Application Permissions to reduce "traffic" - SOLUTION!!!

Hi Everyone! :slight_smile:

I’ve got a Routing StatServer (7.6.100.12) that is not playing very nicely… It seems to be falling over when too many updates are being applied (from config), whilst dealing with stat requests from our URS…

Rather than looking at the number of requests, I am considering what I can do to reduce the number of updates being applied through the config. From what I understand, if the StatServer Application Permissions are updated in CME, then the Application is restarted, you can reduce the config updates being sent to it. So - when updates are being applied to other Solutions (such as WfM or Outbound or Reporting) the Application is excluded from receiving those updates and concentrates solely on the updates it requires (Stats and Routing Objects only) and it can then better fulfill it’s primary role of dealing with stat requests from the URS…

This is just a theory - does anyone have any experience in applying this, to any degree of success?

Thanks!

Tony

I seemed to have the same issue with Stat server 7.6 ( dont remeber the exact version any more) it was fialing ie randlomly stopping once we changed users in Config server or made changes to the object we upgraded to the following hot fix 7.6.100.37 [12/11/2009] – Hot Fix seemed to resolve the issue try it

thanks

Hi,

I’ve used a similar approach (CME permissions) to reduce load on StatServers used for realtime reporting (with CCPulse) where there was a dedicated StatServer for each geographic site (with a “central” switch i.e. common T-Server).

I considered it very successful, but CME permissions can become a headache to manage when they get complex.

We also found a number of defects in Configuration Server (7.6) most of which were fixed by 7.6.000.36 related to permissions changes.

Also, making CME permissions changes when applications are under load (i.e. during business hours) can cause problems (particularly to Genesys Desktop) in my experience.

Regards,
Alistair

OK - I’ll take a look at the possibility of an upgrade (the version mentioned in actually a Hot Fix and I am not keen on that..) and I will continue to look at permissions as a way forwards…

Thanks for the input so far guys! :slight_smile:

Tony

I’m using permissions to reduce network traffic and avoid some problems (per example with Symon Genesys Collector performance). From my point of view it’s quite simple. If you are using geographically distributed environments with CSProxy is even simpler and permissions you can set up only at CSProxy level (no need to distribute this to all applications). Till now I’ve found one big challenge - DataSourcer. It’s quite obvious if it collects data only for agents, groups, routing points and queues, but if it collects also calling list and campaign groups data you must be very careful, especially if after setting permissions DataSourcer is seeing less objects. For other applications like StatServer or URS I didn’t notice any problems.

1 Like

Hi Tony.

I see your reply by e-mail notification, but I don’t see it in topic tree. To answer your questions I wouldn’t recommend modifying SYSTEM account permissions. It’s one possible way, but I think very dangerous. I can recommend to create new account, propagate No Access permission at Tenant level, then give access to specific and needed objects and start applications with this specific, newly created account (App Security\Log On As). I think it’s the best and secure way to achieve your goals.

1 Like

Excellent responses - I understand them implicitly - thank you!

I think I am going to have a bit of a task on my hands, though - I am looking at the Permissions for our Network URS and it seems as if it needs Permissions to just about everything, anyway… I wanted to exclude Service Numbers or perhaps some of the Site/Premise Objects but it seems to use those too.

Has anyone any specific advice relating to the Permissions for a Network URS - perhaps some Do’s and Dont’s…?

Great stuff so far everyone - thank you! :slight_smile:

T

Sort of nearly answering my own question…

The Routing Stat Servers serve the Inbound Call Routing being served by the Network URS’s. We also have MCR, WfM, CCA and a few other Solutions which have nothing to do with our ICR Solution. I can use an Access Group and a new User to exclude access for the Routing Stat Servers to those Applications and components in CME.

In this way, I should be able to reduce the amount of config updates and general “traffic” being sent to the Routing Stat Server.

Is anyone able to confirm that this a “Best Practice” approach?

Thanks!

T

Almost done with this - all you Dev/Planning and Implementation guys out there might want to consider the following…

If you create Solution Sub-Folders in the Resources Section within CME, you can restrict access to for your Server Applications much more easily - thereby reducing the load on them.

For example;

Your Resources>Persons Folder (…and >Place Groups and >DN Groups and >Agent Groups… etc.) could contain 2 sub-Folders at the top level, to enable you to split your Resources into Multimedia and Voice. You would also need to create a User who has Permissions to access the Multimedia Folders (and not the Voice Folders) and another User who has Permissions to access the Voice Folders (and not the Multimedia Folders). Applying these Users as the Account you use to (re-)start your Server Applications means (for example); when you restart your Mutlimedia Routing Stat Server it will only accept/receive updates regarding Mutlimedia Resources - and not Voice Resources (which it doesn’t need), cutting down the configuration messaging traffic dramatically in both Solutions.

