McAfee EPOLICY ORCHESTRATOR 3.6 - WALKTHROUGH GUIDE Betriebsanweisung Seite 1

Stöbern Sie online oder laden Sie Betriebsanweisung nach Software McAfee EPOLICY ORCHESTRATOR 3.6 - WALKTHROUGH GUIDE herunter. McAfee EPOLICY ORCHESTRATOR 3.6 - WALKTHROUGH GUIDE Product guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 200
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - Product Guide

McAfee ePolicy Orchestrator 4.0Product Guide

Seite 2

Registering ePO servers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173Crea

Seite 3 - Contents

Ensuring access to the source siteUse these tasks to ensure the master repository and managed systems can access the Internetwhen using the McAfeeHttp

Seite 4

6 Type proxy information into the appropriate fields. To use the default source and fallbacksites, enter the information for HTTP and FTP.7 Select Use

Seite 5

If your server does not need a proxy to access the Internet, select Don’t use proxysettings, then click OK.3 Next to Proxy authentication, configure t

Seite 6

1 Go to Software | Source sites. A list of all sites that can be used as the source or fallbackappear.Figure 20: Source Sites tab2 Locate the site in

Seite 7

Editing source and fallback sitesUse this task to edit the settings of source or fallback sites, such as URL address, port number,and download authent

Seite 8

Deleting SuperAgent distributed repositoriesCreating SuperAgent repositoriesUse this task to create a SuperAgent repository. The desired system must h

Seite 9

1 Go to Software | Distributed Repositories. A list of all distributed repositories appears.2 Locate the desired SuperAgent repository, then click Edi

Seite 10

Creating a folder location on an FTP, HTTP server or UNC shareUse this task to create the folder that hosts repository contents on the distributed rep

Seite 11

If credentials are incorrect, check the:• User name and password.• URL or path on the previous panel of the wizard.• The HTTP, FTP or UNC site on the

Seite 12 - The ePO server

Editing distributed repositoriesUse this task to edit a distributed repository.TaskFor option definitions, click ? on the page displaying the options.

Seite 13 - Using this guide

Performing weekly maintenance of MSDE databases. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 188Performing regular mainten

Seite 14 - Audience

Before you beginYou must have appropriate permissions to perform this task.TaskFor option definitions, click ? on the page displaying the options.1 Go

Seite 15

Before you beginYou must have appropriate permissions to perform this task.TaskFor option definitions, click ? on the page displaying the options.1 Go

Seite 16 - How permission sets work

2 Select the type of distributed repository for which you want to change credentials, thenclick Next. The Repository Selection page appears.3 Select t

Seite 17 - Contacts

Managing Products with Policies and ClientTasksManaging products from a single location is a central feature of ePolicy Orchestrator and isaccomplishe

Seite 18

• Policy pages.• Server tasks.• Client tasks.• Default queries.• New result types, chart types, and properties to select with the Query Builder wizard

Seite 19 - The Event Log

Setting policy enforcementFor each managed product or component, choose whether the agent enforces all or none ofits policy selections for that produc

Seite 20

When you assign a new policy to a particular group of the System Tree, all child groups andsystems that are set to inherit the policy from this assign

Seite 21 - MyAVERT Security Threats

Bringing products under managementUse this task to install an extension (ZIP) file. A product’s extension must be installed beforeePolicy Orchestrator

Seite 22 - Working with user accounts

1 Go to Systems | Policy Catalog, then select the desired Product and Category. Allcreated policies for that category appear in the details pane.Figur

Seite 23 - Working with permission sets

2 Click the blue text next to Product enforcement status, which indicates the number ofassignments where enforcement is disabled, if any. The Enforcem

Seite 24 - Duplicating permission sets

Introducing ePolicy Orchestrator 4.0ePolicy Orchestrator 4.0 provides a scalable platform for centralized policy management andenforcement of your sec

Seite 25 - Working with contacts

1 Go to Systems | System Tree | Policies. All assigned policies, organized by product,are appear in the details pane.2 The desired policy row, under B

Seite 26 - Working with server settings

2 Click New Policy at the bottom of the page. The Create New Policy dialog box appears.3 Select the policy you want to duplicate from the Create a pol

Seite 27 - Specifying an email server

1 Go to Systems | Policy Catalog, then select the Product and Category from thedrop-down lists. All created policies for that category appear in the d

