Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0 Przewodnik Instalacji

Przeglądaj online lub pobierz Przewodnik Instalacji dla Ogólne oprogramowanie narzędziowe Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0. Red Hat SYSTEM 8.0 - MIGRATION GUIDE 7.X TO 8.0 Installation guide Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj

Podsumowanie treści

Strona 1 - Installation Guide

McAfee Host Intrusion Prevention 8.0Installation Guide

Strona 2

Extension/client functionality• Two versions of Host Intrusion Prevention 8.0: a firewall-only version and a full versioncontaining both firewall and

Strona 3 - Contents

Best Practices for Quick SuccessMcAfee Host Intrusion Prevention delivers great value to your organization by reducing patchingfrequency and urgency,

Strona 4

5 Optional adaptive mode6 Enhanced protection and advanced tuning7 Maintenance and expansion beyond IPSBoth desktops and servers follow a similar roll

Strona 5

1. Strategize2. Prepare a pilot environment3. Install and configure4. Do initial tuning5. Activate adaptive mode (optional)6. Refine tuning7. Perform

Strona 6 - Components

• Servers running dedicated database, web, email, or other applications, as well as print andfile servers.Lab or real world?Many enterprises require l

Strona 7 - Installation overview

“Patch Tuesday” issues were shielded using the out-of-the-box basic protection level. Activatingeven default protection offers significant immediate v

Strona 8

Choose your optionOption 1 helps you gain the most protection benefit from your IPS investment. Option 2 presentsa reliable, lightweight strategy. Pic

Strona 9

Process overview:Figure 2: Host Intrusion Prevention installation and maintenance using ePolicy Orchestrator• The ePO server works with McAfee Agent o

Strona 10

Group the clients logically. Clients can be grouped according to any criteria that fit in the ePOSystem Tree hierarchy. For example, you might group a

Strona 11

Refine baseline policies (optional)Some administrators tweak protection defaults immediately, before starting the deployment.You can automatically pro

Strona 12 - Product Guide

COPYRIGHTCopyright © 2010 McAfee, Inc. All Rights Reserved.No part of this publication may be reproduced, transmitted, transcribed, stored in a retrie

Strona 13 - 1. Strategize

1 Check that the Host IPS services (FireSvc.exe, mfefire.exe, mfevtp.exe) and frameworkservice (McAfeeFramework.exe) are started.2 Very Important! Run

Strona 14

legitimate activities, most common with internally-developed applications, these false positivescan be resolved in the next step.TIP: Often when scann

Strona 15

legitimate applications, and you do not need to permit these behaviors. Validate that theuser application functions correctly and continue blocking.TI

Strona 16

5. Activate adaptive mode (optional)After completing a business cycle with the software in place, begin to implement well-targetedrules to create cust

Strona 17

• Track client rules in the ePO console, viewing them in regular, filtered, and aggregatedviews.• Use automatically created client rules to define new

Strona 18 - 3. Install and configure

Continue tuningReview exceptions and any issues that emerge. Manage these as discussed in the initial tuningstep.• Monitor help desk calls and user co

Strona 19 - Define client functionality

computers fit into a few usage profiles. Managing a large deployment is reduced tomaintaining a few policy rules.• Repeat the process for power users

Strona 20 - 4. Do initial tuning

Installing in ePolicy OrchestratorThis version of Host Intrusion Prevention requires that you install one or more extensions inePolicy Orchestrator de

Strona 21

FunctionalityRequired extensionsFile nameMcAfee ePOversionePO Help with Host IntrusionPrevention 8.0 informationHelp Content: hip_800_help* Valid only

Strona 22

In ePolicy Orchestrator 4.0, Host Intrusion Prevention 8.0.0 and Host IPS LicenseExtension, if installed, appear in the Managed Products list under ex

Strona 23

ContentsInstalling McAfee Host Intrusion Prevention. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5Components.