If you already knew this - well done! :slight_smile: If you didn’t and your Platform is “struggling” it might be time to give it a closer look… :wink:

Tony

Hey Tony,
Nice tip, but for a better understanding do you think you can attach a network diagram of how many servers were impacted by this and which components were on each one? In that way we can have a better idea on how to deploy it and if needed…
Thanks!

Hi Tony,

Beside subfolders, you can also use Configuration Units. Then managing permissions is even simpler.

Configuration Units…? Please tell me more… lol

Tony

Hi cav :slight_smile:

I still can’t seem to attach anything to my posts, so I’ll take a look at the build at the next opportunity and write them out… I’m not clear on how that will help anyone, though..?

Tony

Really ?? :wink:

1 Like

Yes please - so far, I have been segregating my Resource Folders into “Voice” and “Multimedia”, so that I can use Permissions to separate the Assets… Configuration Units - that sounds like something where you can dump everything in another Folder somewhere, making the job much much easier… ???

TT

Configuration Units are used to create complex configuration hierarchies for business, geographical or any other reasons. At Tenant/Environment level in 7.0+ framework you can create special “subfolder” called Configuration Unit. Inside CU you create folder tree analogical to that one on tenant/environment level so per example for Tenant create folders like Persons, Switches, Agent Groups, Campaigns etc. In that way inside single Configuration Unit you can create all relevant resources for Voice or Multimedia solutions in one place.

Look at framework 7.0+ documentations for specifics.

Thank you - I shall take a look…

…I’m just wondering how I missed this in the documentation… since 7.x…??? :slight_smile:

TT

I suppose that usually you don’t do ‘right-click’ on Tenant or Environment level so you didn’t discover this functionality. Besides CU I’ve done ‘right-click’ only to re-configure GVP.

1 Like

OK - I see it now… I also understand that that may have been a good option to chose when first implementing Configuration items, to seperate the various Solutions during the initial build. I’ve had a play around with it and you can drag>drop any Folder into it, which is very useful.

Very useful for new Sites but the environment I am woking with is rather complex and I think it would actually be easier to allocate Solution sub-Folders & Permissions under each type of Resource, rather than splitting everything between (4) Solution Configuration Units.

TT

Since I (still) cannot attach graphics, here is a narrative;

ALWAYS TRY OUT EVERYTHING BEFORE YOU APPLY IT IN YOUR PRODUCTION SYSTEM! :slight_smile:

METHOD:

Add sub-folders under the following Resources and drag/drop the relevant sub-sub-Folders into each one, according to the Solution-type;

Agent Groups>Voice>(Agent Groups)
Agent Groups>Multimedia>(Agent Groups)
AND
DN Groups>Voice>(DN Groups)
DN Groups>Multimedia>(DN Groups)
AND
Persons>Voice>(Persons)
Persons>Multimedia>(Persons)
AND
Place Groups>Voice>(Place Groups)
Place Groups>Multimedia>(Place Groups)
AND
Places>Voice>(Places)
Places>Multimedia>(Places)
AND
Skills>Voice>(Skills)
Skills>Multimedia>(Skills)

Create a Username (Person) configured with access removed for all of the Multimedia Folders (Called “Voice Only”). Do this by navigating to all of the Resources>Multimedia Sub-Folders, right-click them and update the Security>Permissions options, adding the Voice Only Username then select “No Access”.

Create a Username (Person) configured with access removed for all of the Voice Folders (Called “Multimedia Only”). Do this by navigating to all of the Resources>Voice Sub-Folders, right-click them and update the Security>Permissions options, adding the Multimedia Only Username then select “No Access”.

Identify the Applications which are ONLY Voice (and do not need access to Multimedia Resources such as DN Groups, Agent Groups, Place Groups, etc.) - this may include identifying Config Proxies too - and restart them, using the “Log On As” Username Voice Only. Do this by navigating to the Application(s) in the Environment Section and click on the Security Tab - then navigate to the “Log On As” section and updated the “SYSTEM Account” to “This Account” and select the Username Voice Only.

Identify the Applications which are ONLY Multimedia(and do not need access to Voice Resources such as DN Groups, Agent Groups, Place Groups, etc.) - this may include identifying Config Proxies too - and restart them, using the “Log On As” Username Multimedia Only. Do this by navigating to the Application(s) in the Enviornment Section and click on the Security Tab - then navigate to the “Log On As” section and update the “SYSTEM Account” to “This Account” and select the Username Multimedia Only.

RESULTS EXPECTED:

The end effect is that the Applications for Voice should only be servicing Voice components and the data throughput is greatly reduced, since it is not “aware” of Multimedia components/objects - and vice versa for Multimedia Applications.

This, overall, shoud add a massive amount of stability to the overall Platform by ensuring the Framework and Solution Applications are constrained to their own Solution objects and statistics, etc. - and are not operating with a high volume of messaging for objects and statistics which it does not use.

  • Let me know if this makes sense, anyone…? lol

TT