Product Guide Revision 1.0
ProtectionPilot
™
Maximum Protection. Simple Administration. version 1.0
COPYRIGHT Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved. No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or by any means without the written permission of Networks Associates Technology, Inc., or its suppliers or affiliate companies. To obtain this permission, write to the attention of the Network Associates legal department at: 5000 Headquarters Drive, Plano, Texas 75024, or call +1-972-963-8000. TRADEMARK ATTRIBUTIONS Active Firewall, Active Security, Active Security (in Katakana), ActiveHelp, ActiveShield, AntiVirus Anyware and design, Appera, AVERT, Bomb Shelter, Certified Network Expert, Clean-Up, CleanUp Wizard, ClickNet, CNX, CNX Certification Certified Network Expert and design, Covert, Design (stylized N), Disk Minder, Distributed Sniffer System, Distributed Sniffer System (in Katakana), Dr Solomon’s, Dr Solomon’s label, E and Design, Entercept, Enterprise SecureCast, Enterprise SecureCast (in Katakana), ePolicy Orchestrator, Event Orchestrator (in Katakana), EZ SetUp, First Aid, ForceField, GMT, GroupShield, GroupShield (in Katakana), Guard Dog, HelpDesk, HelpDesk IQ, HomeGuard, Hunter, Impermia, InfiniStream, Intrusion Prevention Through Innovation, IntruShield, IntruVert Networks, LANGuru, LANGuru (in Katakana), M and design, Magic Solutions, Magic Solutions (in Katakana), Magic University, MagicSpy, MagicTree, McAfee, McAfee (in Katakana), McAfee and design, McAfee.com, MultiMedia Cloaking, NA Network Associates, Net Tools, Net Tools (in Katakana), NetAsyst, NetCrypto, NetOctopus, NetScan, NetShield, NetStalker, Network Associates, Network Performance Orchestrator, NetXray, NotesGuard, nPO, Nuts & Bolts, Oil Change, PC Medic, PCNotary, PortalShield, Powered by SpamAssassin, PrimeSupport, Recoverkey, Recoverkey – International, Registry Wizard, Remote Desktop, ReportMagic, RingFence, Router PM, Safe & Sound, SalesMagic, SecureCast, SecureSelect, SecurityShield, Service Level Manager, ServiceMagic, SmartDesk, Sniffer, Sniffer (in Hangul), SpamKiller, SpamAssassin, Stalker, SupportMagic, ThreatScan, TIS, TMEG, Total Network Security, Total Network Visibility, Total Network Visibility (in Katakana), Total Service Desk, Total Virus Defense, Trusted Mail, UnInstaller, VIDS, Virex, Virus Forum, ViruScan, VirusScan, WebScan, WebShield, WebShield (in Katakana), WebSniffer, WebStalker, WebWall, What's The State Of Your IDS?, Who’s Watching Your Network, WinGauge, Your E-Business Defender, ZAC 2000, Zip Manager are registered trademarks or trademarks of Network Associates, Inc. and/or its affiliates in the US and/or other countries. Sniffer® brand products are made only by Network Associates, Inc. All other registered and unregistered trademarks herein are the sole property of their respective owners. LICENSE INFORMATION License Agreement NOTICE TO ALL USERS: CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE LICENSE YOU PURCHASED, WHICH SETS FORTH THE GENERAL TERMS AND CONDITIONS FOR THE USE OF THE LICENSED SOFTWARE. IF YOU DO NOT KNOW WHICH TYPE OF LICENSE YOU HAVE ACQUIRED, PLEASE CONSULT THE SALES AND OTHER RELATED LICENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANIES YOUR SOFTWARE PACKAGING OR THAT YOU HAVE RECEIVED SEPARATELY AS PART OF THE PURCHASE (AS A BOOKLET, A FILE ON THE PRODUCT CD, OR A FILE AVAILABLE ON THE WEB SITE FROM WHICH YOU DOWNLOADED THE SOFTWARE PACKAGE). IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT, DO NOT INSTALL THE SOFTWARE. IF APPLICABLE, YOU MAY RETURN THE PRODUCT TO NETWORK ASSOCIATES OR THE PLACE OF PURCHASE FOR A FULL REFUND.
Attributions This product includes or may include: ! Software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/). ! Cryptographic software written by Eric A. Young and software written by Tim J. Hudson. ! Some software programs that are licensed (or sublicensed) to the user under the GNU General Public License (GPL) or other similar Free Software licenses which, among other rights, permit the user to copy, modify and redistribute certain programs, or portions thereof, and have access to the source code. The GPL requires that for any software covered under the GPL which is distributed to someone in an executable binary format, that the source code also be made available to those users. For any such software covered under the GPL, the source code is made available on this CD. If any Free Software licenses require that Network Associates provide rights to use, copy or modify a software program that are broader than the rights granted in this agreement, then such rights shall take precedence over the rights and restrictions herein. ! Software originally written by Henry Spencer, Copyright 1992, 1993, 1994, 1997 Henry Spencer. ! Software originally written by Robert Nordier, Copyright © 1996-7 Robert Nordier. All rights reserved. ! Software written by Douglas W. Sauder. ! Software developed by the Apache Software Foundation (http://www.apache.org/). ! International Components for Unicode (“ICU”) Copyright © 1995-2002 International Business Machines Corporation and others. All rights reserved. ! Software developed by CrystalClear Software, Inc., Copyright © 2000 CrystalClear Software, Inc. ! FEAD ® Optimizer® technology, Copyright Netopsystems AG, Berlin, Germany. ! Outside In® Viewer Technology © 1992-2001 Stellent Chicago, Inc. and/or Outside In® HTML Export, © 2001 Stellent Chicago, Inc. ! Software copyrighted by Thai Open Source Software Center Ltd. and Clark Cooper, © 1998, 1999, 2000. ! Software copyrighted by Expat maintainers. ! Software copyrighted by The Regents of the University of California, © 1989. ! Software copyrighted by Gunnar Ritter. ! Software copyrighted by Sun Microsystems ®, Inc. ! Software copyrighted by Gisle Aas. All rights reserved, © 1995-2003. ! Software copyrighted by Michael A. Chase, © 1999-2000. ! Software copyrighted by Neil Winton, © 1995-1996. ! Software copyrighted by RSA Data Security, Inc., © 1990-1992. ! Software copyrighted by Sean M. Burke, © 1999, 2000. ! Software copyrighted by Martijn Koster, © 1995. ! Software copyrighted by Brad Appleton, © 1996-1999. ! Software copyrighted by Michael G. Schwern, © 2001. ! Software copyrighted by Graham Barr, © 1998. ! Software copyrighted by Larry Wall and Clark Cooper, © 1998-2000. ! Software copyrighted by Frodo Looijaard, © 1997.
PATENT INFORMATION Protected by US Patents 6,470,384; 6,493,756; 6,496,875; 6,553,377; 6,553,378.
Issued March 2004 / ProtectionPilot™ software version 1.0 DBN 008-EN
Contents Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Audience . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Getting help . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 Getting information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 Contacting McAfee Security & Network Associates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
1 Introducing ProtectionPilot . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 Supported products . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 Using the console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 Database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
2 Getting Started with ProtectionPilot . . . . . . . . . . . . . . . . . . . . . . 17 What to do after installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 Automatic DAT and engine updates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 Existing update locations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 Novell environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 Proxy settings for the server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 Answers to common questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 How is up-to-dateness defined? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 What’s my current level of protection? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 Are my computers up-to-date? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 Have there been any detections lately? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 Are there any new threats or updates? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 When did I get the latest updates? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 Where to find information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Product Guide
iii
Contents
3 Making Sure Computers are Managed and Protected . . . . . . . . 23 Deploying products to new computers and putting them under management . . . . . . . . . . 24 Putting existing McAfee Security products under management . . . . . . . . . . . . . . . . . . . . . 29 Manually installing the agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 Adding computers that use a system image of a managed computer . . . . . . . . . . . . . . . . 35 Adding products to the server repository . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
4 Keeping Products Up-To-Date . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 Upgrading products . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38 Performing immediate DAT and engine updates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 Changing the frequency of DAT and engine updates . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41
5 Organizing Computers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 Defining the organization of computers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 Renaming groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 Moving computers between groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 Removing a computer from management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 Removing an entire group of computers from management . . . . . . . . . . . . . . . . . . . . . . . 47
6 Changing Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49 Changing agent policy settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50 Changing managed product policy settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 Restoring default policy settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52
7 Scheduling Client Tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53 Performing scheduled updates (VirusScan) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 Performing scheduled scans . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56 Modifying default on-demand scan client tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58 Modifying user-defined client tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 Deleting user-defined client tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60
8 Investigating Detections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61 Listing computers with reported detections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62 Listing what has been detected . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63 Listing which files have been impacted . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64 Viewing detection history for computers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65
iv
ProtectionPilot ™ software version 1.0
Contents
Learning more about detections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67 Scanning managed computers for possible infections . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68 Printing detection reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
9 Resolving Compliance Issues . . . . . . . . . . . . . . . . . . . . . . . . . . . 71 Listing non-compliant computers and taking action to bring them up-to-date . . . . . . . . . . 72 Viewing agent log files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76 Viewing computer and product properties . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77 Viewing update history for computers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78 Printing compliance reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
10 Managing the Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83 Adding proxy settings for the server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 84 Using the proxy settings in Internet Explorer for the server . . . . . . . . . . . . . . . . . . . . 84 Defining custom proxy settings for the server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85 Changing the definition of “not communicating” . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 86 Changing the server password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87 Changing port numbers used for server communication . . . . . . . . . . . . . . . . . . . . . . . . . . 88 Changing the name of the server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89 Viewing the server log file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89 Modifying the size of the server log file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 90
A Managing AutoUpdate Repositories . . . . . . . . . . . . . . . . . . . . . . 91 When to use AutoUpdate repositories . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 92 Download and replication credentials . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93 Creating distributed repositories on non-dedicated computers . . . . . . . . . . . . . . . . . . . . . 93 Creating distributed repositories on HTTP servers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 94 Creating distributed repositories on FTP servers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96 Creating distributed repositories using UNC shares . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 97 Modifying distributed repositories . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99 Removing distributed repositories from management . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99 Replicating to distributed repositories immediately . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100 Adding proxy settings for managed computers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101 Using the proxy settings in Internet Explorer for managed computers . . . . . . . . . . 101 Defining custom proxy settings for managed computers . . . . . . . . . . . . . . . . . . . . . 102
Product Guide
v
Contents
B Receiving Notification of Incidents . . . . . . . . . . . . . . . . . . . . . . 105 Setting up the Alert Manager server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106 Sending notifications of alert messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107 Sending notifications as text messages via e-mail or pagers . . . . . . . . . . . . . . . . . 108 Sending alert messages to the Alert Manager server . . . . . . . . . . . . . . . . . . . . . . . . . . . 109 Sending alert messages from VirusScan 4.5.1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110 Sending alert messages from VirusScan Enterprise 7.0 or 7.1 . . . . . . . . . . . . . . . . 111 Sending alert messages from NetShield 4.6 for NetWare . . . . . . . . . . . . . . . . . . . . 112
C Managing NetShield for NetWare . . . . . . . . . . . . . . . . . . . . . . . . 115 Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
vi
ProtectionPilot™ software version 1.0
Preface This guide introduces McAfee® ProtectionPilot™ software version 1.0, and provides the following information: "
Overview of the product.
"
Descriptions of product features.
"
Detailed instructions for configuring and deploying the software.
"
Procedures for performing tasks.
"
Troubleshooting information.
"
Glossary of terms.
Audience This information is designed for system and network administrators who are managing up to 500 computers and are responsible for their company’s anti-virus program.
Getting help There are a variety of resources available to you when you need more information about the product. "
Click Help or
from anywhere in the application.
"
Review the ProtectionPilot 1.0 Release Notes (README.TXT) for a list of known issues and last-minute updates to the product and its documentation. The default location is: C:\PROGRAM FILES\ NETWORK ASSOCIATES\PROTECTIONPILOT\1.0.0
"
Click McAfee Support under Resource Sites on the Welcome to McAfee ProtectionPilot page for access to a free knowledge base of known issues and supplemental documentation.
Product Guide
7
Preface
Conventions This guide uses the following conventions: Bold
All words from the user interface, including options, menus, buttons, and dialog box names. Example
Type the User name and Password of the desired account. Courier
Text that represents something the user types exactly (for example, a command at the system prompt). Examples
Run this command on the computer: C:\SETUP.EXE
Italic
For emphasis or when introducing a new term; for names of product manuals and topics (headings) within the manuals. Example
Refer to the VirusScan Enterprise Product Guide for more information. <TERM>
Angle brackets enclose a generic term. Example
In the tree pane under ePolicy Orchestrator, right-click <SERVER>.