Strona 24 - 6. Refine tuning

Migrating PoliciesYou cannot use McAfee Host Intrusion Prevention version 6.1 or 7.0 policies with version 8.0clients without first migrating version

Strona 25

To version 8.0, do this...To migrate this version of Host IntrusionPrevention...• Migrate 6.1 policies to 8.0 policies by running the HostIPS 8.0 migr

Strona 26

Migrating policies through an xml fileIf the McAfee Host Intrusion Prevention 6.1 or 7.0 extension is not installed and you havepreviously exported se

Strona 27

Installing the Windows ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Windows clie

Strona 28 - Installing the extension

• Enterprise Edition• Ultimate EditionWindows Server 2003 SP2, 2003 R2, 2003 R2 SP2 (32- & 64-bit)• All editionsWindows Server 2008, 2008 SP1, 200

Strona 29 - Removing the extension

MED-V 1.0, 1.0 SP1•• App-V 4.5, 4.6• SCVMM 2008, 2008 R2• SCCM 2007SP2, 2007 R2• SCOM 2007, 2007 R2• Microsoft App-V 4.5, 4.6• XP Mode Windows 7 32- a

Strona 30 - Migrating Policies

Before you beginIf a previous version of the client exists, be sure to disable IPS protection before attempting toinstall.Task1 Copy the client instal

Strona 31

Task1 From the ePO server, select the system from which you want to remove the software.2 Enforce the Host Intrusion Prevention Client UI policy optio

Strona 32

3 Set debugging: Select Help | Troubleshooting and enable full debug logging for firewalland IPS).4 Ensure that both Host IPS and Network IPS are disa

Strona 33

Installing the Solaris ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Solaris clie

Strona 34 - Windows client details

Installing the Solaris client locally. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 35

Policy enforcementNot all Host Intrusion Prevention 8.0 policies are available for the Solaris client. In brief, HostIntrusion Prevention protects the

Strona 36 - Removing the Windows client

For more information on editing signatures, seeAppendix A — Writing Custom Signaturesinthe product guide or help.Installing the Solaris client remotel

Strona 37 - Product:

You are now ready to monitor and deploy IPS policies for the Solaris client. For details, see theMcAfee Host Intrusion Prevention 8.0 Product Guide.To

Strona 38 - Restarting the Windows client

Verify the Solaris client is runningThe client might be installed correctly, but you might encounter problems with its operation. Ifthe client does no

Strona 39 - Installing the Solaris Client

Installing the Linux ClientThis section describes the requirements, properties, and installation of McAfee Host IntrusionPrevention 8.0 Linux client,

Strona 40

• Red Hat Linux Enterprise 5, 64-bit• 2.6.18-8.el5• SUSE Linux Enterprise 10, 32-bit• 2.6.16.21-0.8-bigsmp• 2.6.16.21-0.8-default• 2.6.16.21-0.8-smp•

Strona 41

Available optionsPolicy• Signatures (default and custom HIPS rules only)NOTE: NIPS signatures and Application Protection Rules are notavailable.AllIPS

Strona 42

Task1 Copy the appropriate .rpm file from the client installation package to the Linux system:• Red Hat Linux Enterprise 4, 32-bit1 MFEhiplsm-kernel-8

Strona 43 - Restarting the Solaris client

You are now ready to monitor and deploy IPS policies for the Linux client. For details, see theHost Intrusion Prevention 8.0 Product Guide.To be sure

Strona 44 - Installing the Linux Client

Verify the Linux client is runningThe client might be installed correctly, but you might encounter problems with its operation. Ifthe client does not

Strona 45

Installing McAfee Host Intrusion PreventionThis guide provides all the information you need to install and start using Host IntrusionPrevention 8.0 so

Strona 46

collect event information, and transmit the information back to ePolicy Orchestrator throughthe McAfee Agent.Figure 1: Host Intrusion Prevention prote

Strona 47

• McAfee Agent — Agent installed on a managed system that acts as the intermediary betweenthe Host Intrusion Prevention client and the ePolicy Orchest

Strona 48

On client systemsOn the ePolicy Orchestrator serverLinuxSolarisWindowsHost IPS 8.0 extensionsVersion––Firewall only for ePO 4.54.5• McAfee Agent 4.0(P

Strona 49 - Restarting the Linux client

TrustedSource rating and blocking: Firewall rules block or allow incoming or outgoingtraffic according to McAfee TrustedSource ratings•• IP spoof prot

Komentarze do niniejszej Instrukcji

Brak uwag