Select a scan and click the Advanced Options tab.3 Pull down the throttling menu and choose one of the following.• No Throttling (default)• Kbps (kilobits per second)• Mbps (megabits per second)4 Click Save.On a 100‐Mbps LAN, limit bandwidth to 50 Mbps to limit the crawler to half of the bandwidthavailable. If bandwidth is throttled correctly and there is L3 connectivity between networks,<strong>McAfee</strong> DLP Discover can be deployed across a WAN, though object viewing might be slowerdue to WAN latency. For example, if a 1 Gbps link between Tokyo and London is used, only~10 Kbps throughput might be available for a CIFS scan.Bandwidth throttling is applied as an average across the entire scan rather than as eachindividual file is being fetched. A Discover scan might burst above or below the configuredthrottle limit, but the average throughput measured across the entire scan will remain veryclose to the configured limit.Scanning in full duplex mode<strong>McAfee</strong> DLP Discover must be deployed in full‐duplex mode.Every interface between the Discover appliance and target nodes (intermediary switch, router, firewall,etc.) cannot be set to half‐duplex mode.<strong>Guide</strong>lines for Fast Ethernet networks• Hard‐code the speed and duplex of the Discover appliance to 100 Mbps and full duplex.• Ensure that all intermediary devices are either hard‐coded to 100 Mbps and full duplex, or validatethat all intermediary devices have negotiated to full duplex if configured for automatic negotiation.<strong>Guide</strong>lines for Gigabit Ethernet networks• Set the speed and duplex of the Discover appliance to 1000 Mbps and full duplex or to auto‐detect.• Ensure that all intermediary devices are either hard‐coded to 1000 Mbps and full duplex, or validatethat all intermediary devices have negotiated to full duplex if configured for automatic negotiationManaging scan loadScan load might have an impact on performance of <strong>McAfee</strong> DLP systems. If too many operations arerunning concurrently, a scan might appear to be stalled.Operations that add load to the system include:• Deleting or creating scans in the same time frame• Crawlers running and processing files from an extended scan106 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!