8
NOTE
Supplemental information; for example, an alternate method of executing the same command.
WARNING
Important advice to protect a user, computer system, enterprise, software installation, or data.
ProtectionPilot™ software version 1.0
Getting information
Getting information Evaluation Guide *^
Procedures on preparing for, installing, and deploying the software in a test environment, and detailed instructions for common tasks.
Quick Reference Card *^
Detailed instructions for both common and infrequent, but important tasks.
Installation Guide *^
Procedures on preparing for, installing, and deploying the software in a production environment.
Product Guide *
Procedures on customizing the software for your environment and maintaining the software. Product introduction and features, detailed instructions for configuring the software, information on deployment, recurring tasks, and operating procedures.
Help §
Context-sensitive help topics accessible from most pages that list the procedures related to that page, reference information, and all information found in the Product Guide.
Release Notes ‡
ReadMe. Product information, resolved issues, any known issues, and last-minute additions or changes to the product or its documentation.
Contacts ‡
Contact information for McAfee Security and Network Associates services and resources: technical support, customer service, AVERT (Anti-Virus Emergency Response Team), beta program, and training. This file also includes phone numbers, street addresses, web addresses, and fax numbers for Network Associates offices in the United States and around the world.
* An Adobe Acrobat .PDF file on the product CD, or the McAfee Security download site. ^ A printed manual that accompanies the product CD. Note: Some language manuals may be available only as a .PDF file. ‡ Text files included with the software application and on the product CD. § Help accessed from the software application: Help menu and/or Help button for page-level help.
Product Guide
9
Preface
Contacting McAfee Security & Network Associates Technical Support Home Page
http://www.networkassociates.com/us/support/
KnowledgeBase Search
https://knowledgemap.nai.com/phpclient/homepage.aspx
PrimeSupport Service Portal *
https://mysupport.nai.com
McAfee Security Beta Program
http://www.networkassociates.com/us/downloads/beta/
Security Headquarters — AVERT (Anti-Virus Emergency Response Team) Home Page
http://www.networkassociates.com/us/security/home.asp
Virus Information Library
http://vil.nai.com
Submit a Sample — AVERT WebImmune
https://www.webimmune.net/default.asp
AVERT DAT Notification Service
http://vil.nai.com/vil/join-DAT-list.asp
Download Site Home Page
http://www.networkassociates.com/us/downloads/
DAT File and Engine Updates
http://www.networkassociates.com/us/downloads/updates/ ftp://ftp.nai.com/pub/antivirus/datfiles/4.x
Product Upgrades *
https://secure.nai.com/us/forms/downloads/upgrades/login.asp
Training McAfee Security University
http://www.networkassociates.com/us/services/education/mcafee/univer sity.htm
Network Associates Customer Service E-mail
services_corporate_division@nai.com
Web
http://www.networkassociates.com/us/index.asp
US, Canada, and Latin America toll-free: Phone
+1-888-VIRUS NO
or
+1-888-847-8766
Monday – Friday, 8 a.m. – 8 p.m., Central Time For additional information on contacting Network Associates and McAfee Security – including toll-free numbers for other geographic areas – see the Contact file that accompanies this product release. * Logon credentials required.
10
ProtectionPilot ™ software version 1.0
Introducing ProtectionPilot
1
The ProtectionPilot software is a security management system that simplifies anti-virus management tasks for network administrators who manage up to 500 computers. Management consists of deploying (sending and installing) anti-virus products, configuring product settings, and keeping those products up-to-date. The software is a system made up of these components: server, console, database, and agent.
Supported products You can use the McAfee ProtectionPilot software to manage these McAfee Security products: "
Alert Manager 4.5 (client software only).
"
Alert Manager 4.7 (server and client software).
"
NetShield 4.6 for NetWare.
"
VirusScan 4.5.1, Service Pack 1.
"
VirusScan Enterprise 7.0 or later.
Product Guide
11
Introducing ProtectionPilot
Server Executing all console requests and handling the exchange of data from the console and agents to the database, the ProtectionPilot server does a majority of the work of the software.
Agents
Consoles
Server
Database
Figure 1-1. How the server handles data received from agents and the console
12
ProtectionPilot ™ software version 1.0
Console
Console The piece you interact with directly to execute tasks and view data is the ProtectionPilot console. Although a console is always installed with the server, you can also install it separately. In this case, it is called a remote console because it is used to access the server remotely (from a different computer). Remote consoles are useful if you need to access the server from another computer or location; for example, if access to the server room is restricted or it isn’t set up as a work space.
Console
Server
Computer
Remote Consoles
Computer Figure 1-2. Relationship between the console, remote consoles, and the server
Product Guide
13
Introducing ProtectionPilot
Using the console The main user interface components of the ProtectionPilot console are described below.
1
3
2
4
Figure 1-3. User interface components Sections — Click the buttons at the top of the center pane of the console to go directly to the corresponding section (a group of related pages). For example, click the Server button to display the Server section. 1
2
Tree pane — You can also click the items in the tree pane (left pane of the
console) to go directly to the corresponding section. This is the only way to go directly to the group and computer sections. 3
Back — Click
to go back to the page that you last viewed.
Print — Click to open a printer-friendly version of the contents of the center pane. The right pane of the console (contains the back, print, and help buttons, and Management Tasks) is excluded. Help — Click page appear. 4
14
to open the Help file. Descriptions of the options on the current
Management Tasks — Provides quick access to tasks related to the current page.
ProtectionPilot ™ software version 1.0
Database
Database The core component of ProtectionPilot is the database, which stores all data about those computers and products you are managing with the software. Typically, the database is installed on the same computer as the server (local database), but you can also install it on a different computer (remote database). You can even take advantage of an existing database.
Server
Database
Computer
Figure 1-4. Local database
Server
Computer
Database
Computer Figure 1-5. Remote database
Product Guide
15
Introducing ProtectionPilot
Agent The ProtectionPilot agent is the key to remotely managing products. Installed on each computer, it deploys products, updates virus definition (DAT) files and the virus-scanning engine, and upgrades existing products with service pack and patch releases. It also gathers data about installed anti-virus products, the computer, and infection and system activity. In addition, it ensures that requests from the server are executed and re-executed or enforced as needed. For example, if a user removes the anti-virus product you have defined for the computer, the agent will reinstall the product automatically.
Managed Computer Agent
Managed Products
Server
Figure 1-6. Relationship between the agent, managed computer and products, and the server
16
ProtectionPilot ™ software version 1.0
Getting Started with ProtectionPilot
2
Before you start using the ProtectionPilot software, you might find it useful to review these sections: "
What to do after installation.
"
Answers to common questions.
"
Where to find information.
What to do after installation If you have just installed the server and console for the first-time, you might need to complete additional tasks to ensure proper functionality: "
Automatic DAT and engine updates.
"
Existing update locations.
"
Novell environment.
"
Proxy settings for the server.
Automatic DAT and engine updates By default, ProtectionPilot automatically retrieves virus definition (DAT) files and the virus-scanning engine from Network Associates hourly, then begins updating managed products immediately. This default setup ensures that the latest DAT and engine files are protecting your network as soon as they are available. You can change how often DAT and engine files are updated. For instructions, see Changing the frequency of DAT and engine updates on page 41.
Existing update locations If you have been using update locations (repositories) to centrally distribute virus definition (DAT) files and the virus-scanning engine to computers, this updating strategy is no longer used once you install the server and console. Instead, new DAT and engine files are automatically retrieved from Network Associates every hour, and the updating of managed products begins immediately following. Although we recommend using this default updating strategy, there are situations in which using AutoUpdate repositories are recommended. For more information, see Managing AutoUpdate Repositories on page 91.
Product Guide
17
Getting Started with ProtectionPilot
Novell environment You must manually install the agent to computers in Novell networks before you can deploy the VirusScan software. For instructions, see Manually installing the agent on page 34 and Deploying products to new computers and putting them under management on page 24. For more information on managing NetShield 4.6 for NetWare, see Managing NetShield for NetWare on page 115.
Proxy settings for the server If the ProtectionPilot server connects to the Internet via a proxy server, you need to add these settings before the automatic updating of virus definition (DAT) files and the virus-scanning engine can begin. For instructions, see Adding proxy settings for the server on page 84.
Answers to common questions This section provides answers to these commonly asked questions: "
How is up-to-dateness defined?
"
What’s my current level of protection?
"
Are my computers up-to-date?
"
Have there been any detections lately?
"
Are there any new threats or updates?
"
When did I get the latest updates?
How is up-to-dateness defined? There are two items that together define product compliance, or whether a computer is reported as up-to-date:
18
"
The contents of the server repository — Any managed computer with one or more product, agent, DAT, or engine versions that are earlier than those in the server repository is reported as out-of-date (not up-of-date).
"
How recently the agent has connected to the server — How long it’s been since an agent last communicated with the server affects whether the managed computer is reported as up-to-date. By default, this time period is 7 days. You can change this time period as needed. For instructions, see Changing the definition of “not communicating” on page 86.
ProtectionPilot ™ software version 1.0
Answers to common questions
What’s my current level of protection? To view the DAT and engine version numbers: "
From the Home section, see DAT version and Engine version under ProtectionPilot Server.
Figure 2-1. Viewing DAT and engine version numbers from the Home section "
From the Server section, see DAT version and Engine version under Server Status.
Figure 2-2. Viewing DAT and engine version numbers from the Server section
To view the version numbers of all products: "
From the Server section, click the Repository tab. The product names and version numbers are listed under Server Repository.
Figure 2-3. Viewing the version number of all products in the server repository
Product Guide
19
Getting Started with ProtectionPilot
Are my computers up-to-date? Once you know what up-to-dateness means and how to control the definition of product compliance, the question becomes: “Are my managed computers actually up-to-date?” (For more information on product compliance, see How is up-to-dateness defined? on page 18.) Compliance reports break this question down into these categories: "
Up-to-date — All product, agent, DAT, and engine versions are equal to or later
than those in the server repository, and the agent has communicated recently. "
Pending — An immediate update has been sent, but the agent has not yet returned the update status to the server.
"
Not communicating — The agent hasn’t communicated recently.
"
Not up-to-date — One or more product, agent, DAT, or engine versions are earlier than those in the server repository, and the agent has communicated recently.
You can click any of these categories to view compliance details on computers. You can use this data to determine why some computers are non-compliant and take action to bring them up-to-date. For instructions, see Resolving Compliance Issues on page 71.
Have there been any detections lately? Of course, before you can investigate detections, you need to know whether any have occurred recently. Detection reports provide this information to you at-a-glance: "
Cleaned / Blocked — Files where clean or block succeeded.
"
Deleted — Files where delete succeeded.
"
Quarantined — Files where move (quarantine) succeeded.
"
Error — Files where access was denied, or where clean, block, delete, or move
(quarantine) failed. You can click any of these categories to view detection details on computers. You can use this data to determine what has been detected and which files have been impacted. For instructions, see Investigating Detections on page 61.
20
ProtectionPilot ™ software version 1.0
Answers to common questions
Are there any new threats or updates? The default setup monitors the Network Associates web site on an hourly basis for updates. While this takes care of the question ”Are there any new updates?” for you, you can choose to take a more active role in protecting your network. One way to do this is by monitoring the AVERT (Anti-Virus Emergency Response Team) web site for newly discovered threats and the availability of updates that detect them. "
From the Home section, click AVERT Information under Resource Sites.
When did I get the latest updates? Regardless of whether you actively monitor the AVERT (Anti-Virus Emergency Response Team) web site for new threats and updates, you will often want to know when the ProtectionPilot server last checked for new virus definition (DAT) files and the virus-scanning engine on the Network Associates web site, whether that task completed successfully, and when the site will be checked again for new updates. "
From the Home section, see Last update under ProtectionPilot Server.
Figure 2-4. Last update answers the question “When did I get the latest updates?”
Product Guide
21
Getting Started with ProtectionPilot
Where to find information Once you’ve completed the post-installation tasks, you are ready to customize the software for your environment, maintain it, and troubleshoot it: "
Making Sure Computers are Managed and Protected — Different ways you can ensure that new computers are put under management and protected by the McAfee anti-virus products.
"
Keeping Products Up-To-Date — Updating virus definition (DAT) files and the virus-scanning engine, and upgrading existing products with service pack and patch releases.
"
Organizing Computers — Keeping your managed computers organized.
"
Changing Policies — How to change policy settings and restore the default
settings. "
Scheduling Client Tasks — How to schedule the client tasks used to update managed products and scan managed computers.
