McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE Spezifikationen

Stöbern Sie online oder laden Sie Spezifikationen nach Software McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE herunter. McAfee ENDPOINT ENCRYPTION ENTERPRISE - BEST PRACTICES GUIDE Specifications Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 120
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - 4.0 and

Best Practices GuideMcAfee® ePolicy Orchestrator® 4.0 and4.5

Seite 3 - Contents

Task1Click Menu | Automation | Server Tasks to open the Server Tasks Builder.2Click Edit for one of the following tasks.• Duplicate Agent GUID — Clear

Seite 4

Task1Under Reliability and Performance, click Monitoring Tools | Performance Monitoring, then click the plus sign(+). The Add Counters dialog box appe

Seite 5 - Index 113

You can also check how quickly your ePolicy Orchestrator server processes events from agents bylooking in the Events folder on the McAfee ePO server.

Seite 6

• "4.0.0" — Is the product revision number• "1421" — Is the build number. That build number indicates this is "Patch 2"T

Seite 7 - About this guide

• Because the scan timed out due to the size of the file, which is a 1059 event• The file was not scanned because it was inaccessible due to a passwor

Seite 8 - Finding product documentation

13SQL maintenanceFor your McAfee ePO server to function correctly it is very important to have a well performing SQLdatabase. It is the central storag

Seite 9

Setting up a maintenance task to automatically reindex and rebuild your ePolicy Orchestrator SQLdatabase only takes a few minutes and is essential to

Seite 10

14Disaster recovery Many ePolicy Orchestrator users want to know how to set up ePolicy Orchestrator for a disasterrecovery scenario. There are a few o

Seite 11 - Architecture overview

Use server clusters for disaster recoveryIf you require zero downtime if a hardware failure occurs you can cluster your ePolicy Orchestrator andSQL se

Seite 12

Now, if the primary site fails you must make all the agents previously communicating with the primaryMcAfee ePO server start communicating with the s

Seite 13 - Hardware configuration

2ePolicy Orchestrator product architectureThe ePolicy Orchestrator software architecture offers extensive functionality that can be configuredmany dif

Seite 15

15Reference documentationFollowing are several informative and valuable links for your McAfee implementation.Product videosSupport Video Tutorials— Th

Seite 16

Other Informative ArticlesDeploying SQL Server 2005 with SAN #1Deploying SQL Server 2005 with SAN #2Deploying SQL Server 2005 with SAN #3SQL Storage T

Seite 17 - SAN usage

IndexAabout this guide 7Active Directoryorganizing the System Tree 51synchronization 46, 51AD, See Active DirectoryAgent Handlersabout 11, 35increased

Seite 18 - Small organization example

databases (continued)installed with ePolicy Orchestrator 13maintaining 105recommended hardware 17reindex 105restoring 107server clusters for disaster

Seite 19 - Large organization example

IP address (continued)used to sort the System Tree 52LLDF file 14Mmaster repositorydefault 29disabling from ePolicy Orchestrator server 73on ePolicy O

Seite 20 - • 32 – 128 GB of RAM

server tasks (continued)acting on a query 69serverscombining ePolicy Orchestrator and database 13disaster recovery 107finding performance problems 100

Seite 24

1ePO server — Connects to the McAfee update server to download the latest security content2ePO Microsoft SQL database — Stores all the data about the

Seite 26

6McAfee update server — Hosts the latest security content so your ePolicy Orchestrator can pullthe content at scheduled intervals.7Distributed reposit

Seite 27 - Place repositories

Use VMs for the McAfee ePO ServerThe McAfee ePO server supports multiple versions of virtual environments, but when your node countreaches 25,000 to 3

Seite 28

Manage fewer than 5,000 nodesIf you have fewer than 5,000 nodes to manage with the McAfee ePO server, disk configuration is rarelyan issue. Use your n

Seite 29 - Determine repository count

• RAID 1 for the operating system with individual partitions for the SQL database (the MDF file) andthe SQL transaction log (the LDF file).• RAID 1 fo

Seite 30

SAN usageStorage area network (SAN) devices are the standard configuration for larger storage requirementssuch as SQL databases that require backup a

