
1
Planning and Overview
8
EFW Domain
An EFW domain is a collection of Policy Server and EFW device components that can share
EFW-related data, such as the following policy and EFW device information:
■
A policy defined within an EFW domain can be assigned to any EFW device in that
domain.
■
Any Policy Server in a domain can serve as a backup Policy Server for any EFW device
in this domain since it has access to all information about this EFW device.
■
Audit queries can search all audit data generated within a domain.
An EFW domain can consist of as many as three Policy Servers. Although the EFW system
software does not place any limits on the number of devices for which a Policy Server is
the primary Policy Server, to ensure better performance a maximum of 1,000 EFW devices
per Policy Server is recommended. A Management Console connected to any Policy Server
in a domain has access to all EFW data for that domain. When you are connected to any
Policy Server within a domain, you can view or make changes to any EFW device in that
domain, regardless of whether it is a primary or backup server for that EFW device.
When installing a new Policy Server, you must indicate whether the Policy Server is the
first Policy Server in a new domain or if it is joining an existing domain. If it is joining an
existing domain, you must identify a Policy Server that already belongs to that domain.
The new Policy Server automatically obtains all domain information from the existing
Policy Server when it joins the domain.
NOTE:
Organizations that require more than three Policy Servers or 3,000 EFW
devices need to partition their enterprise into multiple EFW domains. However, the
same Management Console may be used to access any domain.
Server
Workstation
EFW
device
Management
Console
EFW
device
Policy Server
EFW
device
Secured
computer
Secured
computer
(with multiple NICs)
EFW
device
EFW
device