"
Investigating Detections — Investigating and responding to detections.
"
Resolving Compliance Issues — Determining why computers are non-compliant and taking action to bring them up-to-date.
"
Managing the Server — Tasks associated with managing the ProtectionPilot
server. "
Managing AutoUpdate Repositories — When to use AutoUpdate repositories and
how to manage them.
22
"
Receiving Notification of Incidents — How to be notified whenever McAfee anti-virus products detect activity categorized at a certain priority level.
"
Managing NetShield for NetWare — Tasks for managing NetShield for NetWare are outlined here with references to the detailed steps.
"
Reference — Tasks for backing up, restoring, and maintaining the ProtectionPilot database, minimum software and hardware requirements, and reference information on predefined variables used in the software; see the Help file.
ProtectionPilot ™ software version 1.0
3
Making Sure Computers are Managed and Protected
There are a number of ways you can ensure that new computers are put under management and are protected by the McAfee anti-virus products. This section covers these tasks for managing and protecting new computers: "
Deploying products to new computers and putting them under management.
"
Putting existing McAfee Security products under management.
"
Manually installing the agent.
"
Adding computers that use a system image of a managed computer.
"
Adding products to the server repository.
The Help file covers this additional task for managing and protecting new computers: "
Replacing Symantec AntiVirus with VirusScan.
Product Guide
23
Making Sure Computers are Managed and Protected
Deploying products to new computers and putting them under management For option definitions, click Help or
in the interface.
1
From the All Computers section on the General tab, click Add Computers under Management Tasks.
2
Click Next in the Add Computers Wizard.
3
Select the desired domains or individual computers, then click Next.
Figure 3-1. Add Computers Wizard — Select computers to be managed
24
ProtectionPilot ™ software version 1.0
Deploying products to new computers and putting them under management
4
Specify how to organize the selected computers under All Computers, then click Next. To Add Computers To...
Select...
Existing groups with predefined IP settings.
According to group IP settings or domain names.
Existing groups with the same name as the computer’s domain or workgroup.
According to group IP settings or domain names.
An existing group.
In an existing group, then select the desired group from the list.
A new group.
In a new group, then type its name in the box.
Figure 3-2. Add Computers Wizard — Specify how the selected computers should be placed into groups
Product Guide
25
Making Sure Computers are Managed and Protected
5
Select the desired products, then click Next. If the product isn’t listed here, you need to add it to the server repository. For instructions, see Adding products to the server repository on page 35. If you select multiple VirusScan products, VirusScan Enterprise is installed on all computers except those using Windows 95, Windows 98, or Windows Me, on which VirusScan 4.5.1 is installed. VirusScan 4.5.1 is installed after the manual installation of agent. The agent is required to remotely manage products and it must be manually installed on computers running Windows 95, Windows 98, or Windows Me. NOTE
When upgrading from VirusScan 4.5.1 to VirusScan Enterprise 7.1, the VirusScan system tray icon doesn’t re-appear until the next time users log on to their computers.
Figure 3-3. Add Computers Wizard — Select products to deploy
26
ProtectionPilot ™ software version 1.0
Deploying products to new computers and putting them under management
6
To deploy the agent to computers running supported versions of Windows NT, Windows 2000, Windows XP, and Windows Server 2003, select Push agent. a
To hide the agent installation, select Hide agent installation user interface for agent push.
b
In Domain\User, type the credentials to use when installing the agent on the selected computers:
Figure 3-4. Add Computers Wizard — Specify agent deployment options
If the computers are in a domain... Then, these permissions are needed...
Use this format in Domain\User...
Domain administrator (in that domain)
<DOMAIN>\<USER> Example: MAIN\ADMINISTRATOR
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ ADMINISTRATOR
Product Guide
27
Making Sure Computers are Managed and Protected
If the computers are in a workgroup... Then, these permissions are needed...
Use this format in Domain\User...
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
NOTE
We recommend setting up the same local administrator user account on all computers, so you can put all of the computers under management at once. Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ ADMINISTRATOR
NOTE
The local administrator user accounts on the server and on each computer must be the same. c
28
Type the password associated with the user account that you provided in Password.
7
To save the agent package (FRAMEPKG.EXE) for manual installation, select Download agent, then click Browse to select a location. The agent must be manually installed on computers running supported versions of Windows 95, Windows 98, and Windows Me, and in Novell networks. For instructions, see Manually installing the agent on page 34.
8
Click Next, then Finish. Computers appear in the console within – at the most – three minutes.
ProtectionPilot ™ software version 1.0
Putting existing McAfee Security products under management
Putting existing McAfee Security products under management For option definitions, click Help or
in the interface.
1
From the All Computers section on the General tab, click Add Computers under Management Tasks.
2
Click Next in the Add Computers Wizard.
3
Select the desired domains or individual computers, then click Next.
Figure 3-5. Add Computers Wizard — Select computers to be managed
Product Guide
29
Making Sure Computers are Managed and Protected
4
Specify how to organize the selected computers under All Computers, then click Next. To Add Computers To...
Select...
Existing groups with predefined IP settings.
According to group IP settings or domain names.
Existing groups with the same name as the computer’s domain or workgroup.
According to group IP settings or domain names.
An existing group.
In an existing group, then select the desired group from the list.
A new group.
In a new group, then type its name in the box.
Figure 3-6. Add Computers Wizard — Specify how the selected computers should be placed into groups
30
ProtectionPilot ™ software version 1.0
Putting existing McAfee Security products under management
5
Deselect all products, then click Next.
Figure 3-7. Add Computers Wizard — Select products to be deploy
Product Guide
31
Making Sure Computers are Managed and Protected
6
To deploy the agent to computers running supported versions of Windows NT, Windows 2000, Windows XP, and Windows Server 2003, select Push agent. a
To hide the agent installation, select Hide agent installation user interface for agent push.
b
In Domain\User, type the credentials to use when installing the agent on the selected computers:
Figure 3-8. Add Computers Wizard — Specify agent deployment options
If the computers are in a domain... Then, these permissions are needed...
Use this format in Domain\User...
Domain administrator (in that domain)
<DOMAIN>\<USER> Example: MAIN\ADMINISTRATOR
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
Local administrator (on the ProtectionPilot server)
32
ProtectionPilot ™ software version 1.0
.\<USER> Example: .\ ADMINISTRATOR
Putting existing McAfee Security products under management
If the computers are in a workgroup... Then, these permissions are needed...
Use this format in Domain\User...
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
NOTE
We recommend setting up the same local administrator user account on all computers, so you can put all of the computers under management at once. Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ ADMINISTRATOR
NOTE
The local administrator user accounts on the server and on each computer must be the same. c
Type the password associated with the user account that you provided in Password.
7
To save the agent package (FRAMEPKG.EXE) for manual installation, select Download agent, then click Browse to select a location. The agent must be manually installed on computers running supported versions of Windows 95, Windows 98, and Windows Me, and in Novell networks. For instructions, see Manually installing the agent on page 34.
8
Click Next, then Finish. Computers appear in the console within – at the most – three minutes.
Product Guide
33
Making Sure Computers are Managed and Protected
Manually installing the agent You need to distribute the agent package (FRAMEPKG.EXE) to users for them to install when any of the following are true: "
You don’t have remote access to computers.
"
Computers are running supported versions of Windows 95, Windows 98, or Windows Me.
"
Computers are in a Novell network.
Once installed, the agent contacts the ProtectionPilot server within – at the most – three minutes, and the computer appears in Lost&Found. To save agent package for manual installation: 1
From the Home section, click Download Agent Package under Management Tasks.
2
Click Save when asked whether you want to open or save the file.
3
Specify a location, then click Save.
4
Once the file has been downloaded, click Close in the Download Complete dialog box.
To manually install the agent: "
Install the agent via a logon script. — OR —
"
Distribute the file to users using one of these methods, and ask them to install the agent by double-clicking the FRAMEPKG.EXE file:
#
Network directory — Copy the package to a network directory (for example, \\<COMPUTER>\<FOLDER>) to which users have permissions.
#
Removable media — Copy the package to removable media (for example,
3.5-inch disk).
#
34
E-mail — Attach the package to an e-mail message.
ProtectionPilot ™ software version 1.0
Adding computers that use a system image of a managed computer
Adding computers that use a system image of a managed computer You can install the agent and McAfee Security products on computers used to create system images of software. The first time you log on to a computer built using a system image – that includes the agent – the agent immediately contacts the ProtectionPilot server. If this computer meets the criteria of existing groups (domain or workgroup membership or IP settings), it appears in those groups; otherwise, it appears in Lost&Found.
Adding products to the server repository During the installation, the files you need to deploy (send and install) VirusScan 4.5.1 and VirusScan Enterprise 7.1 are added to the server repository. Before you can deploy other products, you must add their package (PKGCATALOG.Z) file to the server repository. The server repository stores product releases and updates, and is where managed computers retrieve them. Package files contain the Setup program and other files needed for product deployment. For option definitions, click Help or 1
in the interface.
Locate the package (PKGCATALOG.Z) file on the product CD, or download it from the Network Associates web site (requires a Network Associates grant number): https://secure.nai.com/us/forms/downloads/upgrades/login.asp
2
From the Server section, click the Repository tab. The Manage AutoUpdate Repositories page appears.
3
Click Check In Package under Management Tasks.
4
Click Next in the Check In Package wizard.
Product Guide
35
Making Sure Computers are Managed and Protected
5
Select Products and updates, then click Next.
Figure 3-9. Check In Package Wizard (page 1) 6
Click Browse to select the package ( PKGCATALOG.Z) file for the product.
Figure 3-10. Check In Package Wizard (page 2) 7
36
Click Finish, then OK.
ProtectionPilot ™ software version 1.0
4
Keeping Products Up-To-Date
The task of keeping your anti-virus products up-to-date includes updating virus definition (DAT) files and the virus-scanning engine, and upgrading existing products with service pack and patch releases. This section covers these tasks for keeping products up-to-date: "
Upgrading products.
"
Performing immediate DAT and engine updates.
"
Changing the frequency of DAT and engine updates.
The Help file covers these additional tasks for keeping products up-to-date: "
Downloading and updating DAT or engine files manually.
"
Updating DAT or engine files using SuperDAT packages.
"
Updating EXTRA.DAT files.
"
Downgrading DAT files.
"
Starting a program after an update.
Product Guide
37
Keeping Products Up-To-Date
Upgrading products Use this procedure to deploy new versions of the VirusScan software or other products to managed computers. Periodically, you might also want to upgrade existing products with service pack or patch releases. For option definitions, click Help or 1
in the interface.
Locate the package (PKGCATALOG.Z) file on the product CD, or download it from the Network Associates web site (requires a Network Associates grant number): https://secure.nai.com/us/forms/downloads/upgrades/login.asp
2
From the Server section, click the Repository tab. The Manage AutoUpdate Repositories page appears.
3
Click Check In Package under Management Tasks.
4
Click Next in the Check In Package wizard.
5
Select Products and updates, then click Next.
Figure 4-1. Check In Package Wizard (page 1)
38
ProtectionPilot ™ software version 1.0
Upgrading products
6
Click Browse to select the package (PKGCATALOG.Z) file for the product release.
Figure 4-2. Check In Package Wizard (page 2) 7
Click Finish, then OK. Managed products are immediately upgraded.
Product Guide
39
Keeping Products Up-To-Date
Performing immediate DAT and engine updates By default, ProtectionPilot automatically retrieves virus definition (DAT) files and the virus-scanning engine from Network Associates hourly, then begins updating managed products immediately. You can immediately update managed products by first checking the Network Associates web site for new DAT and engine files, or by using the files that are in the server repository. To update from Network Associates: 1
From the Home section, click Update All under Management Tasks. The Update All Wizard appears and lists the version numbers of the most current DAT and engine files.
2
Click Finish to perform the update.
Figure 4-3. Update All Wizard
To update from the server repository: "
40
From the All Computers section on the General tab, click Update under Management Tasks.
ProtectionPilot ™ software version 1.0
Changing the frequency of DAT and engine updates
Changing the frequency of DAT and engine updates You can change how often ProtectionPilot checks the Network Associates web site for updated virus definition (DAT) files and the virus-scanning engine. For option definitions, click Help or
in the interface.
1
From the Server section on the Summary tab, click Server Update under Server Tasks to expand the task options.
2
Select the desired frequency options. For example, let’s say you want to retrieve updates from Network Associates every Wednesday at noon. Select the Weekly interval, then indicate that the task should run every Wednesday at 12:00 pm.
3
Be sure that the Enabled box is selected.
Figure 4-4. Server Update server task 4
Click Apply Settings under Management Tasks to save the current entries.
Product Guide
41
Keeping Products Up-To-Date
42
ProtectionPilot ™ software version 1.0
5
Organizing Computers
You most likely have reasons to apply different product settings and tasks to each department, office, or computer type. How you organize your managed computers under All Computers can be a useful tool in their management. For example, you might want more restrictive product settings on server computers than on workstations. Keeping your managed computers organized is an important aspect in managing them efficiently. This section covers these tasks for managing the organization of computers under All Computers: "
Defining the organization of computers.
"
Renaming groups.
"
Moving computers between groups.
"
Removing a computer from management.
"
Removing an entire group of computers from management.
The Help file covers this additional information and tasks for managing the organization of computers under All Computers: "
Lost&Found.
"
Adding IP settings to existing groups.
"
Modifying IP settings of existing groups.
"
Deleting IP settings from existing groups.
"
Verifying the integrity of IP settings.
"
Sorting computers by IP address.
Product Guide
43
Organizing Computers
Defining the organization of computers You define how to organize the computers you want to manage by creating groups. A group is a collection of computers that share common characteristics. You can create groups based on domain or workgroup membership; logical groupings (for example, geographic location or computer type, such as server versus workstation); or IP address. Groups simplify management by allowing you to perform tasks on all computers in a group at once. For option definitions, click Help or
in the interface.
To create a group: 1
From the All Computers section on the General tab, click Add Group under Management Tasks.
2
Click Next in the Add Group Wizard. By domain or workgroup membership:
# Select Domain name, select the domain or workgroup from the list box, then click Next. Using logical groupings:
# Select Group name, type a descriptive and unique name in the box, then click Next twice.
Figure 5-1. Add Group Wizard — Specify group name
44
ProtectionPilot ™ software version 1.0
Defining the organization of computers By IP address: a
Select Group name, type a descriptive and unique name in the box, then click Next.
b
Click Add to open the IP Management dialog box. You can define multiple IP settings for a group by repeating this step. NOTE
IP addresses cannot overlap between or within groups. "
To specify an IP address range, type the beginning and ending IP addresses in the range in IP range, then click OK. Use this format: XXX.XXX.XXX.XXX, where X is 0 – 255; for example, 161.69.0.0 – 161.69.255.255.
"
To specify an address mask, type the address mask and number of significant bits in IP subnet mask, then click OK. Use this format: XXX.XXX.XXX.XXX/YY, where X is 0 – 255 and Y is 0 – 32. For example, the address mask 161.69.0.0/16 equals the range 161.69.0.0 – 161.69.255.255. The address mask 161.69.255.0/18 equals the range 161.69.192.0 – 161.69.255.255.
Figure 5-2. Add Group Wizard — Specify IP settings c 3
When you’re done defining the IP settings, click Next.
Click Finish. Groups appear in the console within – at the most – three minutes.
Product Guide
45
Organizing Computers
Renaming groups You can easily rename groups as you refine the organization of managed computers. 1
In the tree pane under McAfee ProtectionPilot | All Computers, right-click a group, then click Rename.
2
Type the new name, then press ENTER.
Moving computers between groups You can use cut-and-paste or drag-and-drop operations to move computers from one group to another. Remember that if a computer belongs to a group that is based on IP addresses, the computer will reappear in that group whenever you sort computers by IP address until you modify the group’s IP settings to exclude it. For instructions, see Modifying IP settings of existing groups in the Help file. You will most often need to move computers from the Lost&Found into the correct group. We recommend that you first move computers from the Lost&Found to their respective groups before taking any other actions on them. For more information on this special group, see Lost&Found in the Help file. "
Drag the computer from one group to another.
— OR — 1
In the tree pane under McAfee ProtectionPilot | All Computers, right-click a computer from one group, then click Cut.
2
Right-click another group, then click Paste.
Removing a computer from management When you delete a computer, it is removed from its group under All Computers and removed from management (in other words, the agent is uninstalled from the computer). The anti-virus products remain. "
46
In the tree pane under McAfee ProtectionPilot | All Computers, right-click a computer from its group, then click Delete.
ProtectionPilot ™ software version 1.0
Removing an entire group of computers from management
Removing an entire group of computers from management When you delete a group, it and all of its computers are removed from All Computers, and the computers are removed from management (in other words, the agent is uninstalled from the computers). The anti-virus products remain. "
In the tree pane under McAfee ProtectionPilot | All Computers, right-click a group, then click Delete.
Product Guide
47
Organizing Computers
48
ProtectionPilot ™ software version 1.0
6
Changing Policies
Policies are the configuration settings for each product that can be managed via ProtectionPilot. These settings determine how the product behaves on managed computers. For example, you can specify which types of files that you want VirusScan Enterprise 7.0 to scan by choosing those settings on the corresponding policy page. You can change policy settings for all computers, a group of computers, or an individual computer. NOTE
Be sure to always click Apply Settings or Apply to save your policy changes. This section covers these tasks for changing policies: "
Changing agent policy settings.
"
Changing managed product policy settings.
"
Restoring default policy settings.
The Help file covers this additional task for changing policies: "
Changing agent for NetWare policy settings.
Product Guide
49
Changing Policies
Changing agent policy settings You can control how the agent behaves on managed computers by changing its policy settings. You can restore the default policy settings at any time. For instructions, see Restoring default policy settings on page 52. 1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Policies tab.
3
Click ProtectionPilot Agent to open the Policy Settings dialog box.
4
On the General tab, deselect Inherit.
Figure 6-1. ProtectionPilot Agent policy page To make the agent user interface accessible from managed computers:
When shown, the agent icon appears in the system tray of managed computers and allows management tasks to be performed locally.
# To show the agent system tray icon, select Show Agent Tray Icon. To define how often existing settings are reapplied:
The policy enforcement interval determines how often existing product policy settings are reapplied (enforced) on managed computers. Because this enforcement occurs locally, this interval does not require any bandwidth.
# Change the Policy Enforcement Interval (default is 5 minutes) as needed.
50
ProtectionPilot ™ software version 1.0
Changing managed product policy settings
To define how often updated settings are retrieved:
The agent-to-server communication interval (ASCI) determines how often the agent retrieves updated product policy settings and client tasks from the ProtectionPilot server. New policy settings are applied (enforced) as soon as they are received. New tasks run at the next scheduled time after being received. To conserve bandwidth, only data that has changed since the last ASCI is transmitted.
# Change the Agent to Server communication interval (default is 7 minutes) as needed. To specify how to handle restarts required during product installations: a
When computers need to be restarted as part of an installation, select Prompt user when software installation requires reboot to display a dialog box notifying users of this. Otherwise, computers are automatically restarted when required.
b
When computers need to be restarted as part of an installation, select Automatic reboot with timeout to restart computers if the user does not intervene before the specified time (in seconds) has elapsed.
5
Click Apply All to save the current entries.
6
Click Close to return to the Policies page.
Changing managed product policy settings You can control how each managed product behaves on managed computers by changing its policy settings. You can restore the default policy settings at any time. For instructions, see Restoring default policy settings on page 52. 1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Policies tab.
3
Click the desired product (for example, VirusScan Enterprise 7.1) to open the Policy Settings dialog box.
4
Select the desired option (for example, General Policies) in Select policy categories.
5
Deselect Inherit.
6
Make changes as needed. For information about each option, see the product documentation for each McAfee Security product.
7
Click Apply All to save the current entries.
8
Click Close to return to the Policies page.
Product Guide
51
Changing Policies
Restoring default policy settings You can reset product policies to their original settings. NOTE
You can also restore the default policy settings on any policy page by selecting Inherit, then clicking Apply. For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Policies tab.
3
Select Restore Inheritance under Management Tasks.
Figure 6-2. Reset Policy Inheritance dialog box
52
4
Select the Level at which you want to restore the default policy settings.
5
Specify whether you want to reset the default settings on All products or Selected products.
6
If you choose Selected products, select the desired products from the Products list.
7
Click OK.
ProtectionPilot ™ software version 1.0
7
Scheduling Client Tasks
Although you can update VirusScan products immediately or have the VirusScan products scan computers immediately by clicking Update or Scan (respectively) under Management Tasks, you can also schedule these activities to occur on a one-time or periodic basis. In addition, you can update the NetShield for NetWare product or have the NetShield for NetWare product scan computers only by scheduling the appropriate client tasks. This section covers these procedures for scheduling client tasks: "
Performing scheduled updates (VirusScan).
"
Performing scheduled scans.
"
Modifying default on-demand scan client tasks.
"
Modifying user-defined client tasks.
"
Deleting user-defined client tasks.
The Help file covers these additional tasks for scheduling client tasks: "
Performing scheduled DAT updates (NetShield for NetWare).
"
Performing scheduled engine updates (NetShield for NetWare).
Product Guide
53
Scheduling Client Tasks
Performing scheduled updates (VirusScan) You can perform scheduled updates using these steps for VirusScan 4.5.1 and VirusScan Enterprise 7.0 or later. The Update client task updates these managed products with the virus definition (DAT) files, virus-scanning engine, service pack releases, and patch releases in the server repository. For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Scheduled Tasks tab. The Scheduled Tasks page appears.
3
Click Create Task under Management Tasks.
4
Select the ProtectionPilot Agent | Update task, then click Next under Management Tasks.
Figure 7-1. Scheduled Tasks — Task Types page 5
Type a descriptive name for the task in Name under Task Settings.
6
Click Settings to open the Task Settings dialog box.
Figure 7-2. ProtectionPilot Agent — Update Task Settings dialog box 7
To display the progress of the update to users, select Show update progress dialog.
To install the update without notifying users, deselect Show update progress dialog.
54
ProtectionPilot ™ software version 1.0
Performing scheduled updates (VirusScan)
8
To provide users the option to postpone the update, select Allow users to postpone this update. Users can specify how long to postpone the update.
9
In Maximum number of postpones allowed, type the maximum number of times users can postpone the update before it is installed automatically.
10 In Postpone timeout interval, type how long (in seconds) users have to postpone
the update before it is installed automatically. 11 Click OK to save the current entries. 12 Deselect Inherit under Schedule Settings.
Figure 7-3. Scheduled Tasks — Task and Schedule Settings page 13 Select Enable; otherwise, the task won’t start, regardless of settings on this
page. 14 To limit the amount of time for which the task can run before it is automatically
cancelled, select Stop the task if it runs for, then specify the time limit. 15 Select the frequency for the task in Select an interval, then specify the
corresponding frequency options that appear. For example, if you selected Daily, Daily Options appear. 16 Click Apply Settings under Management Tasks to save the current entries.
Product Guide
55
Scheduling Client Tasks
Performing scheduled scans You can perform scheduled scans of managed computers. You must schedule separate On-Demand Scan client tasks for each managed product. The On-Demand Scan task scans the computers using the task settings you specify. For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Scheduled Tasks tab. The Scheduled Tasks page appears.
3
Click Create Task under Management Tasks.
4
Select the <PRODUCT> | On-Demand Scan task, then click Next under Management Tasks.
Figure 7-4. Schedule Tasks page
56
5
Type a descriptive name for the task in Name under Task Settings.
6
Click Settings to open the Task Settings dialog box.
7
Make changes as needed. For information about each option, see the product documentation for each McAfee Security product.
8
Click OK to save the current entries.
ProtectionPilot ™ software version 1.0
Performing scheduled scans
9
Deselect Inherit under Schedule Settings.
Figure 7-5. Scheduled Tasks — Task and Schedule Settings page 10 Select Enable; otherwise, the task won’t start, regardless of settings on this
page. 11 To limit the amount of time for which the task can run before it is automatically
cancelled, select Stop the task if it runs for, then specify the time limit. 12 Select the frequency for the task in Select an interval, then specify the
corresponding frequency options that appear. For example, if you selected Daily, Daily Options appears. 13 Click Apply Settings under Management Tasks to save the current entries.
Product Guide
57
Scheduling Client Tasks
Modifying default on-demand scan client tasks When you click Scan under Management Tasks, default on-demand scan client tasks are created for VirusScan 4.5.1, VirusScan Enterprise 7.0, and VirusScan Enterprise 7.1. If you click Scan from the Manage Computer page, only the task for the product version installed on that computer is created. Once created, you can modify the settings for these tasks; however, default tasks cannot be deleted. These default tasks are always scheduled to run immediately. Any changes you make to the schedule settings will be overwritten. For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Scheduled Tasks tab.
3
In the Scheduled tasks table, select a default on-demand scan task (<PRODUCT>_<VERSION>_DefaultODS; for example, VirusScan Enterprise_7.1.0_DefaultODS), then click Edit.
Figure 7-6. Scheduled Tasks page
58
4
Click Settings to make changes to the task settings, then click OK to save the current entries.
5
Click Apply Settings under Management Tasks to save the current entries.
ProtectionPilot ™ software version 1.0
Modifying user-defined client tasks
Modifying user-defined client tasks For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Scheduled Tasks tab. The Scheduled Tasks page appears.
3
Select a task from the table, then click Edit.
Figure 7-7. Scheduled Tasks page 4
Click Settings to make changes to the task settings, then click OK to save the current entries.
5
Make changes to the schedule settings as needed.
6
Click Apply Settings under Management Tasks to save the current entries.
Product Guide
59
Scheduling Client Tasks
Deleting user-defined client tasks For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Scheduled Tasks tab. The Scheduled Tasks page appears.
3
Select a task from the table, then click Delete.
Figure 7-8. Scheduled Tasks page
60
ProtectionPilot ™ software version 1.0
Investigating Detections
8
You can view detection data in a variety of ways including which computers and files were impacted by which detections. You can even go directly to the authority – McAfee Security AVERT (Anti-Virus Emergency Response Team) – to learn everything you ever wanted to know about each detection at the click of a button. This section covers these tasks for investigating detections: "
Listing computers with reported detections.
"
Listing what has been detected.
"
Listing which files have been impacted.
"
Viewing detection history for computers.
"
Learning more about detections.
"
Scanning managed computers for possible infections.
"
Printing detection reports.
Product Guide
61
Investigating Detections
Listing computers with reported detections 1
From the All Computers section, click the General tab.
2
Select a time frame, such as Today or This week.
Figure 8-1. Detections reported this week 3
Click a detection category, such as Quarantined or Error, to view detections reported within that time frame, grouped by computer name.
Figure 8-2. Detection detail grouped by computers
62
ProtectionPilot ™ software version 1.0
Listing what has been detected
Listing what has been detected 1
From the All Computers section, click the General tab.
2
Select a time frame, such as Today or This week.
Figure 8-3. Detections reported this week 3
Click a detection category, such as Quarantined or Error.
4
Click Detection detail grouped by detections.
Figure 8-4. Detection detail grouped by detections
Product Guide
63
Investigating Detections
Listing which files have been impacted 1
From the All Computers section, click the General tab.
2
Select a time frame, such as Today or This week.
Figure 8-5. Detections reported this week 3
Click a detection category, such as Quarantined or Error.
Figure 8-6. Detection detail grouped by computers
64
ProtectionPilot ™ software version 1.0
Viewing detection history for computers
4
Click Detection Count to view the files that were impacted by that detection.
Figure 8-7. Which files have been impacted
Viewing detection history for computers 1
From the All Computers section, click the General tab.
2
Select a time frame, such as Today or This week.
Figure 8-8. Detections reported this week
Product Guide
65
Investigating Detections
3
Click a detection category, such as Quarantined or Error.
Figure 8-9. Detection detail grouped by computers 4
Click Detection Count to view the detection history for computers.
Figure 8-10. Detection History
66
ProtectionPilot ™ software version 1.0
Learning more about detections
Learning more about detections Each detection name listed in the detection details is linked directly to its description in the Virus Information Library provided by AVERT (Anti-Virus Emergency Response Team). Find out the minimum version of virus definition (DAT) files and the virus-scanning engine you need to protect your network against every known virus. Learn about the symptoms and method of infection and much more. 1
From the All Computers section, click the General tab.
2
Select a time frame, such as Today or This week.
Figure 8-11. Detections reported this week 3
Click a detection category, such as Quarantined or Error.
Figure 8-12. Detection detail grouped by computers
Product Guide
67
Investigating Detections
4
Click Detection Name to go to the AVERT web site for a complete description of that detection.
Figure 8-13. Description of viruses on AVERT web site
Scanning managed computers for possible infections You can modify the settings of this immediate scan, or perform scheduled scans of managed computers. For instructions, see Modifying default on-demand scan client tasks on page 58 or Performing scheduled scans on page 56, respectively.
68
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click Scan under Management Tasks.
ProtectionPilot ™ software version 1.0
Printing detection reports
Printing detection reports To print data for all computers: 1
From the Home section, select a time frame (such as Today or This week) under the detection reports.
2
Click
3
Use the browser to print the report or save it to a file; for example, File | Print or File | Save As.
to open a printer-friendly version of the report in Internet Explorer.
Figure 8-14. Detection report from the Home section
Product Guide
69
Investigating Detections
To print data for all computers and groups: 1
From the All Computers section on the General tab, select a time frame (such as Today or This week) under the detection reports.
2
Click
to open a printer-friendly version of the report in Internet Explorer.
Figure 8-15. Detection reports from the All Computers section 3
70
Use the browser to print the report or save it to a file; for example, File | Print or File | Save As.
ProtectionPilot ™ software version 1.0
9
Resolving Compliance Issues
If managed computers are reported as Not communicating or Not up-to-date, how to determine why they are non-compliant and take action to bring them up-to-date are vital tasks to ensuring that your network is protected. This section covers these tasks for resolving product compliance issues: "
Listing non-compliant computers and taking action to bring them up-to-date.
"
Viewing agent log files.
"
Viewing computer and product properties.
"
Viewing update history for computers.
"
Printing compliance reports.
The Help file covers this additional task for resolving product compliance issues: "
Creating an updating activity log file.
Product Guide
71
Resolving Compliance Issues
Listing non-compliant computers and taking action to bring them up-to-date 1
From the All Computers section, click the General tab.
2
Click a compliance category, such as Not communicating or Not up-to-date, to view compliance issues, grouped by computer name.
Figure 9-1. Manage All Computers page
Cells that appear in red indicate that one or more product versions are earlier than those in the server repository, or that the agent has not communicated recently.
Figure 9-2. Red cells indicating which products are out-of-date
72
ProtectionPilot ™ software version 1.0
Listing non-compliant computers and taking action to bring them up-to-date
To check computer and agent connectivity:
# Select the desired computers, then click Check Connection. Whether the computer is online and the agent is running is verified. The Status column is updated with the current connection status as described below: If the Status is...
Then...
Inactive
The computer is online, but the agent is not running. Reinstall the agent, see To reinstall the agent:, following.
Not Tested
Connectivity hasn’t been checked within the last minute.
Offline
The computer is offline. The agent status cannot be determined. Start the computer. If it is still reported as non-compliant, continue troubleshooting.
Online
The computer is online and the agent is running. Continue troubleshooting.
Figure 9-3. Offline status of laptop computers that are out of the office To force an immediate DAT and engine update:
# If the DAT or Engine cells appear in red, select those computers, then click Update. The updating of managed products with all product updates in the server repository begins immediately.
Product Guide
73
Resolving Compliance Issues To install or reinstall products: a
If the Product Version cell appears in red, select those computers, then click Deploy.
b
Click Next in the Deploy Products Wizard.
c
Select the desired products. If the product isn’t listed here, you need to add it to the server repository. For instructions, see Adding products to the server repository on page 35. If you select multiple VirusScan products, VirusScan Enterprise is installed on all computers except those using Windows 95, Windows 98, or Windows Me, on which VirusScan 4.5.1 is installed. VirusScan 4.5.1 is installed after the manual installation of agent. The agent is required to remotely manage products and it must be manually installed on computers running Windows 95, Windows 98, or Windows Me. NOTE
When upgrading from VirusScan 4.5.1 to VirusScan Enterprise 7.1, the VirusScan system tray icon doesn’t re-appear until the next time users log on to their computers. d
Deselect Reinstall McAfee ProtectionPilot agent, then click Next.
e
Click Finish.
To reinstall the agent: a
If the Agent Version or Last Contact cells appear in red, select those computers, then click Deploy.
b
Click Next in the Deploy Products Wizard.
c
Select Reinstall McAfee ProtectionPilot agent.
d
Deselect all products, then click Next.
e
To deploy the agent to computers running supported versions of Windows NT, Windows 2000, Windows XP, and Windows Server 2003, select Push agent.
f
To hide the agent installation, select Hide agent installation user interface for agent push.
74
ProtectionPilot ™ software version 1.0
Listing non-compliant computers and taking action to bring them up-to-date
g
In Domain\User, type the credentials to use when installing the agent on the selected computers: If the computers are in a domain... Then, these permissions are needed...
Use this format in Domain\User...
Domain administrator (in that domain)
<DOMAIN>\<USER> Example: MAIN\ADMINISTRATOR
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ ADMINISTRATOR
If the computers are in a workgroup... Then, these permissions are needed...
Use this format in Domain\User...
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
NOTE
We recommend setting up the same local administrator user account on all computers, so you can put all of the computers under management at once. Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ ADMINISTRATOR
NOTE
The local administrator user accounts on the server and on each computer must be the same. h
Type the password associated with the user account that you provided in Password.
i
To save the agent package (FRAMEPKG.EXE) for manual installation, select Download agent, then click Browse to select a location. The agent must be manually installed on computers running supported versions of Windows 95, Windows 98, and Windows Me, and in Novell networks. For instructions, see Manually installing the agent on page 34.
j
Click Next, then Finish.
Product Guide
75
Resolving Compliance Issues
To force an immediate collection of computer and product properties:
# To have the complete set of properties resent to you, select the desired computers, then click Enforce. To force an immediate policy and task enforcement:
# To reapply (enforce) the existing product policy settings and tasks on managed computers manually, select the desired computers, then click Enforce. 3
If computers are still reported as non-compliant, here are additional tasks you can use to track down the source of the issue:
# Viewing agent log files on page 76. # Viewing computer and product properties on page 77. # Viewing update history for computers on page 78. # Creating an updating activity log file in the Help file.
Viewing agent log files 1
In the tree pane under McAfee ProtectionPilot| All Computers, select a computer from its group.
2
Click the Agent Log tab to view the agent activity log file.
Figure 9-4. Agent Activity log file
To view the current or previous agent installation log file, click current or previous next to FrameSvc. To view the current client tasks log file, click current next to NaPrdMgr. To print a log file:
76
a
Click
to open a printer-friendly version of the log in Internet Explorer.
b
Use the browser to print the log or save it to a file; for example, File | Print or File | Save As.
ProtectionPilot ™ software version 1.0
Viewing computer and product properties
To refresh the contents of a log file:
# Click Refresh under Management Tasks.
Viewing computer and product properties 1
From the All Computers section, click the General tab.
2
Under Compliance, select whether to view compliance data for all computers (displayed by default) or sorted by group (click to expand).
3
Click a compliance category, such as Not communicating or Not up-to-date, to view compliance issues grouped by computer name.
Figure 9-5. Compliance Details page 4
Click a computer name. The Manage Computer page appears.
Figure 9-6. Manage Computer page
Product Guide
77
Resolving Compliance Issues
5
To view the complete set of properties, click View detailed properties under Computer Conditions.
Figure 9-7. Properties for Computer page
Viewing update history for computers 1
From the All Computers section, click the General tab.
2
Under Compliance, select whether to view compliance data for all computers (displayed by default) or sorted by group (click to expand).
3
Click a compliance category, such as Not communicating or Not up-to-date, to view compliance issues grouped by computer name.
Figure 9-8. Compliance Details page
78
ProtectionPilot ™ software version 1.0
Viewing update history for computers
4
Click a computer name. The Manage Computer page appears.
Figure 9-9. Manage Computer page 5
Click View update history under Compliance.
Figure 9-10. Update History for Computer page
Product Guide
79
Resolving Compliance Issues
Printing compliance reports To print data for all computers: 1
From the Home section, click in Internet Explorer.
to open a printer-friendly version of the report
2
Use the browser to print the report or save it to a file; for example, File | Print or File | Save As.
Figure 9-11. Compliance report from the Home section
80
ProtectionPilot ™ software version 1.0
Printing compliance reports
To print data for all computers and groups: 1
From the All Computers section, click the report in Internet Explorer.
to open a printer-friendly version of
2
Use the browser to print the report or save it to a file; for example, File | Print or File | Save As.
Figure 9-12. Compliance reports from the All Computers section
Product Guide
81
Resolving Compliance Issues
82
ProtectionPilot ™ software version 1.0
10
Managing the Server
Many of the tasks associated with managing the ProtectionPilot server will need to be done only once – if at all – when you initially install the server and console or when specific settings on your network, such as proxy settings, change. This section covers these tasks for managing the server: "
Adding proxy settings for the server.
"
Changing the definition of “not communicating”.
"
Changing the server password.
"
Changing port numbers used for server communication.
"
Changing the name of the server.
"
Viewing the server log file.
