McAfee EPOCDE-AA-BA Product Guide - Page 150

Agent-server communication interval, General

Page 150 highlights

13 Working with the agent from the McAfee ePO server Agent-server communication Agent-server communication interval The agent-server communication interval determines how often the agent calls in to the server. The agent-server communication interval (ASCI) is set on the General tab of the McAfee Agent policy page. The default setting of 60 minutes means that the agent contacts the server once every hour. When deciding whether to modify the interval, consider what the agent does at each ASCI: • The agent collects and sends its properties to the server or Agent Handler. • The agent sends the events that have occurred since the last agent-server communication. • The server or Agent Handler sends new policies and tasks to the client. This action might dictate other resource-consuming actions, such as an immediate DAT download. • The agent enforces policies. Although these activities do not burden any one computer, a number of factors can cause the cumulative demand on the network, McAfee ePO servers, or on Agent Handlers to be significant. • A large number of systems being managed by ePolicy Orchestrator. • Your organization has stringent threat response requirements. • The network or physical location of clients in relation to servers or Agent Handlers is highly distributed. • Inadequate available bandwidth. In general, if your environment includes these variables, you want to perform an agent-server communication less frequently. For clients with critical functions, you might want to set a more frequent interval. Agent-server communication interruption handling Agent-server communication follows a specific algorithm designed to work around issues that might cause a problem connecting with an ePolicy Orchestrator server. Communication interruptions can happen for many of reasons, and the agent-server connection algorithm is designed to re-attempt communication if its first attempt fails. The agent cycles through the following connection methods up to 6 times or until one of a set of responses is returned. 1 IP Address 2 Fully qualified domain name 3 NetBIOS The agent iterates through those three connection methods in that order up to six times for a total of 18 connection attempts. There is no delay between connection attempts. The agent stops this cycle if a connection attempt results in any of the following: • No error • Download failed • Upload failed • Agent is shutting down • Transfer aborted • Server busy (status code from McAfee ePO) 150 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Agent-server communication interval
The agent-server communication interval determines how often the agent calls in to the server.
The agent-server communication interval (ASCI) is set on the
General
tab of the McAfee Agent policy
page. The default setting of 60 minutes means that the agent contacts the server once every hour.
When deciding whether to modify the interval, consider what the agent does at each ASCI:
The agent collects and sends its properties to the server or Agent Handler.
The agent sends the events that have occurred since the last agent-server communication.
The server or Agent Handler sends new policies and tasks to the client. This action might dictate
other resource-consuming actions, such as an immediate DAT download.
The agent enforces policies.
Although these activities do not burden any one computer, a number of factors can cause the
cumulative demand on the network, McAfee ePO servers, or on Agent Handlers to be significant.
A large number of systems being managed by ePolicy Orchestrator.
Your organization has stringent threat response requirements.
The network or physical location of clients in relation to servers or Agent Handlers is highly
distributed.
Inadequate available bandwidth.
In general, if your environment includes these variables, you want to perform an agent-server
communication less frequently. For clients with critical functions, you might want to set a more
frequent interval.
Agent-server communication interruption handling
Agent-server communication follows a specific algorithm designed to work around issues that might
cause a problem connecting with an ePolicy Orchestrator server.
Communication interruptions can happen for many of reasons, and the agent-server connection
algorithm is designed to re-attempt communication if its first attempt fails.
The agent cycles through the following connection methods up to 6 times or until one of a set of
responses is returned.
1
IP Address
2
Fully qualified domain name
3
NetBIOS
The agent iterates through those three connection methods in that order up to six times for a total of
18 connection attempts. There is no delay between connection attempts. The agent stops this cycle if
a connection attempt results in any of the following:
No error
Download failed
Upload failed
Agent is shutting down
Transfer aborted
Server busy (status code from McAfee ePO)
13
Working with the agent from the McAfee ePO server
Agent-server communication
150
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide