Best Practices
Recommended best practices for effective management of cluster:
- Perform all HySecure administration from the Active node in the cluster.
- Ensure every node in the cluster NTP is configured and running.
- Make sure to create any additional host file entries on all nodes as these entries do not sync among the nodes.
- To verify the logs, you must log in as a certificate user on the Active or Standby gateway and check the log.
- Always reboot or shut down the gateway from the management console or OS console.
- Ensure that all maintenance activities, such as HySecure upgrade and failover, must be performed within a 2-hour maintenance window. It is recommended to carry out these activities during off-peak hours.
- Do not change the ping settings on the default gateway.
- Nodes in the cluster must not have any firewall between them and should be installed within the same subnet.
- Take regular backups of configuration by taking User Backup. Also, take System Backup for all certificate backups.
- Set up alerts for resource usage, including RAM and disk.
- Use the latest TLS protocols for the HySecure gateway.
- Configure log archival for optimum disk consumption.
- Enable HyID policies to ensure all login into HySecure gateways are secured by MFA.
- Enable Device ID policies to allow login into the HySecure gateway through authenticated devices only.
- Enable Endpoint Security policies to ensure users log in from secure devices.
- Configure Stale user management to revoke policies and authorization for disabled/removed users from a configured authentication server.
- Ensure that the HySecure gateway is always configured in high availability mode.