Need recommendation on Log Server deployment for distributed network

rated by 0 users
Answered (Not Verified) This post has 0 verified answers | 9 Replies | 6 Followers

Not Ranked
1 Posts
Arnold1 posted on 5 Aug 2009 8:09 AM

I have a distributed network of subnets spread out geographically, all connected via point to points or internet T1s with firewalls.  I want one central repository for capturing log information.  How should I deploy WebSense Logging?  Should I install the database at the central point and install the Log Server on each WebSense server on each subnet, or does the Log Server need to be installed at the central point only?

One recommendation I would have, and I'm sorry if this isn't the right place to do this, is modify the installer to focus on the role of the WebSense server, such as the Policy Broker Main Hub, a central Log Report Server, or a satellite filtering server at a remote office, and then install the typical services required for that setup.  Not that what you have now doesn't work, but I've always found it easier to install things by roles, and less so than by features.

 

|

All Replies

Top 10 Contributor
1,532 Posts
Moderator
Suggested by Hacken Liu

According to your current network infrastructure, you can deploy multiple filtering services separately on each of your remote office, and all of these filtering services can point to one policy server in your central office. In this deployment, you can only have one log server installed in your central office, and all the log data will be logged into one log database instance.

Note: One policy server should have one log server. If you deployed multiple policy servers, multiple log servers are required.

Websense Forum Moderator

Web Security | Data Security | Email Security

|
Top 150 Contributor
23 Posts
BPC replied on 11 Aug 2010 12:15 PM

Hacken, sorry to comment on an old thread, but in this scenario, is it possible to have policy servers at each site, each with their own log server, but only have the policy broker at one site, and both the other remote sites to it?

|
Top 10 Contributor
446 Posts
Trusted Users (MVP)

Don't mean to hijack the thread, but I am pretty sure you can do this. This was why websense moved to a policy broker service.

I am not sure of the implications of having multiple Log servers though. Your reporting information would then be spread over multiple DB's. You would probably need a Websense manager at each site to allow for reporting on each database.

Susie, maybe you can comment on this?

|
Top 10 Contributor
1,744 Posts
Moderator

Hi,

Which Websense version are you using?

Log Server can log to only one Log Database at a time, and only one Log Server can be installed for each Policy Server. If your environment includes both multiple Policy Servers and multiple Log Servers, make sure you log on to each Policy Server separately, and verify that it is communicating with the correct Log Server. All Log Server instances should be configured to send data to the main Log Database at the main site. See more information on the Web Security Help for your version.

 

For v7.5

If you have multiple Log Server instances, there are special considerations for also deploying multiple TRITON - Web Security instances. In these distributed logging environments, it is important that only one TRITON - Web Security instance be used for reporting. Administrators connecting to the reporting instance of TRITON – Web Security will see all reporting features. Administrators connecting to other TRITON - Web Security instances will not see reporting features.

 

Best regards

|
Top 150 Contributor
23 Posts
BPC replied on 12 Aug 2010 11:30 AM

This would be in regards to v7.5. I think I understand what you are saying, I just want to verify that with multiple log servers and policy servers, can you still have just 1 policy broker service, so that you wouldn't have to manually update policies at all locations. I understand that you would have to log in to each location's websense manager in order to do reporting, since they each have their own log server. Is this correct?


Thanks for the feedback so far!

|
Top 10 Contributor
1,744 Posts
Moderator

1. With multiple log servers and policy servers, can you still have just 1 policy broker service?

Yes.

2. I understand that you would have to log in to each location's websense manager in order to do reporting, since they each have their own log server. Is this correct?

Yes. but all Log Server instances should be configured to send data to the main Log Database at the main site, and only  the main websense manager be used for reporting.

Best regards

|
Not Ranked
1 Posts

Hey Susie,

I understand from your above reply that ,even thought we have multiple log servers , we can still get centralized reporting with v7.5,,

Could you please help me finding as in what specific configuration would be required to achieve this.

I shall really be thankful.

Background -

We have 2 V10k appliance, now we want complete HA on both WSG+WWS... hence we have used the first appliace to serve as Centralized policy broker+Database for both V10ks

Therfor if 1st appliance goes down , 2nd works for 14 days with same policies......now the problem is reporting ...

as both appliances have their own policy servers , hence 2 diffrent log servers, which is not an ideal situation...coz for complete employee details, we have to login to 2 different WWS and generate..

 

|
Top 10 Contributor
1,744 Posts
Moderator

Hi,

As I am not very familiar with V10K issue, I would recommend that you raise a support case. I am sorry  I cann't help you.

Kind regards,

Best regards

|
Not Ranked
3 Posts

Yuting_W:

Hi,

Which Websense version are you using?

Log Server can log to only one Log Database at a time, and only one Log Server can be installed for each Policy Server. If your environment includes both multiple Policy Servers and multiple Log Servers, make sure you log on to each Policy Server separately, and verify that it is communicating with the correct Log Server. All Log Server instances should be configured to send data to the main Log Database at the main site. See more information on the Web Security Help for your version.

 

For v7.5

If you have multiple Log Server instances, there are special considerations for also deploying multiple TRITON - Web Security instances. In these distributed logging environments, it is important that only one TRITON - Web Security instance be used for reporting. Administrators connecting to the reporting instance of TRITON – Web Security will see all reporting features. Administrators connecting to other TRITON - Web Security instances will not see reporting features.

 

,

Hi,

about v.7.5: does websense have some solutions on version v7.6? I need to see all reports(logs) about all offices on Central office and each secondary office must see own reports (logs).

 

|
Page 1 of 1 (10 items)