Seite 31

The following sections offer hypothetical environments to provide some guidelines for organization sizeand hardware requirements.These example provide

Seite 32 - Global updates

Medium organization exampleA medium organization ranges from 5,000 to 25,000 nodes. A single McAfee ePO server can easilymanage this size organization

Seite 33 - How Global Updates works

COPYRIGHTCopyright © 2011 McAfee, Inc. All Rights Reserved.No part of this publication may be reproduced, transmitted, transcribed, stored in a retrie

Seite 34

• 16 processors• 32 – 128 GB of RAM• At least 300 GB of space for the SQL databaseThese are not upper limits for hardware. If you have the budget fora

Seite 35 - Agent Handlers

3RepositoriesA repository is a file sharing device that serves out files for clients to download. It does not managepolicies, collect events, or have

Seite 36

• UNC share repositories• SuperAgentsThere are several things to keep in mind about these repositories:• The McAfee ePO server requires certain protoc

Seite 37 - Orchestrator software

1Create the folder2Adjust share permissions3Change the NTFS permissions4Create two accounts, one with read and another with write accessAll of these t

Seite 38 - In-place upgrade tips

Creating a new SuperAgent policyA SuperAgent policy allows you to assign that policy to client machines to convert them to SuperAgents.Task1From the P

Seite 39 - Move the server

Task1From the System Tree, click System Tree Actions | New Subgroup and give it a distinctive name, forexample 1_SuperAgents. 2Click OK. The new grou

Seite 40

Task1From the SuperAgent group you created, click the Assign Policies tab and select McAfee Agent from theProduct list.2From the Actions column, click

Seite 41 - Using Transfer Systems

Task1In the System Tree, click the Systems tab and find the system you want to change to a SuperAgentrepository.2Drag that row with the system name an

Seite 42

To download the daily DAT file randomly from the central ePO server to the system agents takes thefollowing bandwidth: 100 Agents * 200 KB file = 20 M

Seite 43 - McAfee Agent

Example 2 — A large office in TokyoThe large office in Tokyo needs to download the 200 Kb per day for DAT files to its 4,000 nodes, usingthe formula:(

Seite 44 - Deploying agents

Contents1 Preface 7About this guide ...7Audience ...7Conventions ...

Seite 45

Server hardware Nodes updated Dedicated or sharedclient hardwareSingle 3 Ghz processor with 4 GB of memory 3,000 Shared with otherapplications3,000 –

Seite 46

The EMEA offices have another data center in the UK with several other offices across EMEA. Theseother offices range from 200 nodes 3,000 nodes. The o

Seite 47 - Communication column

Improve agent update performanceIn large environments, the ePolicy Orchestrator server is already very busy distributing policies andcollecting events

Seite 48

How Global Updates worksIf the McAfee ePO server is scheduled to pull the latest DATs from the McAfee website at 2 p.m.Eastern time, and it changes th

Seite 50

4Agent HandlersAgent Handlers co-ordinate work between themselves and the McAfee ePO server that communicateswith the remote Agent Handlers. Agent Han

Seite 52

5Installation and upgrade of ePolicyOrchestrator softwareThere are two types of ePolicy Orchestrator installations: a new installation in an environme

Seite 53

• You retain all your policies and client tasks — This means you don't have to rebuild them andcould save you time.• You retain your directory st

Seite 54

• Test your upgrade in a VM environment with a copy of your SQL database to make sure theupgrade works smoothly.• Validate all your settings to confir

Seite 55 - Policies and packages

6 McAfee Agent 43Agent functionality ...43Deploying agents ...44Deploy from the McAfee

Seite 56 - McAfee agent policy

Move McAfee Agents between servers Before the release of ePolicy Orchestrator 4.5, many customers wanted an upgrade path that wouldallow them to start

Seite 57

Exporting and import the ASSC keysYou must export the agent-server secure communication (ASSC) keys from the old server to the newserver before moving

Seite 58 - Configuring ASCI

3Select the systems to move to the new McAfee ePO server and click Actions | Agents | Transfer Systems.The Transfer Systems dialog box appears. 4Sele