"
Modifying the size of the server log file.
The Help file covers this additional task for managing the server: "
Removing proxy settings on the server.
Product Guide
83
Managing the Server
Adding proxy settings for the server If the ProtectionPilot server connects to the Internet via a proxy server, you need to add these settings before updates can be retrieved from the Network Associates web site and managed computers updated with them. You can use the proxy settings in Internet Explorer or specify custom proxy settings. "
Using the proxy settings in Internet Explorer for the server.
"
Defining custom proxy settings for the server.
Using the proxy settings in Internet Explorer for the server For option definitions, click Help or 1
in the interface.
From the Server section, click the Proxy tab.
Figure 10-1. Proxy Settings for Server and Repositories page 2
Select Use Internet Explorer proxy settings.
3
Provide a user account with permissions to the proxy server specified in Internet Explorer.
4
84
a
Select Use HTTP proxy authentication or Use FTP proxy authentication.
b
In the User name, Password, and Re-enter password boxes that correspond to the desired protocol, type the user name and password associated with the user account.
Click Apply Settings under Management Tasks.
ProtectionPilot ™ software version 1.0
Adding proxy settings for the server
Defining custom proxy settings for the server For option definitions, click Help or 1
in the interface.
From the Server section, click the Proxy tab.
Figure 10-2. Proxy Settings for Server and Repositories page 2
Select Use custom proxy settings.
3
Provide the address and port number of the proxy server you want to use to gain access to distributed repositories using HTTP or FTP protocols. a
In Hostname or IP Address, type the IP address or fully-qualified domain name of the proxy server.
b
In Port, type the port number of the proxy server.
4
To specify distributed repositories to which the server can connect directly, select Bypass local addresses, then type the IP addresses or fully-qualified domain name of those computers separated by a semi-colon (;).
5
Provide a user account with permissions to the proxy server you specified in HTTP or FTP in Step 3.
6
a
Select Use HTTP proxy authentication or Use FTP proxy authentication.
b
In the User name, Password, and Re-enter password boxes that correspond to the desired protocol, type the user name and password associated with the user account.
Click Apply Settings under Management Tasks.
Product Guide
85
Managing the Server
Changing the definition of “not communicating” How long it’s been since an agent last communicated with the server affects whether the managed computer is reported as up-to-date. For more information, see How is up-to-dateness defined? on page 18. For option definitions, click Help or
in the interface.
1
From the Server section, click the Settings tab.
2
Change the “Not communication” definition, then click Apply Settings under Management Tasks.
Figure 10-3. Server Settings page
86
ProtectionPilot ™ software version 1.0
Changing the server password
Changing the server password Although you specify a secure password during the initial installation of the server and console, it’s a good idea to periodically change the password to ensure that the server is kept secure. How often you need to change the server password will depend on your company’s security policies. For option definitions, click Help or
in the interface.
1
From the Server section, click the Settings tab.
2
Select Change server password.
Figure 10-4. Server Settings page 3
Type the new password in New server password and Confirm new password.
4
Click Apply Settings under Management Tasks.
Product Guide
87
Managing the Server
Changing port numbers used for server communication Typically, you won’t need to change the port numbers used for communication to and from the server once you define them during the initial installation. However, you might need to when installing new software or when your company’s security policies change. Most often you will only need to refresh your memory on which port numbers the server uses for communication. For option definitions, click Help or 1
in the interface.
From the Server section, click the Settings tab.
Figure 10-5. Server Settings page 2
The Agent-to-server communications port is display only. If you need to change this port number, back up the ProtectionPilot database, uninstall the server and console, then assign the new port number when you re-install the server and console.
3
The Console-to-server communications port is display only. If you need to change this port number, back up the ProtectionPilot database, uninstall the server and console, and any remote consoles, then assign the new port number when you re-install the server and consoles.
4
Type a different Server-to-agent communications port (default is 8081) as needed. If you change this port number, immediate client tasks are disabled until the next agent-to-server communication.
5
88
Click Apply Settings under Management Tasks.
ProtectionPilot ™ software version 1.0
Changing the name of the server
Changing the name of the server If you need to change the name of the server, back up the ProtectionPilot database, uninstall the server and all consoles, then change the computer name before you re-install the server and console and any remote consoles.
Viewing the server log file The server log file contains entries about server activity, server events, and server tasks. "
From the Server section, click the Log tab.
Figure 10-6. View Server Log page To print the log file: a
Click
to open a printer-friendly version of the log in Internet Explorer.
b
Use the browser to print the log; for example, File | Print.
To refresh contents of the log file:
# Click Refresh under Management Tasks. To save the log to a file: a
Click
to open a printer-friendly version of the log in Internet Explorer.
b
Use the browser to save the log to a file; for example, File | Save As.
Product Guide
89
Managing the Server
Modifying the size of the server log file For option definitions, click Help or 1
in the interface.
From the Server section, click the Settings tab.
Figure 10-7. Server Settings page
90
2
Type a different Server log size (default is 2048KB) as needed.
3
Click Apply Settings under Management Tasks.
ProtectionPilot ™ software version 1.0
A
Managing AutoUpdate Repositories
If you have been using update locations to centrally distribute virus definition (DAT) files and the virus-scanning engine to computers, this updating strategy is no longer used once you install the server and console. Instead, new DAT and engine files are automatically retrieved from Network Associates every hour, and the updating of managed products begins immediately following. Although we recommend using this default updating strategy, there are situations in which using AutoUpdate repositories are recommended. This section covers these tasks for managing AutoUpdate repositories: "
When to use AutoUpdate repositories.
"
Download and replication credentials.
"
Creating distributed repositories on non-dedicated computers.
"
Creating distributed repositories on HTTP servers.
"
Creating distributed repositories on FTP servers.
"
Creating distributed repositories using UNC shares.
"
Modifying distributed repositories.
"
Removing distributed repositories from management.
"
Replicating to distributed repositories immediately.
"
Adding proxy settings for managed computers.
The Help file covers these additional tasks for managing AutoUpdate repositories: "
Removing proxy settings on managed computers.
"
Specifying the order in which AutoUpdate repositories are selected.
Product Guide
91
Managing AutoUpdate Repositories
When to use AutoUpdate repositories If your company is geographically dispersed, we recommend setting up a separate distributed AutoUpdate repository in each satellite office that has more than five end-users. We also recommend choosing a computer, such as a server, that is always on to host these repositories. Those offices with less than five end-users and mobile users can use the server repository instead of setting up a separate one.
Network Associates web site
Satellite Office or Mobile Users Server Managed Computers
Server Repository
Managed Computer
Managed Computer
Managed Computer
Distributed Repository
Main Office Managed Computers
Satellite Office Figure A-1. Setting up AutoUpdate repositories across geographically dispersed offices
92
ProtectionPilot ™ software version 1.0
Download and replication credentials
Download and replication credentials Download credentials are used by managed computers to connect to AutoUpdate repositories. Provide user accounts with read-only permissions to the HTTP server, FTP server, or UNC share that hosts the repository. Replication credentials are used by the server repository to copy files to AutoUpdate repositories. Provide user accounts with read and write permissions to the HTTP server, FTP server, or UNC share that hosts the repository. Agent-based AutoUpdate repositories don’t need download or replication credentials because the agent authenticates the files.
Creating distributed repositories on non-dedicated computers Before you begin "
Verify that the computer has at least 100MB (on the drive where the repository is stored) of free disk space and 256MB of RAM.
"
You need to know a local directory on the managed computer to store the repository.
To create distributed repositories on non-dedicated computers:
For option definitions, click Help or
in the interface.
1
From the Server section, click the Repository tab.
2
Click Add Repository under Management Tasks.
3
Select Agent, then click Next under Management Tasks.
Product Guide
93
Managing AutoUpdate Repositories
4
Select a managed computer to host the repository from the table.
Figure A-2. Manage AutoUpdate Repositories — Agent Repository Options page 5
The Repository name defaults to EPOSA_<COMPUTER>, where <COMPUTER> is the name of the managed computer.
6
Type a local directory (for example, C:\REPOSITORY) where you want to store the repository in Repository path. You can also use predefined or system environment variables to define this location. For more information, see Variables in the Help file.
7
Click Apply Settings under Management Tasks.
Creating distributed repositories on HTTP servers Before you begin
94
"
Verify that the computer is an HTTP-compliant (version 1.1) server on Microsoft Windows, Linux, or Novell NetWare operating systems with a UNC share.
"
You need to know the web address and port number of the HTTP server.
"
You need to know a network directory on the HTTP server to store the repository.
ProtectionPilot ™ software version 1.0
Creating distributed repositories on HTTP servers
"
Make sure you have user accounts with the appropriate credentials, see Download and replication credentials on page 93.
"
If managed computers connect to repositories through a firewall, ensure that the repository accepts inbound communication on the appropriate communication port. Typically, this is port 80.
To create distributed repositories on HTTP servers:
For option definitions, click Help or
in the interface.
1
From the Server section, click the Repository tab.
2
Click Add Repository under Management Tasks.
3
Select HTTP, then click Next under Management Tasks.
Figure A-3. Manage AutoUpdate Repositories — HTTP Options page 4
Type the web address of the HTTP server in URL.
5
Type the port number that the HTTP server uses for communication (typically, this is port 80) in Port.
6
Type a descriptive and unique name for the repository in Repository name.
7
If the HTTP server requires authentication, select Use download credentials, then type the user account information in User name, Password, and Re-enter password under HTTP Download Credentials. To authenticate the user account you specified, click Verify.
Product Guide
95
Managing AutoUpdate Repositories
8
Under HTTP Replication Credentials, type the UNC share name of the physical directory that represents the virtual directory where you want to store the repository on the HTTP server in UNC path. Use this format: \\<COMPUTER>\<FOLDER>. You can also use predefined or system environment variables to define this location. For more information, see Variables in the Help file.
9
Type the user account information for the network directory in Domain name, User name, Password, and Re-enter password. To authenticate the user account you specified, click Verify.
10 Click Apply Settings under Management Tasks.
Creating distributed repositories on FTP servers Before you begin "
Verify that the computer is a Windows, Linux, or NetWare FTP server.
"
You need to know the web address and port number of the FTP server.
"
Make sure you have user accounts with the appropriate credentials, see Download and replication credentials on page 93.
"
If managed computers connect to repositories through a firewall, ensure that the repository accepts inbound communication on the appropriate communication port. Typically, this is port 20 or 21.
To create distributed repositories on FTP servers:
For option definitions, click Help or
96
in the interface.
1
From the Server section, click the Repository tab.
2
Click Add Repository under Management Tasks.
ProtectionPilot ™ software version 1.0
Creating distributed repositories using UNC shares
3
Select FTP, then click Next under Management Tasks.
Figure A-4. Manage AutoUpdate Repositories — FTP Options page 4
Type the web address of the FTP server in URL.
5
Type the port number that the FTP server uses for communication (typically, this is port 20 or 21) in Port.
6
Type a descriptive and unique name for the repository in Repository name.
7
Under Download Credentials, select Use Anonymous or type the user account information in User name, Password, and Re-enter password. To authenticate the user account you specified, click Verify.
8
Under Replication Credentials, type the user account information in User name, Password, and Re-enter password . To authenticate the user account you specified, click Verify.
9
Click Apply Settings under Management Tasks.
Creating distributed repositories using UNC shares Before you begin "
Verify that the computer uses Windows, Linux, NetWare, or UNIX Samba UNC shares.
"
You need to know a network directory to store the repository.
Product Guide
97
Managing AutoUpdate Repositories
"
Make sure you have user accounts with the appropriate credentials, see Download and replication credentials on page 93.
"
If managed computers connect to repositories through a firewall, ensure that the repository accepts inbound communication on the appropriate communication port. Typically, this is port 137, 138, or 139.
To create distributed repositories using UNC shares:
For option definitions, click Help or
in the interface.
1
From the Server section, click the Repository tab.
2
Click Add Repository under Management Tasks.
3
Select UNC, then click Next under Management Tasks.
Figure A-5. Manage AutoUpdate Repositories — UNC Options page 4
Type the network directory where you want to store the repository in Share path. Use this format: \\<COMPUTER>\<FOLDER>. You can also use predefined or system environment variables to define this location. For more information, see Variables in the Help file.
5
Type a descriptive and unique name for the repository in Repository name.
6
Under Download Credentials, select Use logged on user or type the user account information in Domain name, User name, Password, and Re-enter password . To authenticate the user account you specified, click Verify.
98
ProtectionPilot ™ software version 1.0
Modifying distributed repositories
7
Under Replication Credentials, type the user account information in Domain name, User name, Password, and Re-enter password. To authenticate the user account you specified, click Verify.
