- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Policy Preset limitation
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Policy Preset limitation
Our current setup includes four Multi-Domain Management servers, where Domain Management servers are spread across all of them in order to distribute the load. R80.20 Take 107
The issue/limitation we are facing is that in order for Policy Preset (scheduled or not) to work, we must have Global domain Active on the MDM that holds a DMS with policy targets, what breaks the idea of centralized management and makes policy installation automation far away from straightforward.
Also, for the ones who faced the following warning when creating a new Policy Preset - this is the same problem. make sure that Global Domain is active on the MDM that holds the DMS with policy targets.
Does someone know if there is a plan to improve this or we need to do a RFE?
Additional posts for the similar subjects:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you are right.
Was doing some tests regarding policy installation from MDM, and good news is that everything is not that bad as it sounds.
We don't need to set Global Domain Active on MDM where DMS is. In order to run policy installation (scheduled or not) it's enough to be logged into MDM where corresponding DMS is (regardless of it's being secondary or primary DMS)
But what needs to be taken to consideration:
1. Global domain must be active on primary MDS
2. Last run time is not synchronized across MDMs. If you run policy installation from one MDM, you will not see it on another ones.
It's still quite a limitation for centralized management. We can see all policy packages/target gateways on primary MDM, but not install policy on them.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Was doing some tests again, and turned out that it is actually that bad as I though at the beginning.
Basically scheduled policy installation is not working indeed until we set Global domain as Active on the MDM where we have DMS with policy targets. However if you just want to install bulk of policies, you just need to be logged into respectful MDM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would like to share our findings and discussion with R&D team on the issue with policy installation preset.
1. Regarding the need of switching the Global Domain to the MDS server, which holds the target CMA prior to scheduled policy installation.
This limitation is documented at R80.20 Administration guide - "Multi-Domain Security Management Administration Guide R80.20, Page 36"
Note - The policy preset is installed on the Multi-Domain Server with the active global Domain. If a domain has no domain server on the Multi-Domain Server with the active global Domain, then the policy preset is not installed on this Domain.
2. While connected to the Primary MDS, the policy installation to the gateways on the secondary, tertiary Multi-Domain Security Management servers is not possible.
This is also a current product limitation.
3. If the Global Domain will be changed to the secondary MDS server and the policy installation preset will be triggered, the status of the policy installation preset will not appear on the status task pane on Primary MDS.
This feature is in product road-map and expected to be resolved in the next releases.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
