Deploy Software Agents
Secure Workload software agent is a lightweight piece of software that you install on your workloads. The purpose of the agent is to:
-
Collect host information such as network interfaces and active processes running in the system.
-
Monitor and collect network flow information.
-
Enforce security policies by setting firewall rules for hosts on which the software agent is installed and enabled.
Agents automatically update the Secure Workload inventory when interface addresses change. You do not need to install agents on end-user (employee) computers.
After the software agent is deployed, the agent is assigned a unique identity by the Secure Workload cluster. The unique identity is based on a set of parameters specific to the host where the agent is running. If the host name and the BIOS UUID are a part of the set of parameters, you may encounter the following issues:
|
Installer scripts downloaded from LDAP or AD accounts with automatic role mapping fail once you are logged out. To give the installer scripts uninterrupted access to the cluster, enable Use Local Authentication. |
-
Registration failure when cloning a virtual machine and retaining the BIOS UUID and host name, and when instant cloning a VDI. The registration failure happens because Secure Workload already has a registered software agent using the same parameters set. You can delete the registered agent using OpenAPI. In some cases, a duplicate BIOS UUID configured during startup is changed by VMware after a certain period of time. Agent registration recovers once the Cisco Secure Workload services are restarted.
-
A new identity is generated for the agent if the host name is changed and the host rebooted. The redundant or the old agent is marked as inactive after a certain period of time. For more information, see Frequently Asked Questions section.