Seite 28

1 Go to Systems | Policy Catalog, then select the Product and Category. All createdpolicies for that category appear in the details pane.2 Locate the

Seite 29 - Filtering the Server Task Log

Importing policiesUse this task to import a policy XML file. Regardless of whether you exported a single policy,or all named policies, the import proc

Seite 30 - Working with the Audit Log

4 Locate the desired policy category, then click Edit Assignment.5 If the policy is inherited, select Break inheritance and assign the policy and sett

Seite 31 - Purging the Audit Log

TaskFor option definitions, click ? on the page displaying the options.1 Go to Systems | System Tree | Systems, then select the group under System Tre

Seite 32 - Working with the Event Log

2 Select the desired system, then click Modify Policies on a Single System.3 Click Copy Assignments, then select the desired products or features for

Seite 33

Creating and scheduling client tasksUse this task to create and schedule a client task. The process is similar for all client tasks.TaskFor option def

Seite 34 - Deleting threat notifications

Frequently asked questionsWhat is a policy?A policy is a customized subset of product settings corresponding to a policy category. You cancreate, modi

Seite 35

The ePolicy Orchestrator server can segment the user population into discrete groups forcustomized policy management. Each server can manage up to 250

Seite 36

Deploying Software and UpdatesIn addition to managing security products, ePolicy Orchestrator can deploy products to yournetwork systems. Use ePolicy

Seite 37

Each McAfee product that ePolicy Orchestrator can deploy provides a product deploymentpackage ZIP file. ePolicy Orchestrator can deploy these packages

Seite 38 - The System Tree

OriginationDescriptionPackage typepackages into the master repositorymanually.Package signing and securityAll packages created and distributed by McAf

Seite 39 - Administrator access

Update packagesProduct deployment packagesIf not implementing global updating for product updating,an update client task must be configured and schedu

Seite 40 - Subnets and IP address ranges

If you are using global updating, this task is unnecessary, although you can create a daily taskfor redundancy.Considerations when creating update cli

Seite 41 - Tags and how they work

RequirementsThese requirements must be met to implement global updating:• A SuperAgent must use the same agent-server secure communication key as the

Seite 42

Replication tasksUse replication tasks to copy the contents of the master repository to distributed repositories.Unless you have replicated master rep

Seite 43 - Systems only

How agents select repositoriesBy default, agents can attempt to update from any repository in the repository list file. Theagent can use a network ICM

Seite 44 - Criteria-based sorting

1 Go to Software | Master Repository, then click Check In Package. The Check InPackage wizard appears.Figure 24: Master Repository tab2 Select the pac

Seite 45 - IP address sorting criteria

TasksConfiguring the Deployment task for groups of managed systemsConfiguring the Deployment task to install products on a managed systemConfiguring t

Seite 46 - Catch-all groups

6 Deploy software and updates — Once your update repositories and policy settings arecreated and configured, deploy the products, components, and upda

Seite 47 - Working with tags

1 Go to Systems | System Tree | Systems, then select the group in the System Treewhich contains the desired system.2 Select the checkbox next to the d

Seite 48

TaskFor option definitions, click ? on the page displaying the options.1 Go to Configuration | Server Settings, select Global Updating, then click Edi

Seite 49

TasksUsing pull tasks to update the master repositoryReplicating packages from the master repository to distributed repositoriesUsing pull tasks to up

Seite 50

Select Evaluation to test the packages in a lab environment first.Select Current to use the packages without testing them first.7 Select whether to pu

Seite 51 - Creating groups manually

3 Select the repository branch that receives the packages.Select Evaluation, to test the packages in a lab environment first.Select Current to use the

Seite 52

4 Select Repository Replication from the drop-down list.Figure 28: Repository Replication server task action5 Select Incremental or Full from the Repl

Seite 53 - GroupA\system2

3 Select Incremental replication or Full replication, then click Next.NOTE: If this is the first time you are replicating to a distributed repository,

Seite 54

2 Paste the copied files and subfolders in your repository folder on the distributed repositorysystem.3 Configure an agent policy for managed systems

Seite 55 - Sorting systems manually

4 Next to Branch, select the desired branch.If your environment requires testing new packages before deploying them, McAfeerecommends using the Evalua

Seite 56

TaskFor option definitions, click ? on the page displaying the options.• Go to Reporting | Queries, select VSE: DAT Deployment in the Queries list, th

Seite 57

Configuring ePolicy Orchestrator ServersThe ePO server is the center of your managed environment, providing a single location fromwhich to administer

