
Agent relay capability
If your network configuration blocks communication between the McAfee Agent and the McAfee ePO
server, the agent can't receive content updates, policies, or send events.
Relay capability can be enabled on agents that have direct connectivity to the ePolicy Orchestrator
server or Agent Handlers to bridge communication between the client systems and the McAfee ePO
server. You can configure more than one agent as a RelayServer to maintain network load balance.
• You can enable relay capability on McAfee Agent 4.8 or later.
• The ePolicy Orchestrator server can only initiate communication (for example, Show
agent logs) with a directly connected agent.
• Relay capability is not supported on AIX systems.
Communicating through RelayServers
Enabling relay capability in your network converts an agent to a RelayServer. An agent with relay
capability can access the ePolicy Orchestrator server or the distributed repository.
When an agent fails to connect to the ePolicy Orchestrator server or the Agent Handler directly, it
broadcasts a message to discover an agent with relay capability in its network. The RelayServers
respond to the message and agent establishes connection with the server that first responded.
If an agent fails to connect to the ePolicy Orchestrator server or the Agent Handler directly, it tries to
connect to the first RelayServer which responded to the discovery message. The agent discovers the
RelayServers in the network at every ASCI and caches the details of the first five unique RelayServers
that responded to the discovery message. If the current RelayServer fails to connect with the ePolicy
Orchestrator server or doesn't have the required content update, agent connects to the next
RelayServer available in its cache.
• Agents require User Datagram Protocol (UDP) to discover RelayServers in the network.
• RelayServer connects only with the ePolicy Orchestrator server or the distributed
repositories that are listed in its SiteList.xml file. McAfee recommends you to include
the RelayServers sitelist.xml as a super‑set of the site lists of all agents that are
configured to connect through this RelayServer.
On a Windows client system, after the relay capability is enabled through the policy a new service
MfeServiceMgr.exe is installed. This service can be started or stopped to control relay capability on the
client system.
Once the agent has completed uploading or downloading content from the ePolicy Orchestrator server,
the RelayServer then disconnects the agent and the ePolicy Orchestrator server.
Enable relay capability
You can configure and assign policies to enable the relay capability on an agent.
If enabling a non‑Windows system as a RelayServer, ensure that you manually add an exception for the
cmamesh process and the service manager port to the iptables and ip6tables.
Working with the agent from the McAfee ePO server
Agent relay capability
7
McAfee
®
Agent 4.8.0 Product Guide
73
Commenti su questo manuale