Seite 59

6McAfee AgentThe McAfee agent is the liaison between all point-products and the McAfee ePO server. This 5 MBexecutable file is not a security product

Seite 60 - Deploying packages

Once an agent is installed on a system, you never need to use a third-party deployment tool to updateanything on that client.Figure 6-1 One agent to

Seite 61

The McAfee Agent is a 5 MB executable file that can simply be executed manually or more commonlydeployed on a larger scale to hundreds or thousands of

Seite 62

If you gave this custom McAfee Agent to your desktop team a year ago, it is probably outdated. Itbecomes outdated if, for example you have made change

Seite 63 - Client tasks

• The machines in your AD tree must be well maintained. This is not always the case in many largerorganizations. Machines need to be deleted and place

Seite 64

Using third-party tools is not a requirement, but your organization might have strict policies thatdictate how products are deployed for consistency a

Seite 65 - Updating products

Confirm you deleted the agent GUID before freezing the imageIf you choose option 1, Include the agent in your Windows image it can cause one of the mo

Seite 66

14 Disaster recovery 107Configuring simple disaster recovery ...107Use server clusters for disaster recovery ...

Seite 68

7Organizing your System TreeYour System Tree is a very important feature of your McAfee ePO server and you can configure theSystem Tree hierarchy in m

Seite 69 - Server tasks

Dynamically sorting your machines To dynamically sort your machines into your ePolicy Orchestrator System Tree use a combination ofsystem criteria, su

Seite 70 - Creating a server task

Organizing your System TreeDynamically sorting your machines7McAfee® ePolicy Orchestrator® 4.0 and 4.5 Best Practices Guide53

Seite 72

8Policies and packages Policies are the settings that govern each product on the endpoint. Packages are the binaries that canbe deployed by the McAfee

Seite 73

This is not an exhaustive list and new products are constantly being added as McAfee expands itssolution portfolio. Because of the McAfee ePO server&

Seite 74 - Purge events automatically

• Collects and sends its properties to the McAfee ePO server or Agent Handler• Checks to see if any policy changes or client tasks have occurred on th

Seite 75

Configuring ASCI Configure the ASCI to determine how often every McAfee Agent calls the McAfee ePO serverThe ASCI is set to 60 minutes by default. If

Seite 76 - Purging events by query

Task1Click Menu | Policy | Policy Catalog, then select McAfee Agent from the Product list and General from theCategory list.2Click the General tab, an

Seite 78

1Click Menu | Policy | Policy Catalog, then select McAfee Agent from the Product list and General from theCategory list.2Click the General tab, and ty

Seite 79

TaskFor option definitions, click ? in the interface.1Click Menu | Configuration | Server Settings, then in the Settings Category pane click Repositor

Seite 81 - Reporting

9Client tasks Client tasks run on the clients and are typically scheduled to run at a specific time. They are differentfrom policies because they are

Seite 82 - Custom queries

Configuring which products are deployed Configure the agent client to deploy a product. See McAfee ePolicy Orchestrator 4.5 Product Guide fordetails.T

Seite 83

nodes and you only have one repository, those 5,000 nodes are pulling a total of 180 GB of data fromthat one repository when the deployment task is ex

Seite 84

Signatures, or DAT files, are released on a daily basis at approximately 11 a.m. Eastern time andaverage 200 Kb per day. Optionally, you can deploy ot

Seite 85

4Choose the content to update using this task. In this example the Daily Master Update task downloads the VirusScan Enterprise DAT and Enginefiles.If

Seite 86

5Click Next to configure the schedule for this task.The key to a good update task is updating several times per day at completely random intervals.Man

Seite 87

10Server tasks Server tasks are any item that is scheduled to run on the McAfee ePO server itself. Using server tasksproperly can significantly improv

Seite 88 - Event summary queries

PrefaceContents About this guide Finding product documentationAbout this guideThis information describes the guide's target audience, the t

Seite 89

1Give your server task a descriptive name.2Choose an action then a subaction. This is the most important part of creating your task. After thetask per

