Previous Topic: Define a Logical Host Group

Next Topic: Assignment Paths


Import a Host Group

Importing a host group helps you migrate your existing PMDB structure to advanced policy management. When you import a host group, you create or join hosts to a host group. The hosts correspond to the subscribers of a PMDB.

Note: Advanced policy management does not support hierarchical host groups. When you import a host group from a PMDB, you flatten all subscribers into the same host group. CA Access Control Enterprise Management does not create hosts that correspond to subscriber PMDBs.

For each PMDB subscriber that you join to the host group, CA Access Control Enterprise Management checks if a host (HNODE object) that corresponds to the subscriber already exists on the DMS. If a corresponding host exists on the DMS, CA Access Control adds that host to the host group. If a corresponding host does not exist on the DMS, CA Access Control creates a new host and adds the new host to the host group.

If you do not have permission to access an endpoint, the endpoint does not appear in the wizard and you cannot add the corresponding host to the host group.

To import a host group

  1. In CA Access Control Enterprise Management, do as follows:
    1. Click Policy Management.
    2. Click Host subtab.
    3. Expand the Host Group tree in the task menu on the left.

      The Host Group Import task appears in the list of available tasks.

  2. Click Host Group Import.

    The PMDB Host Login page appears.

  3. Type the user name, password, and name of the PMDB, and click Log In.

    Note: Specify the PMDB name in the format PMDBname@host, for example, master_pmdb@example

    The Host Group Import wizard appears at the General task stage.

  4. Complete the wizard, then click Finish after you read the summary.

    CA Access Control adds the hosts to the host group. If a host does not exist in the DMS, CA Access Control creates a HNODE object for the host before it adds it to the host group (GHNODE).

    Note: When you add a host to an existing host group, CA Access Control automatically deploys to the host any policies that are assigned to the host group.