Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0 Installationsanleitung

Stöbern Sie online oder laden Sie Installationsanleitung nach Allgemeine Dienstprogramm-Software Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0 herunter. Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0 Installation guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken

Inhaltsverzeichnis

Seite 1 - Installation Guide

McAfee Host Intrusion Prevention 8.0Installation Guide

Seite 2

Extension/client functionality• Two versions of Host Intrusion Prevention 8.0: a firewall-only version and a full versioncontaining both firewall and

Seite 3 - Contents

Best Practices for Quick SuccessMcAfee Host Intrusion Prevention delivers great value to your organization by reducing patchingfrequency and urgency,

Seite 4

5 Optional adaptive mode6 Enhanced protection and advanced tuning7 Maintenance and expansion beyond IPSBoth desktops and servers follow a similar roll

Seite 5

1. Strategize2. Prepare a pilot environment3. Install and configure4. Do initial tuning5. Activate adaptive mode (optional)6. Refine tuning7. Perform

Seite 6 - Components

• Servers running dedicated database, web, email, or other applications, as well as print andfile servers.Lab or real world?Many enterprises require l

Seite 7 - Installation overview

“Patch Tuesday” issues were shielded using the out-of-the-box basic protection level. Activatingeven default protection offers significant immediate v

Seite 8

Choose your optionOption 1 helps you gain the most protection benefit from your IPS investment. Option 2 presentsa reliable, lightweight strategy. Pic

Seite 9

Process overview:Figure 2: Host Intrusion Prevention installation and maintenance using ePolicy Orchestrator• The ePO server works with McAfee Agent o

Seite 10

Group the clients logically. Clients can be grouped according to any criteria that fit in the ePOSystem Tree hierarchy. For example, you might group a

Seite 11

Refine baseline policies (optional)Some administrators tweak protection defaults immediately, before starting the deployment.You can automatically pro

Seite 12 - Product Guide

COPYRIGHTCopyright © 2010 McAfee, Inc. All Rights Reserved.No part of this publication may be reproduced, transmitted, transcribed, stored in a retrie

Seite 13 - 1. Strategize

1 Check that the Host IPS services (FireSvc.exe, mfefire.exe, mfevtp.exe) and frameworkservice (McAfeeFramework.exe) are started.2 Very Important! Run

Seite 14

legitimate activities, most common with internally-developed applications, these false positivescan be resolved in the next step.TIP: Often when scann

Seite 15

legitimate applications, and you do not need to permit these behaviors. Validate that theuser application functions correctly and continue blocking.TI

Seite 16

5. Activate adaptive mode (optional)After completing a business cycle with the software in place, begin to implement well-targetedrules to create cust

Seite 17

• Track client rules in the ePO console, viewing them in regular, filtered, and aggregatedviews.• Use automatically created client rules to define new

Seite 18 - 3. Install and configure

Continue tuningReview exceptions and any issues that emerge. Manage these as discussed in the initial tuningstep.• Monitor help desk calls and user co

Seite 19 - Define client functionality

computers fit into a few usage profiles. Managing a large deployment is reduced tomaintaining a few policy rules.• Repeat the process for power users

Seite 20 - 4. Do initial tuning

Installing in ePolicy OrchestratorThis version of Host Intrusion Prevention requires that you install one or more extensions inePolicy Orchestrator de

Seite 21

FunctionalityRequired extensionsFile nameMcAfee ePOversionePO Help with Host IntrusionPrevention 8.0 informationHelp Content: hip_800_help* Valid only

Seite 22

In ePolicy Orchestrator 4.0, Host Intrusion Prevention 8.0.0 and Host IPS LicenseExtension, if installed, appear in the Managed Products list under ex

Seite 23

ContentsInstalling McAfee Host Intrusion Prevention. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Components.