Seite 58

TaskFor option definitions, click ? on the page displaying the options.1 Go to Software | Master Repository. The Packages in Master Repository tableap

Seite 59

Sending NotificationsThe ePolicy Orchestrator Notifications feature alerts you to events that occur on your managedsystems or on the ePolicy Orchestra

Seite 60

Notifications and how it worksBefore you plan the implementation of Notifications, you should understand how this featureworks with ePolicy Orchestrat

Seite 61

rule is named VirusDetected_<groupname>, where <groupname> is the name of thegroup as it appears in the System Tree (for example, VirusDet

Seite 62

Default rulesePolicy Orchestrator provides six default rules that you can enable for immediate use while youlearn more about the feature.NOTE: Once en

Seite 63

• The types of events (product and server) that trigger notification messages in yourenvironment.• Who should receive which notification messages. For

Seite 64 - Agents and SuperAgents

5 To regulate traffic size, type the Maximum number of events per upload.6 Click Save.Determining which events are forwardedUse this task to determine

Seite 65 - Agent-server communication

3 Next to Notifications, click Edit.4 Select the desired Notifications permission:• No permissions• View notification rules and Notification LogNOTE:

Seite 66 - /P command-line option

2 Provide the name and address of the SNMP server, then click Save.The added SNMP Server appears in the SNMP Servers list.Duplicating SNMP serversUse

Seite 67

Working with registered executables and external commandsUse these tasks to configure external commands by adding registered executables and assigning

Seite 68 - Agent policy settings

Working with the Event LogWorking with MyAvert Security ThreatsExporting tables and charts to other formatsAllowed Cron syntax when scheduling a serve

Seite 69

Editing registered executablesUse this task to edit an existing registered executable entry.Before you beginYou must have appropriate permissions to p

Seite 70 - Security Keys

TaskFor option definitions click ? on the page displaying the options.1 Go to Automation | External Commands, then click New External Command at thebo

Seite 71 - Methods of agent distribution

Creating and editing Notification rulesUse these tasks to create and edit Notification rules. These allow you to define when, how, andto whom, notific

Seite 72 - Distributing agents

5 Set the priority of the rule to High, Medium, or Low.NOTE: The priority of the rule is used to set a flag on an email message in the recipient’sInbo

Seite 73

2 If you selected Send a notification if multiple events occur within, you can chooseto send a notification when the specified conditions are met. The

Seite 74

• Selected categories • Selected threat or rule name• Event IDs• First event time• Event descriptions • Actual number of systems• Actual products• Act

Seite 75

TaskFor option definitions, click ? on the page displaying the options.1 Go to Reporting | Notification Log.2 Select the desired period of time for wh

Seite 76 - Installing the agent manually

TaskFor option definitions, click ? on the page displaying the options.1 Go to Reporting | Notification Log, then click Purge at the bottom of the pag

Seite 77 - C:\TEMP

• Any external tool installed on the ePolicy Orchestrator server.Sending NotificationsFrequently asked questionsMcAfee ePolicy Orchestrator 4.0 Produc

Seite 78 - Upgrading existing agents

Querying the DatabaseePolicy Orchestrator 4.0 ships with its own querying and reporting capabilities. These are highlycustomizable and provide flexibi

Seite 79

What happens when I install new products?When a new product extension is installed it may add one or more groups of permissions tothe permission sets.

Seite 80 - Removing the agent

Queries as dashboard monitorsUse almost any query (except those using a table to display the initial results) as a dashboardmonitor. Dashboard monitor

Seite 81 - Maintaining the agent

as well as the ability to make any personal query available to anyone with access to publicqueries.NOTE: To run some queries, you also need permission

Seite 82

• Grouped summary table• Line chart• Pie chart• Summary table• TableTable columnsSpecify columns for the table. If you select Table as the primary dis

Seite 83

Preparing for roll-up queryingUse these tasks to ensure the eporollup_ tables on the reporting server are populated and readyfor using queries based o

Seite 84

3 Select the desired Data Roll Up actions, and select the desired registered server to whichit applies.NOTE: McAfee recommends creating one server tas

Seite 85 - Running an update manually

7 Click Next. The Filter page appears.8 Select properties to narrow the search results. Selected properties appear in the contentpane with operators t

Seite 86 - Viewing agent settings

5 Select the language in which to display the results.Figure 31: Run Query server task actions6 Select an action to take on the results. Available act

