IBM Security Guardium

 View Only
  • 1.  Load Balance

    Posted Wed June 17, 2020 12:21 PM
    Hi Wendy,
     I have setup Load Balance and set those parameter to value as follows: I have Managed group with 3 collector IP and I have STAP group with 15 STAP. i have defined STAP_SQLGUARD_IP for 5 STAP, collector 1, for other 5 STAP, collector 2, while for 5 STAP, collector 3, I didnt define STAP_ADDITIONAL_SQLGUARD_IPS because this value should be taken by Enterprise parameter value CM. But what I am seeing all the STAP's have Primary STAP_SQLGUARD_IP is collector 2, we are having high CPU and Memory Utilization alert on collector 2. why we are seeing this behavior, this STAP should be distributed on coll 1, coll 2 and coll 3.


    STAP_PARTICIPATE_IN_LOAD_BALANCING = 4
    STAP_LOAD_BALANCER_NUM_MUS=3
    STAP_SQLGUARD_IP=

    Thanks,
    Farah





    ------------------------------
    farah zabe
    ------------------------------


  • 2.  RE: Load Balance

    IBM Champion
    Posted Wed June 17, 2020 01:37 PM
    Hi @farah zabe:

    STAP_PARTICIPATE_IN_LOAD_BALANCING needs to be set to 1 to use ELB.

    STAP_LOAD_BALANCER_NUM_MUS you'll want to use 1 or 2.  1 means that the CM will designate a primary collector, 2 means the CM will designate a primary and a secondary, but don't use it unless you are running v10.6 or greater.  3 in this parameter means that it will spread the events across multiple collectors at the same time.  

    STAP_SQLGUARD_IP, with ELB you do not set this parameter, the CM will set it.

    Start using STAP_LOAD_BALANCER_IP and set this as your CM's IP.

    ​​

    ------------------------------
    Wendy Zemba
    ------------------------------



  • 3.  RE: Load Balance

    IBM Champion
    Posted Wed June 17, 2020 01:42 PM
    Hi @farah zabe:

    Correction, sorry.  STAP_PARTICIPATE_IN_LOAD_BALANCING needs to be set to 0 to use ELB.

    ------------------------------
    Wendy
    ------------------------------



  • 4.  RE: Load Balance

    Posted Thu June 18, 2020 09:38 AM
    ​Hi Wendy,
              I have setup all the parameter as you suggested last night, But since then STAP's are in synchronizing state on all 3 collectors.

    Thanks,
    Farah


    ------------------------------
    farah zabe
    ------------------------------



  • 5.  RE: Load Balance

    IBM Champion
    Posted Thu June 18, 2020 01:32 PM
    @farah zabe 

    In 10.6, we had situations where ELB would set the SQLGARD_IP as the CM instead.  I'll have to research for the bug number.

    Do you have ​​access to the guard_tap.ini file on the source system to validate?

    Another thing you should ensure that the value in the STAP_TAP_IP parameter is the same value you are using in your S-TAP group.   IP to IP or hostname to hostname.

    Assume that you opened TLS Port 8443 between CM and Collectors.

    ------------------------------
    Wendy
    ------------------------------



  • 6.  RE: Load Balance

    Posted Tue June 23, 2020 11:58 AM
    ​Hi Wendy,
               I have checked it didn't setup SQLGARD_IP as the CM instead. I had to change the value for this parameter STAP_PARTICIPATE_IN_LOAD_BALANCING  to 4 in order to get STAP active and to capture the traffic successfully.
    I am sure there must be bug for Load Balance. Also we are using 10.6 STAP version while our appliances are on version 10.5.

    Also I have setup windows Load Balance for MSSQL servers. when i am giving this parameter STAP_PARTICIPATE_IN_LOAD_BALANCING  value to 4, all STAP's are inactive on 1 collector while on other 2 additional collector no STAP's are showing up. when i changed this parameter STAP_PARTICIPATE_IN_LOAD_BALANCING  value to 1, all the STAP's are showing up active on collector 1 while still on other 2 collectors nothing is showing up. I will be able to capture the traffic successfully on collector 1.

    Please let me know what is the process to setup Load balance for MSSQL.
    1- what is the correct value for this Parameter for all DB Types
    STAP_PARTICIPATE_IN_LOAD_BALANCING if using ELB.

    Thanks,
    Farah

    ------------------------------
    farah zabe
    ------------------------------



  • 7.  RE: Load Balance

    IBM Champion
    Posted Tue June 23, 2020 12:04 PM
    Hi @farah zabe:

    The correct value for ​ STAP_PARTICIPATE_IN_LOAD_BALANCING is 0 for ELB.  We've had no issues with this feature on Windows machines.  Did you try setting STAP_PARTICIPATE_IN_LOAD_BALANCING to 0 ?

    ------------------------------
    Wendy
    ------------------------------



  • 8.  RE: Load Balance

    Posted Wed June 24, 2020 02:14 PM
    ​Hi Wendy,
            Thank you for your quick response. I will try with 0 this weekend. I will keep you posted.

    Thanks,
    Farah


    ------------------------------
    farah zabe
    ------------------------------



  • 9.  RE: Load Balance

    IBM Champion
    Posted Tue July 07, 2020 10:17 AM
    @farah zabe

    Multi-threading is a completely different thing.  If that's what you are trying to do then we can have a different conversation.  To use Enterprise Load Balancing it should be PARTICIPATE_IN_LOAD_BALANCING=0.  Here's a link to the knowledge center pages on configuring Windows for ELB.  There has to be some other setting that isn't right.

    https://www.ibm.com/support/knowledgecenter/SSMPHH_10.6.0/com.ibm.guardium.doc.stap/stap/r_stapparmsw_tap1.html

    ------------------------------
    Wendy
    ------------------------------



  • 10.  RE: Load Balance

    Posted Wed June 24, 2020 11:36 AM
    Regarding "10.6 STAP version while our appliances are on version 10.5": It is okay for the appliances to be a version ahead of the agents but not the other way around. I recommend to upgrade your appliances to at least 10.6 like the agents, starting with the CM, then Aggregators, and then Collectors. While this may or may not be the cause of the load balancing issues, it may introduce other undesirable behaviors.

    ------------------------------
    Douglas Freeby
    NC
    ------------------------------