8
Click Apply Settings under Management Tasks.
Modifying distributed repositories For option definitions, click Help or
in the interface.
1
From the Server section, click the Repository tab.
2
Select a repository under Distributed Repositories, then click Edit.
Figure A-6. Manage AutoUpdate Repositories page 3
Make changes as needed.
4
Click Apply Settings under Management Tasks to save the current entries.
Removing distributed repositories from management When you remove distributed repositories from management, the contents of the repository remain. You need to manually delete the files from the computer. For option definitions, click Help or
in the interface.
1
From the Server section, click the Repository tab. The Manage AutoUpdate Repositories page appears.
2
Select a repository under Distributed Repositories, then click Delete.
Product Guide
99
Managing AutoUpdate Repositories
Replicating to distributed repositories immediately Although the Server Update task automatically copies the contents of the server repository to all distributed repositories, there are instances when you might want to perform this task on-demand. For example, when troubleshooting issues with product compliance, you might perform an on-demand replication to ensure that all distributed repositories have the same updates as the server repository before updating computers. For option definitions, click Help or
in the interface.
1
From the Server section, click the Repository tab. The Manage AutoUpdate Repositories page appears.
2
Select repositories under Distributed Repositories, then click Replicate.
Figure A-7. Manage AutoUpdate Repositories page 3
Select whether to perform an incremental (copy only new or updated files) or a full replication (copy all files), then click Finish .
Figure A-8. Replicate Wizard
100
ProtectionPilot ™ software version 1.0
Adding proxy settings for managed computers
Adding proxy settings for managed computers If managed computers connect to AutoUpdate repositories via a proxy server, you need to add these settings before updates can be retrieved.You can use the proxy settings in Internet Explorer or specify custom proxy settings. "
Using the proxy settings in Internet Explorer for managed computers.
"
Defining custom proxy settings for managed computers.
Using the proxy settings in Internet Explorer for managed computers For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Policies tab.
3
Click ProtectionPilot Agent to open the Policy Settings dialog box.
4
On the Proxy tab, deselect Inherit.
Figure A-9. Proxy tab in the ProtectionPilot Agent policy page 5
Select Use Internet Explorer Proxy Settings.
6
Provide a user account with permissions to the proxy server specified in Internet Explorer. a
Select Use authentication for HTTP, Use authentication for FTP, or both.
b
In the user name, password, and confirm password boxes that correspond to the desired protocol, type the user name and password associated with the user account.
Product Guide
101
Managing AutoUpdate Repositories
7
Click Apply All to save the current entries.
8
Click Close to return to the Policies page.
Defining custom proxy settings for managed computers For option definitions, click Help or
in the interface.
1
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click the Policies tab.
3
Click ProtectionPilot Agent to open the Policy Settings dialog box.
4
On the Proxy tab, deselect Inherit.
Figure A-10. Proxy tab in the ProtectionPilot Agent policy page
102
5
Select Manually configure the proxy settings.
6
Provide the address and port number of the proxy server you want to use to gain access to distributed repositories using HTTP or FTP protocols. a
In Address, type the IP address or fully-qualified domain name of the proxy server.
b
In Port, type the port number of the proxy server.
c
To use the same Address and Port for both HTTP or FTP protocols, select Use these settings for all proxy types.
ProtectionPilot ™ software version 1.0
Adding proxy settings for managed computers
7
Provide a user account with permissions to the proxy server you specified in HTTP or FTP in Step 6. a
Select Use authentication for HTTP, Use authentication for FTP, or both.
b
In the user name, password, and confirm password boxes that correspond to the desired protocol, type the user name and password associated with the user account.
8
To specify managed computers that connect directly to AutoUpdate repositories bypassing the proxy server, select Specify exceptions, then type the IP addresses or fully-qualified domain name of those computers separated by a semi-colon (;).
9
Click Apply All to save the current entries.
10 Click Close to return to the Policies page.
Product Guide
103
Managing AutoUpdate Repositories
104
ProtectionPilot ™ software version 1.0
B
Receiving Notification of Incidents
You can be notified whenever McAfee anti-virus products detect activity categorized at a certain priority level, such as critical or high. You pick the notification method that is most convenient and timely for you. Notification methods include e-mail messages, pager text messages, print-outs, network popup messages, a program triggered when possible infections are detected, or entries written to a log file. You can set up multiple levels of notification as well. For example, you might want to receive a page for critical alert messages and save low priority messages to a log file. This section covers these tasks for setting up the default alerting method: "
Setting up the Alert Manager server.
"
Sending notifications of alert messages.
"
Sending alert messages to the Alert Manager server.
The Help file covers these tasks for setting up centralized alerting: "
Setting up the Alert Manager server.
"
Setting up a centralized alerting location.
"
Sending notifications of alert messages.
"
Sending alert messages to a centralized alerting location.
Product Guide
105
Receiving Notification of Incidents
Setting up the Alert Manager server The computer that is acting as the Alert Manager server must have VirusScan Enterprise 7.0 or later installed on it. Be sure that the computer that is hosting the Alert Manager server is equipped to send the type of notifications that you want to receive. We recommend setting up the Alert Manager server on a different computer than the ProtectionPilot server, to avoid impacting ProtectionPilot server performance during an outbreak. When to use a centralized alerting location
If you block named pipe connections on your network, you need to forward alert messages to a central location instead of directly to the Alert Manager server. The Alert Manager server periodically retrieves alert messages from this central location, then sends the appropriate notifications to you. For instructions, see Setting up a centralized alerting location in the Help file. Alert messages and mobile (unconnected) computers
Because alert messages are not written to a file, they can only be sent during the session in which they are generated (i.e., they are deleted once the computer is turned off), and then only if the computer is connected to the network. To deploy the Alert Manager software:
106
1
Add the Alert Manager 4.7 package (PKGCATALOG.Z) file to the server repository. For instructions, see Adding products to the server repository on page 35.
2
In the tree pane under McAfee ProtectionPilot | All Computers, select the computer that is hosting the Alert Manager server from its group.
3
Click Deploy under Management Tasks.
4
Click Next in the Deploy Products Wizard.
ProtectionPilot ™ software version 1.0
Sending notifications of alert messages
5
Select Alert Manager 4.7.0, click Next, then Finish.
Figure B-1. Deploy Products Wizard — Select products to deploy
Sending notifications of alert messages This section covers the most common method for sending notifications of alert messages: "
Sending notifications as text messages via e-mail or pagers.
The Help file covers these additional tasks for sending notifications of alert messages: "
Sending notifications as network messages.
"
Sending notifications to a printer.
"
Sending notifications via SNMP.
"
Launching a program in response to detections.
"
Logging alert messages in event log files.
"
Sending notifications to a Terminal Server as network messages.
Product Guide
107
Receiving Notification of Incidents
Sending notifications as text messages via e-mail or pagers You can send notifications of alert messages via e-mail or as text messages on pagers. How fast recipients receive these text messages depends on the response time of the sending and receiving mail servers. 1
In the tree pane under McAfee ProtectionPilot | All Computers, select the computer that is hosting the Alert Manager server from its group.
2
Click the Policies tab.
3
Click Alert Manager 4.7 to open the Policy Settings dialog box.
4
Click the E-mail tab.
5
Deselect Inherit.
Figure B-2. E-Mail tab in the Alert Manager policy page 6
Click Add, then type the recipient’s e-mail address, a message subject, and a reply e-mail address, such as your own.
Figure B-3. E-Mail dialog box
108
ProtectionPilot ™ software version 1.0
Sending alert messages to the Alert Manager server
7
Click Mail Settings, then in Server, type the IP address or computer name of an SMTP mail server. If the mail server requires it – and only if – type its password in Login, then click OK.
Figure B-4. E-Mail Settings dialog box 8
Click Priority Level, then drag the slider to indicate the priority level of alert messages. Messages with the selected priority and higher will generate this type of notification.
Figure B-5. Priority Level dialog box 9
Click OK twice, then click Apply to save the current entries.
10 Click Close to return to the Policies page.
Sending alert messages to the Alert Manager server We recommend that you configure each managed computer to forward their alert messages to the Alert Manager server. In turn, the Alert Manager server sends the appropriate notifications to you. The Alert Manager client-side software is installed by default with these McAfee Security products: "
VirusScan 4.5.1.
"
VirusScan Enterprise 7.0 or later.
"
NetShield for NetWare 4.6.
Product Guide
109
Receiving Notification of Incidents
To forward alert messages, you must define the location of the Alert Manager server for each managed product: "
Sending alert messages from VirusScan 4.5.1.
"
Sending alert messages from VirusScan Enterprise 7.0 or 7.1.
"
Sending alert messages from NetShield 4.6 for NetWare.
Sending alert messages from VirusScan 4.5.1 1
In the tree pane under McAfee ProtectionPilot | All Computers, select a group of computers or an individual computer running VirusScan 4.5.1.
2
Click the Policies tab.
3
Click VirusScan v4.51 for Windows to open the Policy Settings dialog box.
4
Select Alert Options in Select policy categories.
5
Deselect Inherit.
Figure B-6. VirusScan 4.5.1 Alert Options policy page
110
6
Deselect Disable Alerting.
7
To permit users to change these policy settings, select Allow User Changes.
8
Deselect Use DMI ; Desktop Management Interface (DMI) messaging is no longer supported on the server side.
9
Select Enable Alert Manager Alerting.
ProtectionPilot ™ software version 1.0
Sending alert messages to the Alert Manager server 10 For more information on publishing the Alert Manager server to Active
Directory, see the Alert Manager 4.7 product documentation. 11 Type the name of the Alert Manager server in Destination for alerts, using UNC
notation; for example, \\<COMPUTER>. 12 Click Apply to save the current entries. 13 Click Close to return to the Policies page.
Sending alert messages from VirusScan Enterprise 7.0 or 7.1 1
In the tree pane under McAfee ProtectionPilot | All Computers, select a group of computers or an individual computer running VirusScan Enterprise 7.0 or 7.1.
2
Click the Policies tab.
3
Click VirusScan Enterprise <VERSION> (where <VERSION> is 7.0 or 7.1) to open the Policy Settings dialog box.
4
Select Alert Manager Alerts Policies in Select policy categories.
5
Deselect Inherit.
Figure B-7. VirusScan Enterprise 7.1 Alert Manager Alerts policy page 6
Under Which components will generate alerts, select the client-side components from which you want alert messages forwarded:
#
On-Access Scan — Forwards alert messages found by the On-Access Scan
task.
#
On-Demand Scan and scheduled scans — Forwards alert messages found by the On-Demand Scan task and scheduled scan tasks.
Product Guide
111
Receiving Notification of Incidents
#
E-Mail Scan — Forwards alert messages found by the on-delivery and on-demand E-Mail Scan tasks.
#
AutoUpdate — Forwards alert messages found by the AutoUpdate task, Update Now task, and scheduled update tasks.
7
Under Alert Manager destination selection, select Enable Alert Manager alerting.
8
Type the name of the Alert Manager server in Specify Alert Manager server to receive alerts, using UNC notation; for example, \\<COMPUTER>.
9
Click Apply to save the current entries.
10 Click Close to return to the Policies page.
Sending alert messages from NetShield 4.6 for NetWare 1
In the tree pane under McAfee ProtectionPilot | All Computers, select a group of computers or an individual computer running NetShield 4.6 for NetWare.
2
Click the Policies tab.
3
Click NetShield for NetWare v4.6 to open the Policy Settings dialog box.
4
Select Alert Properties in Select policy categories.
5
Deselect Inherit.
6
Under Centralized alerting, deselect Enable centralized alerting.
7
Under Advanced alerting, select Use alert manager.
8
Click Apply to save the current entries.
9
Select Alert Manager in Select policy categories.
10 Click the Forward tab. 11 Deselect Inherit. 12 Click Add , then in Computer, type the name of the Alert Manager server, using UNC notation; for example, \\<COMPUTER>.
13 Select the priority level of alert messages that you want forwarded in Priority
Level. Messages with the selected priority and higher will be forwarded to the
Alert Manager server. NOTE
We recommend setting the priority level to Informational, so that all alert messages are forwarded to the Alert Manager server. This ensures that this setting does not conflict with the priority level setting on the Alert Manager server.
112
ProtectionPilot ™ software version 1.0
Sending alert messages to the Alert Manager server 14 Click Apply to save the current entries. 15 Click Close to return to the Policies page.