Seite 87 - Working with security keys

• Deploy Agents — Deploys agents, according to the configuration on this page, tosystems in the query results. This option is only valid for queries t

Seite 88

Sharing a query between ePO serversUse these tasks to import and export a query for use among multiple servers.TasksExporting queries for use by anoth

Seite 89

4 Select the format of the exported file. If exporting to a PDF file, select the page size andorientation.5 Select whether the files are emailed as at

Seite 90 - Deleting ASSC keys

• Repository Packages — Specifies whether any package can be checked in to any branch.Only agents later then version 3.6 can retrieve packages other t

Seite 91

ePO: Compliance History queryUse this query, with its default settings, to view the percentage of systems (over time) in yourenvironment that are non-

Seite 92 - Backing up all security keys

Comparable report in ePolicy Orchestrator 3.6This query replaces all or part of:• DAT-Definition Deployment Summary• DAT Engine CoverageePO: Distribut

Seite 93 - Agent command-line options

Comparable report in ePolicy Orchestrator 3.6This query replaces all or part of:• DAT-Definition Deployment Summary• DAT Engine CoverageePO: Systems p

Seite 94

Assessing Your Environment With DashboardsDashboards allow you to keep a constant eye on your environment. Dashboards are collectionsof monitors. Moni

Seite 95

• McAfee Links — Hyperlinks to McAfee sites, including ePolicy Orchestrator Support, AvertLabs WebImmune, and Avert Labs Threat Library.Setting up das

Seite 96

Working with DashboardsUse these tasks to create and manage dashboards.TasksCreating dashboardsMaking a dashboard activeSelecting all active dashboard

Seite 97

TaskFor option definitions, click ? on the page displaying them.1 Go to Dashboards, click Options, then select Manage Dashboards. The ManageDashboards

Seite 98

TaskFor option definitions, click ? on the page displaying the options.1 Go to Dashboards, then select Manage Dashboards from the Options drop-down li

Seite 99

Appendix: Maintaining ePolicy OrchestratordatabasesRegardless of whether you use an MSDE or SQL database with ePolicy Orchestrator, yourdatabases requ

Seite 100 - Creating Repositories

Run this utility at least once a week. You can use SQLMAINT.EXE command-prompt utility toperform routine database maintenance activities. It can be us

Seite 101

The Audit LogUse the Audit Log to maintain and access a record of all ePO user actions. The Audit Log entriesdisplay in a sortable table. For added fl

Seite 102

Backing up ePolicy Orchestrator databases regularlyMcAfee recommends that you back up ePolicy Orchestrator databases regularly to protect yourdata and

Seite 103 - Creating source sites

8 Click Backup.9 Click OK when the backup process is done.10 Start the McAfee ePolicy Orchestrator 4.0 Server service and ensure that theMSSQLSERVER s

Seite 104

Restoring a SQL database--see your SQL documentationIf you are using Microsoft SQL Server or SQL 2005 Express as the database, see the SQL Serverprodu

Seite 105

IndexAaccount credentials for agent installation package 72accounts (See user accounts) 16Active Directory containersagent deployment and 73mapping to

Seite 106

branches(continued)Current 143, 147deleting DAT and engine packages 150Evaluation 149manually moving packages between 149Previous 137types of, and rep

Seite 107

enginesdeleting from repository 150repository branches 149Evaluation branchdefined 98using for new DATs and engine 149eventscontacts for notifications

Seite 108

managed systems(continued)roll-up querying 172running an update task manually 85, 86sorting, criteria-based 44tasks for 139viewing agent activity log

Seite 109

policies(continued)importing and exporting 115, 123, 124inheritance 115ownership 116, 118settings, viewing 118sharing between ePO servers 123update se

Seite 110

replication tasks(continued)server task log 137updating master repository 136reportsconfiguring template and location for 27exported data 20exported q

Seite 111

subgroupsand policy management 58criteria-based 46subnets, as grouping criteria 40SuperAgent repositoriesabout 97creating 105deleting 106global updati

Seite 112

COPYRIGHTCopyright © 2007 McAfee, Inc. All Rights Reserved.No part of this publication may be reproduced, transmitted, transcribed, stored in a retrie

Seite 113 - Extensions and what they do

• Engine Version — Version number of the detecting product’s engine (if applicable).• Event Category — Category of the event. Possible categories depe