Seite 90

3Configure a weekly report.• Click Run Query from the Actions list.• Click Managed Inactive Agents query from the Query list dialog box that appears,

Seite 91

3Configure an email report.• Click Run Query from the Actions list.• Click Managed Inactive Agents query from the Query list dialog that appears, then

Seite 92

of content into each branch. Then the different versions can be rolled out to a selected group of testmachines before a full deployment to the entire

Seite 93

3From the Repositories list, find the McAfee ePO server and click Disable in the Actions column. 4Click Save to disable the McAfee ePO server reposit

Seite 94

TaskFor option definitions, click ? in the interface.1Click Menu | Automation | Server Tasks, then click Action | New Task. The Server Task Builder di

Seite 95

events is only 10 days because it collects all URLs that are visited by managed machines. Thiscan save a lot of data in environments with greater than

Seite 96

Deleting inactive systems automaticallyMost environments are constantly changing, new systems are added and old systems removed. Thiscreates inactive

Seite 97

1Click Menu | Automation | Server Tasks and click Edit for the Inactive Agent Cleanup Task for 4.5 in theAction column. The Server Task dialog box app

Seite 98

Changing the Managed Inactive Agents queryThe Inactive Agent Cleanup server task uses a preconfigured query named Managed Inactive Agents.Whichever sy

Seite 99 - FAQ and common scenarios

Finding product documentationMcAfee provides the information you need during each phase of product implementation, frominstallation to daily use and t

Seite 101

11ReportingePolicy Orchestrator ships with its own querying and reporting capabilities. These are highlycustomizable, flexible and easy to use. The Qu

Seite 102

The following example shows some of the categories of preconfigured queries provided with theePolicy Orchestrator software. Custom queries Creating c

Seite 103 - 1051 and 1059 events

• Have not communicated with the McAfee ePO server in a while• Are suspected of not working properly when you attempt to wake them up• Need a new agen

Seite 104

Creating custom event queries Create a custom query.Task1Click Menu | Reporting | Queries, then Actions | New Query. The Query Wizard appears starting

Seite 105 - SQL maintenance

ReportingCustom queries11McAfee® ePolicy Orchestrator® 4.0 and 4.5 Best Practices Guide85

Seite 106

3You must choose the label or variable that you want the report to display. There are many variablesyou can choose to have the McAfee Agent reports di

Seite 107 - Disaster recovery

4You can choose the columns that you want to see if you drill down on any of the variables in yourreport. This is not a critical component when buildi

Seite 108

5Click Next to not create any filters and display all of the operating system types.6Click Run to generate the report and see the results. After you

Seite 109

3Click Events in the Features Group and Client Events in the Result Type. Click Next to continue to theChart dialog box. 4Under Summary, click Single

Seite 110

1History of McAfee ePolicy OrchestratorsoftwareePolicy Orchestrator software is a mature security management platform that delivers the quality andsta

Seite 111 - Reference documentation

5Click Event Description, in the Labels are list, under Threat Event Descriptions to create a filter with agood human readable description of the even

Seite 112 - Other Informative Articles

8Click Run to display the query report. In this example there are 308 client events total. If you want, you can click one event and drilldown on it t

Seite 113

5Click Event Description, in the Labels are list, under Threat Event Descriptions to create a filter with agood human readable description of the even

Seite 114

8Click Run to display the query report. The McAfee ePO server displays approximately 8,000 threat events total.The data shown in this example comes f

Seite 115

9To determine approximately how many events you should have on your network use the followingformula:(10,000 nodes) x (1 to 2 million events) = estima

Seite 116

4If the event is important, make sure you are monitoring the number of events using theCreating event summary queries and Purging events automatically

Seite 117

5Click Next to skip the Columns dialog box. You can choose the columns you want to analyze.You can skip this step because the McAfee ePO server does n

Seite 118

11Find the custom query you just created and click it in the list. 12Schedule the task to run every night, then click Save.You can use this technique

Seite 120

12FAQ and common scenariosThis chapter contains some frequently asked questions (FAQs) and some common scenarios that anePolicy Orchestrator administr

Kommentare zu diesen Handbüchern

Keine Kommentare