Skip to main content

prp_10_eval_guide_en

Page 1

Evaluation Guide Revision 1.0

ProtectionPilot

™

Maximum Protection. Simple Administration. version 1.0


COPYRIGHT Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved. No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or by any means without the written permission of Networks Associates Technology, Inc., or its suppliers or affiliate companies. To obtain this permission, write to the attention of the Network Associates legal department at: 5000 Headquarters Drive, Plano, Texas 75024, or call +1-972-963-8000. TRADEMARK ATTRIBUTIONS Active Firewall, Active Security, Active Security (in Katakana), ActiveHelp, ActiveShield, AntiVirus Anyware and design, Appera, AVERT, Bomb Shelter, Certified Network Expert, Clean-Up, CleanUp Wizard, ClickNet, CNX, CNX Certification Certified Network Expert and design, Covert, Design (stylized N), Disk Minder, Distributed Sniffer System, Distributed Sniffer System (in Katakana), Dr Solomon’s, Dr Solomon’s label, E and Design, Entercept, Enterprise SecureCast, Enterprise SecureCast (in Katakana), ePolicy Orchestrator, Event Orchestrator (in Katakana), EZ SetUp, First Aid, ForceField, GMT, GroupShield, GroupShield (in Katakana), Guard Dog, HelpDesk, HelpDesk IQ, HomeGuard, Hunter, Impermia, InfiniStream, Intrusion Prevention Through Innovation, IntruShield, IntruVert Networks, LANGuru, LANGuru (in Katakana), M and design, Magic Solutions, Magic Solutions (in Katakana), Magic University, MagicSpy, MagicTree, McAfee, McAfee (in Katakana), McAfee and design, McAfee.com, MultiMedia Cloaking, NA Network Associates, Net Tools, Net Tools (in Katakana), NetAsyst, NetCrypto, NetOctopus, NetScan, NetShield, NetStalker, Network Associates, Network Performance Orchestrator, NetXray, NotesGuard, nPO, Nuts & Bolts, Oil Change, PC Medic, PCNotary, PortalShield, Powered by SpamAssassin, PrimeSupport, Recoverkey, Recoverkey – International, Registry Wizard, Remote Desktop, ReportMagic, RingFence, Router PM, Safe & Sound, SalesMagic, SecureCast, SecureSelect, SecurityShield, Service Level Manager, ServiceMagic, SmartDesk, Sniffer, Sniffer (in Hangul), SpamKiller, SpamAssassin, Stalker, SupportMagic, ThreatScan, TIS, TMEG, Total Network Security, Total Network Visibility, Total Network Visibility (in Katakana), Total Service Desk, Total Virus Defense, Trusted Mail, UnInstaller, VIDS, Virex, Virus Forum, ViruScan, VirusScan, WebScan, WebShield, WebShield (in Katakana), WebSniffer, WebStalker, WebWall, What's The State Of Your IDS?, Who’s Watching Your Network, WinGauge, Your E-Business Defender, ZAC 2000, Zip Manager are registered trademarks or trademarks of Network Associates, Inc. and/or its affiliates in the US and/or other countries. Sniffer® brand products are made only by Network Associates, Inc. All other registered and unregistered trademarks herein are the sole property of their respective owners. LICENSE INFORMATION License Agreement NOTICE TO ALL USERS: CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE LICENSE YOU PURCHASED, WHICH SETS FORTH THE GENERAL TERMS AND CONDITIONS FOR THE USE OF THE LICENSED SOFTWARE. IF YOU DO NOT KNOW WHICH TYPE OF LICENSE YOU HAVE ACQUIRED, PLEASE CONSULT THE SALES AND OTHER RELATED LICENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANIES YOUR SOFTWARE PACKAGING OR THAT YOU HAVE RECEIVED SEPARATELY AS PART OF THE PURCHASE (AS A BOOKLET, A FILE ON THE PRODUCT CD, OR A FILE AVAILABLE ON THE WEB SITE FROM WHICH YOU DOWNLOADED THE SOFTWARE PACKAGE). IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT, DO NOT INSTALL THE SOFTWARE. IF APPLICABLE, YOU MAY RETURN THE PRODUCT TO NETWORK ASSOCIATES OR THE PLACE OF PURCHASE FOR A FULL REFUND.

Attributions This product includes or may include: ! Software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/).

! Cryptographic software written by Eric A. Young and software written by Tim J. Hudson. ! Some software programs that are licensed (or sublicensed) to the user under the GNU General Public License (GPL) or other similar Free Software licenses which, among other

rights, permit the user to copy, modify and redistribute certain programs, or portions thereof, and have access to the source code. The GPL requires that for any software covered under the GPL which is distributed to someone in an executable binary format, that the source code also be made available to those users. For any such software covered under the GPL, the source code is made available on this CD. If any Free Software licenses require that Network Associates provide rights to use, copy or modify a software program that are broader than the rights granted in this agreement, then such rights shall take precedence over the rights and restrictions herein. Software originally written by Henry Spencer, Copyright 1992, 1993, 1994, 1997 Henry Spencer.

! ! Software originally written by Robert Nordier, Copyright © 1996-7 Robert Nordier. All rights reserved. ! Software written by Douglas W. Sauder. ! Software developed by the Apache Software Foundation (http://www.apache.org/). ! International Components for Unicode (“ICU”) Copyright © 1995-2002 International Business Machines Corporation and others. All rights reserved. ! Software developed by CrystalClear Software, Inc., Copyright © 2000 CrystalClear Software, Inc. ! FEAD® Optimizer® technology, Copyright Netopsystems AG, Berlin, Germany. ! Outside In® Viewer Technology © 1992-2001 Stellent Chicago, Inc. and/or Outside In® HTML Export, © 2001 Stellent Chicago, Inc. ! Software copyrighted by Thai Open Source Software Center Ltd. and Clark Cooper, © 1998, 1999, 2000. ! Software copyrighted by Expat maintainers. ! Software copyrighted by The Regents of the University of California, © 1989. ! Software copyrighted by Gunnar Ritter. ! Software copyrighted by Sun Microsystems®, Inc. ! Software copyrighted by Gisle Aas. All rights reserved, © 1995-2003. ! Software copyrighted by Michael A. Chase, © 1999-2000. ! Software copyrighted by Neil Winton, © 1995-1996. ! Software copyrighted by RSA Data Security, Inc., © 1990-1992. ! Software copyrighted by Sean M. Burke, © 1999, 2000. ! Software copyrighted by Martijn Koster, © 1995. ! Software copyrighted by Brad Appleton, © 1996-1999. ! Software copyrighted by Michael G. Schwern, © 2001. ! Software copyrighted by Graham Barr, © 1998. ! Software copyrighted by Larry Wall and Clark Cooper, © 1998-2000. ! Software copyrighted by Frodo Looijaard, © 1997. PATENT INFORMATION Protected by US Patents 6,470,384; 6,493,756; 6,496,875; 6,553,377; 6,553,378.

Issued March 2004 / ProtectionPilot™ software version 1.0 DBN 008-EN


Contents 1 Company and Product Overview . . . . . . . . . . . . . . . . . . . . . . . . . . 5 About Network Associates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 Introducing ProtectionPilot . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 Automatic updating . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 Interactive Security Dashboard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 Automatic protection enforcement . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Do it now! Management Task menu . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Centralized deployment and management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Mobile user flexibility . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Fail-over updating . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Bandwidth-friendly . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 Guided installation and management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8

2 Evaluating the ProtectionPilot Software . . . . . . . . . . . . . . . . . . . . 9 Setting up your test environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 System requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 Installing the software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 Deploying the VirusScan software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 Seeing your coverage at-a-glance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 Investigating detections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 Creating sample detections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 Viewing the reported sample detections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 Resolving compliance issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 Simulating a compliance issue . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 Collecting updated product properties . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 Viewing and resolving the compliance issue . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 Responding to a suspected outbreak . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 Updating DAT files immediately . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 Scanning for possible infections immediately . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 Changing a VirusScan Enterprise policy setting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Managing computers remotely . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Checking computer and agent connectivity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33

Evaluation Guide

iii


Contents

Viewing agent log files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 Viewing computer properties . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 Viewing product properties . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 Additional areas to explore . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36

iv

ProtectionPilot™ software version 1.0


1

Company and Product Overview About Network Associates

With headquarters in Santa Clara, California, Network Associates, Inc. creates best-of-breed computer security solutions that prevent intrusions on networks and protect computer systems from the next generation of blended attacks and threats. With two families of products – McAfee System Protection Solutions: securing desktops and servers and McAfee Network Protection Solutions: ensuring the protection and performance of the corporate network – Network Associates offers computer security to large enterprises, governments, small- and medium-sized businesses, and consumers.

Introducing ProtectionPilot Designed for small and medium businesses, McAfee® ProtectionPilot™ software version 1.0 is a centralized tool that provides a simple, proactive approach to the deployment and ongoing management of virus protection. Central to the McAfee Security range of Small and Medium Business Edition solutions, the ProtectionPilot software guides you through the process of deploying, monitoring, and managing virus protection, keeping it in place and up-to-date. The installation wizard ensures the path to protection is simple and straightforward with automatic updates beginning immediately. Administrators can then easily monitor all systems for virus activity and update status from the interactive security dashboard – protection is automatically checked and updated, and any fine-tuning or configuration changes are simple via the easy-to-navigate task menu. Audience profile. Targeted for small and medium businesses with limited

Information Technology (IT) resources who want to manage their anti-virus protection in-house without requiring detailed security or anti-virus knowledge.

Evaluation Guide

5


Company and Product Overview

Automatic updating Maximum protection, effortless maintenance. ProtectionPilot keeps a constant vigil,

automatically checking with Network Associates for any new anti-virus or security updates on an hourly basis. These updates are then immediately deployed to all systems – no interaction is required by the administrator.

Network Associates web site

Internet

ProtectionPilot server computer (SERVER)

Managed Computer (WORKSTATION1)

Managed Computer (WORKSTATION2)

Figure 1-1. Default updating setup

Interactive Security Dashboard Real-time monitoring. Locating out-of-date systems and checking for virus

infections is effortless with the Interactive Security Dashboard. At the click of a button, you can easily view compliance and virus detection activity for all systems, groups, or individuals. More detailed information is obtained with the click-through capability of the dashboard. Critical information is easily viewed on the screen or is printable for later reference.

6

ProtectionPilot™ software version 1.0


Introducing ProtectionPilot

Automatic protection enforcement Automatic enforcement. ProtectionPilot is always at work, automatically enforcing

virus protection settings and policies on each system. In addition to regularly checking with the central server for any policy or setting changes, the ProtectionPilot agent also enforces compliance on each local system. When this interval comes around, the agent automatically checks the local system to ensure that the protection is correctly configured and installed. Automatic policy enforcement helps ensure the protection is effective and removes possible weak links, such as end users who might change settings or disable critical protection software.

Do it now! Management Task menu Take immediate action. Ongoing administration is made simple, quick and effective

with the “Do it now!” approach of the Management Task menu. Tasks, such as deploying protection, scanning for viruses, emergency updating, enforcing settings and policies, and checking the status of a system can all be performed immediately with the click of a button via the Management Task menu.

Centralized deployment and management Reduce administration time. Save time, effort and money with a centralized approach to managing virus protection. No more visiting each individual system or guessing whether protection is in place and working. ProtectionPilot offers a simple yet effective method of centrally managing virus protection. Deploy, update, view, control, and monitor – all from one central location. No more unnecessary visits to individual systems or branch offices.

Mobile user flexibility Manage the “unmanageables.” ProtectionPilot ensures that mobile users are as well

protected and easily managed as LAN-connected users. By enforcing policies even when the laptop is not connected to the network, and making updates happen whenever a connection to the Internet is sensed, ProtectionPilot effectively manages the “unmanageables.” And since the mobile user demands more flexibility, ProtectionPilot allows them to postpone and later resume updating at a more convenient time.

Fail-over updating Update contingency plan. ProtectionPilot offers a fail-over approach to updating.

Each system is instructed to look for update location alternatives if the first location is not available. This ultimately ends with the Network Associates web site, so your systems always have an available place to retrieve updates.

Evaluation Guide

7


Company and Product Overview

Bandwidth-friendly Get the most out of your bandwidth. ProtectionPilot operates from a central server to manage up to 500 users. It also uses an intelligent update design that allows the updating load to be distributed throughout the network or branch offices. Utilizing distributed repositories, customers can keep network traffic low and performance high. This includes updating for all McAfee Security virus definition (DAT) files, the virus-scanning engine, service pack releases, and patch releases.

Guided installation and management No security knowledge required. ProtectionPilot installation and management tasks

are all intelligently wizard-driven, taking the mystery out of deployment and ongoing management of virus protection. Following installation, protection is deployed and settings and policies implemented – domains are automatically recognized at initial installation, which makes locating and deploying to systems across the network simple and straightforward.

8

ProtectionPilot™ software version 1.0


2

Evaluating the ProtectionPilot Software

This guide demonstrates how to install the ProtectionPilot management software and deploy the VirusScan anti-virus software into your test environment. It gets you up and running quickly with ProtectionPilot, illustrates important product features, and provides a list of other areas of interest to explore on your own. The tasks listed below walk you through this evaluation of the ProtectionPilot software. The estimated time to complete the installation is also provided.

Installing ProtectionPilot 1

Setting up your test environment — Outlines the recommended test environment, including minimum software and hardware requirements.

2

Installing the software (~20 minutes) —You will be installing the ProtectionPilot

management software. 3

Deploying the VirusScan software (~10 minutes) — You will be creating two groups, then deploying (sending and installing) the VirusScan anti-virus software to your test computers after putting them under management.

Exercising the ProtectionPilot Features " Seeing your coverage at-a-glance — Highlights how ProtectionPilot answers your anti-virus protection questions, and points out the main user interface components of the software. "

Investigating detections —You will be creating sample infections, then viewing

the reported sample detections. "

Resolving compliance issues —You will be simulating an issue with product compliance, then taking steps to resolve it.

"

Responding to a suspected outbreak — Outlines how you can immediately update and scan all computers in response to a suspected outbreak.

"

Changing a VirusScan Enterprise policy setting — You will be enabling the policy setting to detect potentially unwanted and joke programs on both workstation test computers.

"

Managing computers remotely — Explains some of the basic tools provided by

ProtectionPilot for managing computers remotely. "

Additional areas to explore — Lists additional product features you can

explore.

Evaluation Guide

9


Evaluating the ProtectionPilot Software

Setting up your test environment For your test environment, we recommend that you use one server computer and two workstation computers, and that all of the test computers belong to the same domain or workgroup. Before you install the software, ensure that these test computers meet the minimum software and hardware requirements listed below.

System requirements Server and console requirements

Agent for Windows requirements

Browser — Microsoft Internet Explorer 6.0 or later.

Free disk space — 5MB.

File system — NTFS (NT file system) partition (recommended).

Network environment — Microsoft or Novell NetWare networks. NetWare networks require TCP/IP.

Free disk space — 250MB (minimum); 1GB (recommended).

Memory — 8MB RAM.

Operating system:

IP address — Static IP address (recommended).

#

Windows 95 with or without service packs.

Memory — 256MB RAM.

#

Windows 98 with or without service packs.

Monitor — 1024x768, 256-color, VGA monitor.

#

Windows 98 Second Edition (SE) with or without service packs.

#

Windows 2000 Advanced Server, Service Pack 3 or later.

Windows NT Server 4.0, Service Pack 4 or later.

#

Windows 2000 Professional, Service Pack 3 or later.

Windows NT Workstation 4.0, Service Pack 4 or later.

#

Windows Millennium Edition (Me) with or without service packs.

#

Windows 2000 Advanced Server, Service Pack 3 or later.

#

Windows 2000 Professional, Service Pack 3 or later.

#

Windows 2000 Server, Service Pack 3 or later.

#

Windows XP Professional, Service Pack 1 or later.

#

Windows Server 2003 Standard with or without service packs.

#

Windows Server 2003 Web with or without service packs.

Network environment — TCP/IP. Operating system: # # #

Windows 2000 Server, Service Pack 3 or later.

#

Windows XP Professional, Service Pack 1 or later.

#

Windows Server 2003 Standard with or without service packs.

Other — Internet connection (recommended). Processor — Intel Pentium II-class (or higher) compatible. Processor speed — 400MHz or higher.

Processor — Pentium-class or Celeron (or higher) compatible. Processor speed — 166MHz or higher. Continued on next page

10

ProtectionPilot™ software version 1.0


Setting up your test environment

Continued from previous page

Windows 95 — Computers using Windows 95A, Windows 95B, or Windows 95C must meet these additional requirements: #

VCREDIST.EXE, available at no charge from

Microsoft. At press time, this program and instructions for installation were available on the Microsoft web site: support.microsoft.com/directory/article.asp?ID =KB;EN-US;Q259403& NOTE

After you install VCREDIST.EXE, you must restart the computer. #

DCOM95 1.3, available at no charge from

Microsoft. At press time, this program and instructions for installation were available on the Microsoft web site: www.microsoft.com/com/dcom/dcom95/dcom1 _3.asp NOTE

After you install DCOM95 1.3, you must restart the computer. Windows 98 — Computers using Windows 98 must meet these additional requirements. Client computers using Windows 98 SE do not need this program installed on them. #

VCREDIST.EXE, available at no charge from Microsoft. At press time, this program and instructions for installation were available on the Microsoft web site:

VirusScan 4.5.1, Service Pack 1 requirements Browser — Internet Explorer 4.0.1 or later. Free disk space — 55MB. Memory — 16MB RAM. Operating system: #

Windows 95.

#

Windows 98.

#

Windows 98 SE.

#

Windows NT Workstation 4.0, Service Pack 4 or later.

#

Windows Me.

#

Windows 2000 Professional.

#

Windows XP Home (Fast user switching is not supported).

#

Windows XP Professional (Fast user switching is not supported).

Processor — Pentium-class or compatible; Pentium or Celeron (recommended). Processor speed — 166MHz or higher. Upgrade path — You can upgrade from McAfee VirusScan 4.0.3, 4.0.3a, or 4.5 to VirusScan 4.5.1. To upgrade from versions earlier than 4.0.3 or from VirusScan ThinClient (TC) 6.0, you must manually uninstall them before installing version 4.5.1.

support.microsoft.com/directory/article.asp?ID =KB;EN-US;Q259403& NOTE

After you install VCREDIST.EXE, you must restart the computer.

Evaluation Guide

11


Evaluating the ProtectionPilot Software

VirusScan Enterprise 7.1, server requirements

VirusScan Enterprise 7.1, workstation requirements

Browser — Internet Explorer 4.0 or later.

Browser — Internet Explorer 4.0 or later.

Free disk space — 20MB (complete installation) plus 25MB (temporary space needed for installation).

Free disk space — 20MB (complete installation) plus 25MB (temporary space during installation).

Memory — 32MB RAM. For information on optimal operating system performance, review the Microsoft guidelines for minimum RAM configuration. Operating system:

Memory — 32MB RAM. For information on optimal operating system performance, review the Microsoft guidelines for minimum RAM configuration. Operating system: #

Windows NT Workstation 4.0, Service Pack 6 or 6a.