Seite 114 - Policy management

updating(continued)manually 85, 86master repository with pull tasks 142process description 133Pull Now task to update master repository 143scheduling

Seite 115 - Policy application

MyAVERT Security ThreatsThe MyAvert Security Threats page informs you of the top ten medium-to-high-risk threatsfor corporate users. You no longer nee

Seite 116 - Client tasks and what they do

2 Type the User name and Password of a valid account.NOTE: Passwords are case-sensitive.3 Select the Language you want the software to display.4 Click

Seite 117 - Viewing policy information

4 Select whether to enable or disable the logon status of this account. If this account is forsomeone who is not yet a part of the organization you ma

Seite 118 - Viewing policy ownership

Editing permission setsDeleting permission setsCreating permission sets for user accountsUse this task to create a permission set.Before you beginYou

Seite 119

Editing permission setsUse this task to edit a permission set. Only global administrators can edit permission sets.TaskFor option definitions, click ?

Seite 120

1 Go to Configuration | Contacts, then click New Contact.Figure 2: New Contact page2 Type a first name, last name, and email address for the contact.3

Seite 121 - Sales Europe)

Specifying an email serverUse this task to specify an email server that ePolicy Orchestrator usea to send email messages.TaskFor option definitions, c

Seite 122 - Working with policies

Before you beginYou must be a global administrator to perform this task.TaskFor option definitions, click ? on the page displaying the options.1 Go to

Seite 123 - Exporting a single policy

Filtering the Server Task LogPurging the Server Task LogViewing the Server Task LogUse this task to review the status of server tasks and long-running

Seite 124 - Importing policies

ContentsIntroducing ePolicy Orchestrator 4.0. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12eP

Seite 125

2 Select the desired filter from the Filter drop-down list.Purging the Server Task LogAs the Server Task Log grows, you can purge items older than a u

Seite 126

2 Click any of the column titles to sort the table by that column (alphabetically).3 From the Filter drop-down list, select an option to narrow the am

Seite 127 - Working with client tasks

3 Select Purge Audit Log from the drop-down list.4 Select whether to purge by age or from a queries results. If you purge by query, you mustpick a que

Seite 128 - Deleting client tasks

4 Click OK.Records older than the specified age are deleted permanently.Purging the Event Log on a scheduleUse this task to purge the Event Log with a

Seite 129 - Frequently asked questions

Configuring MyAvert update frequency and proxy settingsUse this task to configure proxy settings adn the update frequency for MyAvert Security Threats

Seite 130

Exporting tables and charts to other formatsUse this task to export data for other purposes. You can export to HTML and PDF finals forviewing formats,

Seite 131

Allowed Special CharactersAllowed ValuesField Name, - * /0 - 23Hours, - * ? / L W C1 - 31Day of Month, - * /1 - 12, or JAN - DECMonth, - * ? / L C #1

Seite 132 - Product and update deployment

Organizing Systems for ManagementePolicy Orchestrator 4.0 provides some new features and improvements to existing features toorganize and manage your

Seite 133 - Update tasks

ContentsThe System TreeConsiderations when planning your System TreeTags and how they workActive Directory and NT domain synchronizationCriteria-based

Seite 134 - Global updating

• When a system is sorted into Lost&Found, it is placed in a subgroup named for the system’sdomain. If no such group exists, one is created.NOTE:

Seite 135 - Pull tasks

Working with contacts. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Seite 136 - Repository selection

These questions impact both the System Tree organization, and the permission sets you createand apply to user accounts.Environmental borders and their

Seite 137 - Checking in packages manually

If possible, consider using sorting criteria based on IP address information to automate SystemTree creation and maintenance. Set IP subnet masks or I

Seite 138

• Apply and remove existing tags to systems in the groups to which they have access.• Exclude systems from receiving specific tags.• Use queries to vi

Seite 139

• Delete systems from the System Tree when they are deleted from Active Directory.• Allow or disallow duplicate entries of systems that already exist

Seite 140

When to use this synchronization typeUse this synchronization type when you use Active Directory as a regular source of systems forePolicy Orchestrato

Seite 141

(even ones with sorting disabled) clicking Move Systems places those systems in the locationidentified.How settings affect sortingYou can choose three

Seite 142

Tag-based sorting criteriaIn addition to using IP address information to sort systems into the appropriate group, you candefine sorting criteria based

Seite 143 - Running a Pull Now task

4 The server applies all criteria-based tags to the system if the server is configured to runsorting criteria at each agent-server communication.5 Wha