Product Guide
113
Receiving Notification of Incidents
114
ProtectionPilot ™ software version 1.0
C
Managing NetShield for NetWare The management of NetShield 4.6 for NetWare differs from that of other supported McAfee Security products. 1
Installing the agent for NetWare — You must install the agent for NetWare manually. This is required to put computers running NetShield 4.6 for NetWare under management. For a list of system requirements, see Agent for NetWare requirements in the Help file. For instructions on installing the agent for NetWare, see the NetShield 4.6 for NetWare product documentation.
2
Changing agent for NetWare settings — You can change the policy settings for the agent for NetWare using the ProtectionPilot console. For instructions, see Changing agent for NetWare policy settings in the Help file.
3
Installing NetShield for NetWare — Installing NetShield for NetWare is a manual process. For a list of system requirements, see NetShield 4.6 for NetWare, server requirements and NetWare administrator computer requirements in the Help file. For instructions on installing the NetShield for NetWare, see the NetShield 4.6 for NetWare product documentation.
4
Changing NetShield for NetWare settings — You can change the policy settings for NetShield for NetWare using the ProtectionPilot console. For instructions, see Changing managed product policy settings on page 51. For information about each option, see the NetShield 4.6 for NetWare product documentation.
5
Upgrading NetShield for NetWare — Upgrading the software with service pack and patch releases is a manual process. For instructions, see the NetShield 4.6 for NetWare product documentation.
6
Updating NetShield for NetWare — You can update the NetShield 4.6 for NetWare software by scheduling the appropriate client tasks. For instructions, see Performing scheduled DAT updates (NetShield for NetWare) and Performing scheduled engine updates (NetShield for NetWare) in the Help file.
7
Scanning NetShield for NetWare computers for possible infections — You can scan computers running the NetShield 4.6 for NetWare software for possible infections by scheduling the appropriate client tasks. For instructions, see Performing scheduled scans on page 56.
Product Guide
115
Managing NetShield for NetWare
116
ProtectionPilot ™ software version 1.0
Index A
alert messages (centralized alerting) sending from NetShield 4.6 for NetWare (See the Help file) sending from VirusScan 4.5.1 (See the Help file)
agent changing settings, defined, 16
50
installing manually,
34
installing via Terminal Services (See the Help file) making user interface accessible from managed computers, 50 restoring default settings, 52 system requirements (See the Help file) testing connectivity,
saving to a file,
sending alert messages to a centralized alerting location (See the Help file) sending alert messages to the Alert Manager server, 109 sending notifications of alert messages,
72
setting up the Alert Manager server,
76
ASCI, defined ,
7
installing (See the NetShield 4.6 for NetWare product documentation)
creating on FTP servers, 96 creating on HTTP servers, 94
system requirements (See the Help file)
creating on non-dedicated computers,
agent installation log files printing, 76
creating using UNC shares, download credentials, 93 76
modifying,
76
alert messages mobile computers,
99
replication credentials,
agent-to-server communication interval (See ASCI) 106
sending from NetShield 4.6 for NetWare, sending from VirusScan 4.5.1, 110 sending from VirusScan Enterprise 7.0 or 7.1 , 111
112
93
97
removing from management, replicating to, 100
agent repositories (See AutoUpdate repositories, creating on non-dedicated computers) agent system tray icon, defined, 50
106
51
audience for this manual, AutoUpdate repositories
changing settings (See the Help file)
saving to a file, viewing, 76
106
when to use a centralized alerting location, Anti-Virus Emergency Response Team (See AVERT), 10
76
viewing, 76 agent for NetWare
refreshing contents,
107
setting up a centralized alerting location (See the Help file)
uninstalling, 46 to 47 agent activity log files printing, 76 refreshing contents,
sending from VirusScan Enterprise 7.0 or 7.1 (See the Help file) alerting
99
93
specifying selection order (See the Help file) system requirements for FTP servers, 96 system requirements for HTTP servers, system requirements for non-dedicated computers, 93 system requirements for UNC shares, when to use, AVERT
94
97
92
DAT notification service,
10
Product Guide
117
Index
submitting potentially infected files, Virus Information Library, web site, 10
connecting via Terminal Services (See the Help file)
10
10
defined, 13 system requirements (See the Help file) user interface, 14 contacting McAfee Security,
B beta program, contacting,
10
10
conventions used in this manual, customer service, contacting,
C cleaned / blocked detection category, defined,
20
client tasks DAT updates for NetShield for NetWare (See the Help file) DAT updates for VirusScan,
deleting user-defined, 60 engine updates for NetShield for NetWare (See the Help file) engine updates for VirusScan, 54 modifying default on-demand scan, modifying user-defined, scheduled scans, client tasks log files printing,
58
59
immediate update from Network Associates , 40 immediate update from the server repository, 40
76
communication ports, changing,
88
version number,
35
database backing up (See the Help file)
46
defined,
putting under management automatically,
24
putting under management manually, 34 removing a group from management, 47 removing from management,
19
viewing update history, 78 web site for updates, 10
computers
moving to another group, organizing, 44
10
updating manually (See the Help file) updating using SuperDAT packages (See the Help file)
compliance (See up-to-dateness) compliance categories, defined, 20 adding from system image, deleting, 46 to 47
21
scheduled updates for NetShield for NetWare (See the Help file) scheduled updates for VirusScan, 54
viewing, 76 common image (See system image)
77
viewing update history, 78 configuration settings (See policy settings) console ProtectionPilot ™ software version 1.0
15
maintenance settings (See the Help file) restoring (See the Help file) system requirements (See the Help file) default policy settings, restoring, 52 deleted detection category, defined, 20
46
taking action on non-compliant computers, testing connectivity, 72
118
41
17
downgrading (See the Help file) forcing immediate update, 40
notification service,
76
viewing properties,
DAT files changing update frequency,
latest retrieved from Network Associates, learning about new, 21
56
refreshing contents, saving to a file, 76
10
D default updating setup,
54
8
72
deployment, definition,
35
detection categories, defined, 20 detection reports, printing, 69 detections impacted files,
64
Index
learning about,
updating using SuperDAT packages (See the Help file)
67
listing, 63 printing, 69 reported on computers,
version number, 19 viewing update history,
62
78
web site for updates, 10 error (failed) detection category, defined ,
viewing history, 65 distributed repositories (See AutoUpdate repositories)
20
existing products, putting under management ,
documentation for the product, 9 domain membership, organizing computers by,
44
download credentials for AutoUpdate repositories, 93
29
existing update locations, post-installation, 17 EXTRA.DAT files, updating (See the Help file)
F
download web site, 10 downloading updates
FrameSvc log files (See agent installation log files)
changing frequency, 41 DAT notification service,
10
getting information,
default updating setup,
17
groups creating,
44
defined,
44
G
forcing immediately, 40 immediate update from Network Associates , 40 latest retrieved from Network Associates, learning about new updates, 21
7, 9
deleting, 47 moving computers between,
21
46
manually (See the Help file)
putting a group of computers under management automatically, 24
scheduled updates for NetShield for NetWare (See the Help file) scheduled updates for VirusScan, 54
removing a group of computers from management, 47
updating using SuperDAT packages (See the Help file) web site
E
renaming,
46
H history, viewing for updates ,
78
I
engine changing update frequency, default updating setup, 17
41
forcing immediate update,
40
IP address organizing computers by, IP settings adding (See the Help file)
immediate update from Network Associates , 40 immediate update from the server repository, 40 latest retrieved from Network Associates, learning about new, 21
44
sorting computers by (See the Help file)
deleting (See the Help file) modifying (See the Help file) verifying integrity (See the Help file)
21
scheduled updates for NetShield for NetWare (See the Help file) scheduled updates for VirusScan, 54
K
updating manually (See the Help file)
L
KnowledgeBase search,
local database, defined ,
10
15
Product Guide
119
Index
modifying default on-demand scan client tasks , 58
log files agent activity, 76 agent installation, 76 client tasks,
scheduling, 56 out-of-date compliance category
76
defined, 20 taking action on non-compliant computers,
server log, 89 updating activity (See the Help file) logical groupings, organizing computers using, Lost&Found moving computers from,
44
P package file, definition,
46
35
password, changing on the server, managed computers (See computers)
upgrading,
managed products (See products) management, defined, 11 manuals,
10
pending compliance category, defined ,
N
PKGCATALOG.Z file, definition, policies (See policy settings)
NaPrdMgr log files (See client tasks log files) NetShield for NetWare
policy enforcement interval, defined, policy settings
installing (See the NetShield 4.6 for NetWare product documentation) managing, 115
agent settings defined,
upgrading (See the NetShield 4.6 for NetWare product documentation) Norton (See Symantec AntiVirus) not communicating compliance category changing the definition, 86 72
e-mail messages, 108 launching programs (See the Help file) logging to a file (See the Help file) network messages (See the Help file) network messages on Terminal Services (See the Help file) pager text messages,
108
print-outs (See the Help file) SNMP (See the Help file)
on-demand scanning
120
50
changing product,
51
defined, 49 product settings defined (See the McAfee Security product documentation)
product compliance (See up-to-dateness) product documentation, 9 product training, contacting,
10
products adding to the server repository, changing settings, 51
ProtectionPilot ™ software version 1.0
35
deploying to new computers, 24 handling restarts required for installations, keeping up-to-date,
51
37
list of supported, 117 policy settings defined (See the McAfee Security product documentation) putting existing products under management, 29
O
50
restoring defaults PrimeSupport, 10
20
taking action on non-compliant computers, notifications of alert messages
20
35
changing agent, 50 changing agent for NetWare (See the Help file)
system requirements (See the Help file)
defined,
54
38
upgrading NetShield for NetWare (See the NetShield 4.6 for NetWare product documentation) , 115
9
McAfee Security University, contacting,
87
patch releases scheduled updates for VirusScan,
M
72
Index
restoring default settings, upgrading, 38 version number,
52
19
viewing properties,
77
77
ProtectionPilot, defined, 11 proxy settings for managed computers adding, 101 defining custom settings,
adding,
server events (See server log file), server log file
89
102
modifying the size,
90
printing, 89 refreshing contents,
89
saving to a file,
101
89
viewing, 89 server repository
84
adding products, 35 viewing contents, 19
using settings in Internet Explorer,
84
service pack releases scheduled updates for VirusScan, upgrading, 38
18
Q quarantine detection category, defined,
20
R remote console, defined,
89
89
defining custom settings, 85 removing (See the Help file) when needed,
changing the name, defined, 12
server activity (See server log file),
removing (See the Help file) using settings in Internet Explorer, proxy settings for the server
87
managing via Terminal Services (See the Help file) system requirements (See the Help file)
viewing update history, 78 program, starting after an update (See the Help file) properties, viewing computer and product,
changing password,
13
remote console, system requirements (See the Help file) remote database, defined, 15
upgrading NetShield for NetWare (See the NetShield 4.6 for NetWare product documentation) , 115 service portal, PrimeSupport, 10 supplemental virus definition files (See EXTRA.DAT files) supported products, list of , 117 Symantec AntiVirus, replacing with VirusScan (See the Help file)
replication credentials for AutoUpdate repositories, 93
system image, adding computers from, system requirements (See the Help file)
repositories (See AutoUpdate repositories) restore inheritance (See default policy settings)
T technical support,
S scanning computers immediately, 68 modifying default on-demand scan client tasks , 58 scheduling,
54
35
10
Terminal Services, system requirements (See the Help file) threats, learning about new , 21 training web site ,
10
tree pane, defined ,
14
56
scanning engine (See engine) section, defined, 14
U updates
security headquarters (See AVERT), server
10
changing communication ports,
88
changing update frequency, DAT notification service,
41
10
Product Guide
121
Index
default updating setup,
17
downgrading DAT files (See the Help file) forcing immediate, 40 immediate update from Network Associates , 40 immediate update from the server repository, 40 latest retrieved from Network Associates,
21
learning about new, 21 scheduled updates for NetShield for NetWare (See the Help file) scheduled updates for VirusScan, 54 updating manually (See the Help file) updating using SuperDAT packages (See the Help file) viewing history, 78 web site updating activity log files, creating (See the Help file) upgrade web site, 10 upgrades scheduled updates for VirusScan, upgrading immediately, 38
54
upgrading NetShield for NetWare (See the NetShield 4.6 for NetWare product documentation) , 115 up-to-date compliance category, defined, 20 up-to-dateness, defined,
18
user interface, defined,
14
V variables, defined (See the Help file) version numbers, viewing,
19
Virus Information Library, 10 VirusScan 4.5.1, system requirements (See the Help file) VirusScan Enterprise 7.1, system requirements (See the Help file) VirusScan system tray icon disappeared after an upgrade, 26 virus-scanning engine (See engine)
W workgroup membership, organizing computers by, 44
122
ProtectionPilot ™ software version 1.0