Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0 Guia de Instalação

Consulte online ou descarregue Guia de Instalação para Software utilitário de uso geral Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0. Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0 Installation guide Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir

Resumo do Conteúdo

Página 1 - Installation Guide

McAfee Host Intrusion Prevention 8.0Installation Guide

Página 2

Extension/client functionality• Two versions of Host Intrusion Prevention 8.0: a firewall-only version and a full versioncontaining both firewall and

Página 3 - Contents

Best Practices for Quick SuccessMcAfee Host Intrusion Prevention delivers great value to your organization by reducing patchingfrequency and urgency,

Página 4

5 Optional adaptive mode6 Enhanced protection and advanced tuning7 Maintenance and expansion beyond IPSBoth desktops and servers follow a similar roll

Página 5

1. Strategize2. Prepare a pilot environment3. Install and configure4. Do initial tuning5. Activate adaptive mode (optional)6. Refine tuning7. Perform

Página 6 - Components

• Servers running dedicated database, web, email, or other applications, as well as print andfile servers.Lab or real world?Many enterprises require l

Página 7 - Installation overview

“Patch Tuesday” issues were shielded using the out-of-the-box basic protection level. Activatingeven default protection offers significant immediate v

Página 8

Choose your optionOption 1 helps you gain the most protection benefit from your IPS investment. Option 2 presentsa reliable, lightweight strategy. Pic

Página 9

Process overview:Figure 2: Host Intrusion Prevention installation and maintenance using ePolicy Orchestrator• The ePO server works with McAfee Agent o

Página 10

Group the clients logically. Clients can be grouped according to any criteria that fit in the ePOSystem Tree hierarchy. For example, you might group a

Página 11

Refine baseline policies (optional)Some administrators tweak protection defaults immediately, before starting the deployment.You can automatically pro

Página 12 - Product Guide

COPYRIGHTCopyright © 2010 McAfee, Inc. All Rights Reserved.No part of this publication may be reproduced, transmitted, transcribed, stored in a retrie

Página 13 - 1. Strategize

1 Check that the Host IPS services (FireSvc.exe, mfefire.exe, mfevtp.exe) and frameworkservice (McAfeeFramework.exe) are started.2 Very Important! Run

Página 14

legitimate activities, most common with internally-developed applications, these false positivescan be resolved in the next step.TIP: Often when scann

Página 15

legitimate applications, and you do not need to permit these behaviors. Validate that theuser application functions correctly and continue blocking.TI

Página 16

5. Activate adaptive mode (optional)After completing a business cycle with the software in place, begin to implement well-targetedrules to create cust

Página 17

• Track client rules in the ePO console, viewing them in regular, filtered, and aggregatedviews.• Use automatically created client rules to define new

Página 18 - 3. Install and configure

Continue tuningReview exceptions and any issues that emerge. Manage these as discussed in the initial tuningstep.• Monitor help desk calls and user co

Página 19 - Define client functionality

computers fit into a few usage profiles. Managing a large deployment is reduced tomaintaining a few policy rules.• Repeat the process for power users

Página 20 - 4. Do initial tuning

Installing in ePolicy OrchestratorThis version of Host Intrusion Prevention requires that you install one or more extensions inePolicy Orchestrator de

Página 21

FunctionalityRequired extensionsFile nameMcAfee ePOversionePO Help with Host IntrusionPrevention 8.0 informationHelp Content: hip_800_help* Valid only

Página 22

In ePolicy Orchestrator 4.0, Host Intrusion Prevention 8.0.0 and Host IPS LicenseExtension, if installed, appear in the Managed Products list under ex

Página 23

ContentsInstalling McAfee Host Intrusion Prevention. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Components.