Seite 144

Creating tags with the Tag BuilderUse this task to create a tag with the Tag Builder wizard. Tags can use criteria that’s evaluatedagainst every syste

Seite 145 - Running a Replicate Now task

b Next to Systems with tag in the details pane, click the link for the number of systemsexcluded from automatic tagging. The Systems Excluded from the

Seite 146

Active Directory synchronization. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42NT domai

Seite 147

Go to Systems | Tag Catalog, then select the desired tag in the list of tags.ab Next to Systems with tag in the details pane, click the link for the n

Seite 148

does not make sense for security management, you can create your System Tree in a text fileand import it into your System Tree. If you have a smaller

Seite 149

TaskFor option definitions, click ? on the page displaying the options.1 Go to Systems | System Tree | Group, then select the desired group in the Sys

Seite 150

Select the agent version to deploy.ab Select whether to suppress the agent installation user interface on the system. Selectthis if you do not want th

Seite 151 - Sending Notifications

TaskFor option definitions, click ? on the page displaying the options.1 Go to Systems | System Tree, then click New Systems. The New Systems pageappe

Seite 152 - Throttling and aggregation

Enabling System Tree sorting on the serverUse this task to enable System Tree sorting on the server. System Tree sorting must be enabledon the server

Seite 153

TaskFor option definitions, click ? on the page displaying the options.1 Go to Systems | System Tree | Systems, then select the group that contains th

Seite 154 - Planning

1 Go to Systems | System Tree | Group, then select the desired group in the SystemTree. This should be the group to which you want to map an Active Di

Seite 155

10 Select whether to deploy agents automatically to new systems. If you do, be sure toconfigure the deployment settings.TIP: McAfee recommends that yo

Seite 156 - Setting up ePO Notifications

TaskFor option definitions, click ? on the page displaying the options.1 Go to Systems | System Tree | Group, then select or create a group in the Sys

Seite 157 - Working with SNMP servers

Deploying the agent with ePolicy Orchestrator. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73Installing the ag

Seite 158 - Importing .MIB files

8 To synchronize the group with the domain immediately, click Synchronize Now, thenwait while the systems in the domain are added to the group.NOTE: C

Seite 159 - Adding registered executables

2 Name the task and choose whether it is enabled once it is created, then click Next. TheActions page appears.3 From the drop-down list, select NT Dom

Seite 160

2 Click Move Systems. The Select New Group page appears.NOTE: You may need to click More Actions to access this action.3 Select whether to enable or d

Seite 161 - Deleting external commands

Distributing Agents to Manage SystemsManaging your network systems effectively is dependent on each system running an active,up-to-date agent.There ar

Seite 162 - Describing the rule

Agents and SuperAgentsThe agent is the distributed component of ePolicy Orchestrator that must be installed on eachsystem in your network that you wan

Seite 163 - Setting filters for the rule

The agent installation packageThe FRAMEPKG.EXE file is created when you install the server. It is a customized installationpackage for agents that rep

Seite 164

Recommended ASCINetwork Size150 minutesWireless LANNOTE: For complete information on balancing bandwidth, server hardware, and ASCIdetermination, see

Seite 165

networks where ePolicy Orchestrator may manage agents in remote sites over lower-speedWAN or VPN connections.Figure 15: SuperAgent and Broadcast Wake-

Seite 166 - Purging the Notifications Log

Agent activity logsThe agent log files are useful for determining agent status or troubleshooting. Two log filesrecord agent activity, both are locate

Seite 167 - Product and component list

use Notifications, enabling immediate uploading of higher severity events is necessary for thosefeatures to function as intended.You can enable immedi

Seite 168

Creating source sites. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 103Ed

Seite 169 - Querying the Database

Agent policy and distributed repositoriesBy default, the agent can update from any repository in its repository list (SITELIST.XML) file.The agent can

Seite 170 - Query permissions

Master repository key pairThe master repository private key signs all unsigned content in the master repository. Thesekeys are in anticipation of the

Seite 171 - Query Builder

DisadvantagesAdvantagesMethodIf you do not use images consistently, thismethod would not be efficient to ensurecoverage.Prevents the bandwidth impact

Seite 172 - Multi-server roll-up querying

Including the agent on an imageUsing other deployment productsDistributing the agent to WebShield appliances and Novell NetWare serversDeploying the a

Seite 173 - Registering ePO servers

• Ensure network access is enabled on Windows XP Home systems. Deploy the agent fromePolicy Orchestrator or install a custom agent installation packag

Seite 174 - Working with queries

Installing the agent with login scriptsUse this task to set up and use network login scripts to install the agent on systems logging onto the network.

