Support

multiple sites, 1 broker with many policy servers

rated by 0 users
Answered (Not Verified) This post has 0 verified answers | 12 Replies | 5 Followers

Top 500 Contributor
8 Posts
PatrickA posted on 19 Oct 2010 6:42

so we are trying to install a websense 7.5 with a broker and 5 remote locations with the filtering and the policy server.

the broker install (first install) went all well on a windows 2003 server in US has been running for 2 months no issues. now we're trying to install a policy server and filtering service in France and for some reason the install is always crashing no matter what we try.

now if we install a test broker in france and then the filtering and policy server on another server in france it will work...

is there a latency thing with this?

I also tried installing a test policy server in US and it worked just fine. I was able to attach it to the broker in US.

this only happens when my broker is in US and I'm trying to install a policy server/filtering services in France or UK or china....

any thoughts?

so far I've got no answers from websense support.

thanks.

|

All Replies

Top 500 Contributor
8 Posts

I get this during the install, it crashes saying,

websense web security was installed on your system. however, there were several issues with the installation. see the details below for your own records of if you wish to contact technical support.

choose next/done to exit the installer.

the following components have failed to install correctly;

policy server: package deployment failed; wbsn.policyserver

1:com.websense.conf.exception.ConfigurationRuntimeException:

com.websense.config.exception.ConfigException:

com.websense.config.exception.WebsenseinstallerException;

package deployment failed; wbsn.policyserver

 

 

|
Top 10 Contributor
386 Posts
Trusted Users (MVP)

I have just gone through the same situation although with only 2 remote sites. I eventually installed the policy server first and then added the other components one at a time to narrow down what was the problem.

I think the issue is latency because I got different results all the time, however after installing just the policy server on a remote site and getting the same error as you, the installation is still working fine. So I would ignore that error and see how it works. I am also using centralised logging and that is working fine.

|
Top 500 Contributor
8 Posts

so for us even installing just the policy server doesn't work.

what we've noticed is that when the latency or ping time from policy server to broker is more than 30ms it crashes... when it's smaller than 30ms the installation will work.

ex: I install a test broker in boston and a test policy server in NY and it works. now if my policy server is in France it will fail, if it's in china it will fail if it's in Canada it will work because ping time from policy server to broker is 16ms...

so we've never even been able to install the policy server alone.

to me this is just insane... I see no reason why there should be a very good latency between the policy server and broker there is no need even on a slow circuit the broker can still transfer information to the policy servers... but I may be wrong and this may have nothing to do with latency.......

I have a websense engineer that's going to call me today and try to install the policy server for me in France... hopefully he can figure this out otherwise we'll have to do all our remote installs without policy servers, just have the policy server/broker on the same machine and all remote have just filtering which wasn't my plan. I wanted all remotes to also have a policy server.

|
Top 10 Contributor
386 Posts
Trusted Users (MVP)

I also got that error message after I installed just the policy server. However when i looked at the services the policy server service was there and running. Despite the error all was/is working fine.

Anyway I would be very interested on the outcome of your session with the Websense Engineer, please post the outcome.

|
Not Ranked
2 Posts

Hi PatrickA , I have the same problem. I have tried to install a Policy Server in Brazil and bind them with a Policy Broker in Austria --> same errors!!

Have you heard anything from support?

Thanks
Tyr-Roger

|
Top 500 Contributor
8 Posts
Suggested by PatrickA

here is how we fixed this and I've been installing my websenses this way and it works.

 

it took a lot of time but this usually happens when the latency time is larger than 30 ms it's what we noticed anyway… it’s not a lot but if you ping the remote site and the ping time is 30ms> there is a good chance you'll get this error. everywhere we had 30ms>  we got this error.

 The fix which isn’t really a fix is,

Install only the policy server, even when it fails it gets installed, so go look under services to see if you have policy server.

 If you don’t have it under services then go in the programfiles/websense/bin you should have a policyserver.exe or something like that now if you do policyserver.exe -i (install) this should install policy server as a service.

so if you go back into services you should see the policy server installed. if not then I can't help it has worked for me so far with many installs.

Once you have policy server installed you can install all the other components.

|
Not Ranked
2 Posts

Even am also facing same issues, while installing Policy server+Filtering server in remote locations.

As per the above conversations i understand that if we install policy server alone and later install filtering service. hope it will work.... Pls confirm,

or did anybody has support feedback on this...??

 

|
Not Ranked
2 Posts

Hi Patrick,

Even i have the similer problem.

Have you got any update on this from websense engineer.,,?

Pls help.

 

Thanks,

Sajith

 

|
Not Ranked
2 Posts

Hi all,

I have an answer from the support - see below. They told me, that if you have a RTT mor than 60ms from your Policy-Server to your Policy Broker it is not supported and in most cases also not working. I am a little confused, because there is no hint in any documentation about this issue!

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Hi Roger,

I can see what the problem is here now. This amount of latency is far too much for the Policy Server to Policy Broker communications.

We do not recommend the Policy Server --> Broker be anything more than 60 m/s! So your ping times are nearly 10 times this number. This is not going to work.

I think the only solution for you is going to be installing the Policy Broker and Policy Database on this same server, and have all the components running on the same box. Or at least install the Broker and Database on a server which is local to the Policy Server machine.

Either way, it is not possible for our components to work together with 400-500 m/s latency between them.

Please let me know if I can assist you any further with the deployment of these components.


Thanks,
Mike
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

 

|
Not Ranked
1 Posts
Suggested by Yuting_W

I had a similar problem where latency between Policy Broker and Police Server is 350ms.

After working with Websense Tech Support they installed a full Websense 7.5 version on the remote site and then removed Policy Broker and Policy DB. After that they modified config.xml file (“BrokerService”) to point to a primary Websense server with Policy Broker.

Everything is working fine.

|
Top 10 Contributor
386 Posts
Trusted Users (MVP)

I have installed the policy servers after hours when WAN activity was low. All the above posts seem to explain my problems. Sometimes the Policy Server would install and other times not. I never checked the RRT as I did not expect it to be a problem, but I suspect my WAN latency must have been borderline. My installation is working fine now.

|
Top 500 Contributor
12 Posts

Where are Websense Support/Development folks? Do they read this thread at all? If there is indeed a requirement to have RTT <= 60ms between Policy Broker and any Policy Server in my deployment, then this needs to be documented somewhere. In fact this requirement makes entire Web Security 7.6 useless for our enterprise. Does Websense want me to start looking elsewhere?

 

|
Page 1 of 1 (13 items)