Página 24 - 6. Refine tuning

Migrating PoliciesYou cannot use McAfee Host Intrusion Prevention version 6.1 or 7.0 policies with version 8.0clients without first migrating version

Página 25

To version 8.0, do this...To migrate this version of Host IntrusionPrevention...• Migrate 6.1 policies to 8.0 policies by running the HostIPS 8.0 migr

Página 26

Migrating policies through an xml fileIf the McAfee Host Intrusion Prevention 6.1 or 7.0 extension is not installed and you havepreviously exported se

Página 27

Installing the Windows ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Windows clie

Página 28 - Installing the extension

• Enterprise Edition• Ultimate EditionWindows Server 2003 SP2, 2003 R2, 2003 R2 SP2 (32- & 64-bit)• All editionsWindows Server 2008, 2008 SP1, 200

Página 29 - Removing the extension

MED-V 1.0, 1.0 SP1•• App-V 4.5, 4.6• SCVMM 2008, 2008 R2• SCCM 2007SP2, 2007 R2• SCOM 2007, 2007 R2• Microsoft App-V 4.5, 4.6• XP Mode Windows 7 32- a

Página 30 - Migrating Policies

Before you beginIf a previous version of the client exists, be sure to disable IPS protection before attempting toinstall.Task1 Copy the client instal

Página 31

Task1 From the ePO server, select the system from which you want to remove the software.2 Enforce the Host Intrusion Prevention Client UI policy optio

Página 32

3 Set debugging: Select Help | Troubleshooting and enable full debug logging for firewalland IPS).4 Ensure that both Host IPS and Network IPS are disa

Página 33

Installing the Solaris ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Solaris clie

Página 34 - Windows client details

Installing the Solaris client locally. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 35

Policy enforcementNot all Host Intrusion Prevention 8.0 policies are available for the Solaris client. In brief, HostIntrusion Prevention protects the

Página 36 - Removing the Windows client

For more information on editing signatures, seeAppendix A — Writing Custom Signaturesinthe product guide or help.Installing the Solaris client remotel

Página 37 - Product:

You are now ready to monitor and deploy IPS policies for the Solaris client. For details, see theMcAfee Host Intrusion Prevention 8.0 Product Guide.To

Página 38 - Restarting the Windows client

Verify the Solaris client is runningThe client might be installed correctly, but you might encounter problems with its operation. Ifthe client does no

Página 39 - Installing the Solaris Client

Installing the Linux ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Linux client,

Página 40

• Red Hat Linux Enterprise 5, 64-bit• 2.6.18-8.el5• SUSE Linux Enterprise 10, 32-bit• 2.6.16.21-0.8-bigsmp• 2.6.16.21-0.8-default• 2.6.16.21-0.8-smp•

Página 41

Available optionsPolicy• Signatures (default and custom HIPS rules only)NOTE: NIPS signatures and Application Protection Rules are notavailable.AllIPS

Página 42

Task1 Copy the appropriate .rpm file from the client installation package to the Linux system:• Red Hat Linux Enterprise 4, 32-bit1 MFEhiplsm-kernel-8

Página 43 - Restarting the Solaris client

You are now ready to monitor and deploy IPS policies for the Linux client. For details, see theHost Intrusion Prevention 8.0 Product Guide.To be sure

Página 44 - Installing the Linux Client

Verify the Linux client is runningThe client might be installed correctly, but you might encounter problems with its operation. Ifthe client does not

Página 45

Installing McAfee Host Intrusion PreventionThis guide provides all the information you need to install and start using Host IntrusionPrevention 8.0 so

Página 46

collect event information, and transmit the information back to ePolicy Orchestrator throughthe McAfee Agent.Figure 1: Host Intrusion Prevention prote

Página 47

• McAfee Agent — Agent installed on a managed system that acts as the intermediary betweenthe Host Intrusion Prevention client and the ePolicy Orchest

Página 48

On client systemsOn the ePolicy Orchestrator serverLinuxSolarisWindowsHost IPS 8.0 extensionsVersion––Firewall only for ePO 4.54.5• McAfee Agent 4.0(P

Página 49 - Restarting the Linux client

TrustedSource rating and blocking: Firewall rules block or allow incoming or outgoingtraffic according to McAfee TrustedSource ratings•• IP spoof prot

Comentários a estes Manuais

Sem comentários