Seite 175 - Running a query on a schedule

Below is a sample batch file that checks whether the agent is installed and, if it is not, runsthe FRAMEPKG.EXE to install the agent.IF EXIST “C:\Wind

Seite 176

Enabling the agent on unmanaged McAfee productsUse this task to enable agents on existing McAfee products in your environment.Before purchasing ePolic

Seite 177 - Duplicating queries

For instructions, see the documentation for your preferred image-creation product.Using other deployment productsYou may already use other network dep

Seite 178 - Importing queries

If you have been using an older version of ePolicy Orchestrator and have previous agent versionsin your environment, you can upgrade those agents once

Seite 179

Editing a policy’s settings from the Policy Catalog. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121Renaming a policy

Seite 180

5 Select the agent version from the drop-down list.6 Select Install from the Action drop-down list.7 Add any command-line options.8 Select whether to

Seite 181

Removing agents when deleting groups from the System TreeUse this task to remove agents from all systems in a group, which you are deleting from theSy

Seite 182

Sending manual wake-up calls to systemsUse this task to manually send an agent or SuperAgent wake-up call to systems in the SystemTree. This is useful

Seite 183 - Dashboards and how they work

Before you beginBefore sending the agent wake-up call to such a group, make sure that wake-up support forthe group is enabled and applied on the Gener

Seite 184

Viewing the agent activity logUse these tasks to view the agent activity log. The agent activity log records an agent’s activity.The amount of detail

Seite 185 - Working with Dashboards

TaskFor option definitions, click ? on the page displaying the options.1 Go to Systems | System Tree | Systems, then select the system.2 Click the sys

Seite 186 - Making a dashboard public

Task1 Right-click the McAfee tray icon at the managed system, then select McAfee Agent |Status Monitor. The Agent Status Monitor appears.2 Click Colle

Seite 187

Viewing agent and product version numbersUse this procedure to look up the agent and product version numbers from the managed system.This is useful fo

Seite 188

1 Export the desired ASSC keys from the desired ePO server.2 Import the ASSC keys to all other servers.3 Make the imported key the master on all serve

Seite 189 - -UpdOptiStats 15

1 Go to Configuration | Server Settings, then select Security Keys in the SettingCategories list.2 In the details pane, click Edit.3 In the Agent-serv

Seite 190 - Backing up an MSDE database

Checking in engine, DAT and EXTRA.DAT update packages manually. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147Updating managed systems

Seite 191

4 Back up all keys.Deleting ASSC keysUse this task to delete unused ASSC keys in the Agent-server secure communication keyslist.CAUTION: Do not delete

Seite 192 - C:\PROGRAM FILES\MCAFEE\EPO

2 Next to Local master repository key pair, click Export Key Pair. The Export MasterRepository Key Pair dialog box appears.3 Click OK. The File Downlo

Seite 193 - (continued)

Backing up and restoring security keysUse these tasks to back up and restore the security keys. McAfee recommends periodicallybacking up all of the se

Seite 194

Agent command-line optionsUse the Command Agent (CMDAGENT.EXE) tool to perform selected agent tasks from themanaged system. CMDAGENT.EXE is installed

Seite 195

DescriptionCommandSample: FRAMEPKG /INSTALL=AGENT /FORCEINSTALL/INSTDIR=c:newagentdirectoryInstalls and enables the agent.Sample: FRAMEPKG /INSTALL=AG

Seite 196

Creating RepositoriesSecurity software is only as effective as the latest installed updates. For example, if your DATfiles are out-of-date, even the b

Seite 197

The master repository is configured when installed. However, you must ensure that proxy serversettings are configured correctly. By default, ePolicy O

Seite 198

If managed systems use a proxy server to access the Internet, you must configure agent policysettings for those systems to use proxy servers when acce

Seite 199

Once the distributed repository is created, use ePolicy Orchestrator to configure managedsystems of a specific System Tree group to update from it.TIP

Seite 200

If needed, you can export the repository list to external files (SITELIST.XML or SITEMGR.XML).Use an exported SITELIST.XML file to:• Import to an agen

Kommentare zu diesen Handbüchern

Keine Kommentare