
13
McAfee
®
IntruShield
®
IPS System IntruShield Best Practices
Special Topics: Best Practices Maintenance, backup, and database tuning
1
Maintenance, backup, and database tuning
Perform regular manual backups of your database using the Backup feature in the
Manager software. Your configuration tables are saved by default once a week on
Saturday. See Backup on page 15, for more information on backup best practices.
Database backups are cumulative and the size of a backup file can become quite
large. Perform regular file maintenance to prevent disk space issues.
Archive your alerts and packet logs regularly, using the Alert and Packet Log Archival
feature. McAfee recommends that you archive your alert data monthly, and that you
discard alert and packet log information from your database every 90 days to
manage your database size. Note that there is currently a 4GB size limitation for a
single archive file.
F
Online database tuning operation causes the creation of temporary alert and packet
log tables; if you are using an agent that queries the database, your agent may
attempt to interact with these tables during tuning. There is a remote chance that
during the transition to the temporary tables, the SQL query will result in an error. If
a SQL query error occurs, simply retry the query. Further information on the impact
of online database tuning of the ISM database will be sent to the third-party vendors
that are directly accessing this database. If you have any specific questions, contact
Technical Support. Also note that there is no change in database SQL query behavior
if online database tuning is disabled.
McAfee recommends that you make a regular practice of defragmenting the disk of
the Manager server, as disk fragmentation can lead to database inefficiency.
When scheduling certain Manager actions (backups, file maintenance, archivals,
database tuning), set a time for each that is unique and is a minimum of an hour
after/before other scheduled actions. Do not run scheduled actions concurrently.
McAfee recommends that you tune your database at regular intervals using the
online tuning tools available beginning with release 2.1.1.
Refer to the Oracle9i Deployment Guide document (included on the product CD) for
information on Oracle hardware requirements, Oracle database setup, IntruShield
Manager installation for use with a remote Oracle database, and for information on
proper database tuning.
If you are using an Oracle database, McAfee strongly recommends that you employ
an Oracle DBA to maintain your database.
Note
See Chapter 4 of the Manager Administrator’s Guide for more details on port
clustering.
Warn ing
A database left untuned can, over time, lead to data corruption.
Tip
See Chapter 6 and Appendix of the Manager Administrator’s Guide for more
information on tuning your database.
Kommentare zu diesen Handbüchern