Seite 24 - 6. Refine tuning

Migrating PoliciesYou cannot use McAfee Host Intrusion Prevention version 6.1 or 7.0 policies with version 8.0clients without first migrating version

Seite 25

To version 8.0, do this...To migrate this version of Host IntrusionPrevention...• Migrate 6.1 policies to 8.0 policies by running the HostIPS 8.0 migr

Seite 26

Migrating policies through an xml fileIf the McAfee Host Intrusion Prevention 6.1 or 7.0 extension is not installed and you havepreviously exported se

Seite 27

Installing the Windows ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Windows clie

Seite 28 - Installing the extension

• Enterprise Edition• Ultimate EditionWindows Server 2003 SP2, 2003 R2, 2003 R2 SP2 (32- & 64-bit)• All editionsWindows Server 2008, 2008 SP1, 200

Seite 29 - Removing the extension

MED-V 1.0, 1.0 SP1•• App-V 4.5, 4.6• SCVMM 2008, 2008 R2• SCCM 2007SP2, 2007 R2• SCOM 2007, 2007 R2• Microsoft App-V 4.5, 4.6• XP Mode Windows 7 32- a

Seite 30 - Migrating Policies

Before you beginIf a previous version of the client exists, be sure to disable IPS protection before attempting toinstall.Task1 Copy the client instal

Seite 31

Task1 From the ePO server, select the system from which you want to remove the software.2 Enforce the Host Intrusion Prevention Client UI policy optio

Seite 32

3 Set debugging: Select Help | Troubleshooting and enable full debug logging for firewalland IPS).4 Ensure that both Host IPS and Network IPS are disa

Seite 33

Installing the Solaris ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Solaris clie

Seite 34 - Windows client details

Installing the Solaris client locally. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Seite 35

Policy enforcementNot all Host Intrusion Prevention 8.0 policies are available for the Solaris client. In brief, HostIntrusion Prevention protects the

Seite 36 - Removing the Windows client

For more information on editing signatures, seeAppendix A — Writing Custom Signaturesinthe product guide or help.Installing the Solaris client remotel

Seite 37 - Product:

You are now ready to monitor and deploy IPS policies for the Solaris client. For details, see theMcAfee Host Intrusion Prevention 8.0 Product Guide.To

Seite 38 - Restarting the Windows client

Verify the Solaris client is runningThe client might be installed correctly, but you might encounter problems with its operation. Ifthe client does no

Seite 39 - Installing the Solaris Client

Installing the Linux ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Linux client,

Seite 40

• Red Hat Linux Enterprise 5, 64-bit• 2.6.18-8.el5• SUSE Linux Enterprise 10, 32-bit• 2.6.16.21-0.8-bigsmp• 2.6.16.21-0.8-default• 2.6.16.21-0.8-smp•

Seite 41

Available optionsPolicy• Signatures (default and custom HIPS rules only)NOTE: NIPS signatures and Application Protection Rules are notavailable.AllIPS

Seite 42

Task1 Copy the appropriate .rpm file from the client installation package to the Linux system:• Red Hat Linux Enterprise 4, 32-bit1 MFEhiplsm-kernel-8

Seite 43 - Restarting the Solaris client

You are now ready to monitor and deploy IPS policies for the Linux client. For details, see theHost Intrusion Prevention 8.0 Product Guide.To be sure

Seite 44 - Installing the Linux Client

Verify the Linux client is runningThe client might be installed correctly, but you might encounter problems with its operation. Ifthe client does not

Seite 45

Installing McAfee Host Intrusion PreventionThis guide provides all the information you need to install and start using Host IntrusionPrevention 8.0 so

Seite 46

collect event information, and transmit the information back to ePolicy Orchestrator throughthe McAfee Agent.Figure 1: Host Intrusion Prevention prote

Seite 47

• McAfee Agent — Agent installed on a managed system that acts as the intermediary betweenthe Host Intrusion Prevention client and the ePolicy Orchest

Seite 48

On client systemsOn the ePolicy Orchestrator serverLinuxSolarisWindowsHost IPS 8.0 extensionsVersion––Firewall only for ePO 4.54.5• McAfee Agent 4.0(P

Seite 49 - Restarting the Linux client

TrustedSource rating and blocking: Firewall rules block or allow incoming or outgoingtraffic according to McAfee TrustedSource ratings•• IP spoof prot

Kommentare zu diesen Handbüchern

Keine Kommentare