Windows NT Enterprise Server 4.0, Service Pack 6 or 6a.

#

Windows 2000 Professional, Service Pack 1, 2, or 3.

#

Windows NT Terminal Server 4.0, Service Pack 6.

#

Windows XP Home, Service Pack 1.

#

Windows XP Professional, Service Pack 1.

#

Windows 2000 Server, Service Pack 1, 2, or 3.

#

Windows XP Tablet PC, Service Pack 1.

#

Windows 2000 Advanced Server, Service Pack 1, 2, or 3.

Processor — Intel or compatible; Pentium or Celeron (recommended).

#

Windows 2000 Datacenter Server, Service Pack 1, 2, or 3.

Processor speed — 166MHz or higher.

#

Windows Server 2003 Standard.

#

Windows Server 2003 Enterprise.

#

Windows Server 2003 Web.

#

Windows Server 2003 Datacenter.

#

Windows NT Server 4.0, Service Pack 6 or 6a.

#

Processor — Intel or compatible; Intel Pentium or Celeron (recommended). Processor speed — 166MHz or higher.

12

ProtectionPilot™ software version 1.0


Installing the software

Installing the software To install the software, you must be logged on to the server test computer as a local administrator or a member of the Administrators group. You might need to restart the computer once or twice during the installation. 1

If you don't already have installation media, download it from the Network Associates web site: http://www.networkassociates.com/us/downloads/evals/

2

Unzip the file to a temporary location on the server test computer; for example, C:\TEMP.

3

Click the Start button, then point to Run.

4

In Open, type the path where the Setup program (SETUP.EXE) is located (for example, C:\TEMP), then click OK.

5

In the McAfee ProtectionPilot 1.0.0 Setup wizard, click Next to begin the installation.

6

A dialog box appears identifying how long you are licensed to use the software. Click OK to continue to the license agreement.

7

In the Network Associates End User License Agreement dialog box, the license agreement always displays in English – regardless of your computer’s system language – and the license type options are disabled. Read the entire license agreement carefully, select I accept the terms in the license agreement to agree to the license terms, then click OK. NOTE

If the license agreement does not display correctly, read the appropriate license in the NETWORK_ASSOCIATES_LICENSE_ AGREEMENT.PDF file supplied with the software. 8

In the Installation Options dialog box, click Next to install the server and console to the default location (C:\PROGRAM FILES\NETWORK ASSOCIATES\PROTECTIONPILOT). NOTE

If a message appears stating that the server test computer doesn’t use a static IP address, you can ignore it and click OK. Using a static IP address on the ProtectionPilot server is only a recommendation. 9

In the Server Installation Options dialog box, type and confirm the password you want to use when starting the console, then click Next.

10 In the Select Database Server dialog box, click Next to install the free

MSDE 2000 database supplied with the software.

Evaluation Guide

13


Evaluating the ProtectionPilot Software 11 In the HTTP Configuration dialog box, click Next to accept the default port

numbers used for communication to and from the server. NOTE

When you click Next, the Setup program verifies whether any of these ports are already in use on this computer. If any port conflicts are found, we recommend incrementing the number by one until none are found. 12 In the Update DAT and Engine dialog box, click Next to retrieve the latest virus

definition (DAT) files and virus-scanning engine from Network Associates. NOTE

If the test server computer connects to the Internet via a proxy server, you need to add these settings before the automatic updating of virus definition (DAT) files and the virus-scanning engine can begin. For instructions, see Adding proxy settings for the server in the ProtectionPilot 1.0 Product Guide or Help file. 13 In the Ready To Install dialog box, click Install to begin the installation.

The Executing Setup dialog box appears and provides the status of the installation.

14

ProtectionPilot™ software version 1.0


Deploying the VirusScan software

Deploying the VirusScan software Define how to organize the test computers: 1 In the Welcome dialog box, click Next to begin. 2

In the Add Group Wizard, click Next.

3

In the Add Group Wizard — Specify group name, select Group name, type SERVER in the box, then click Next three times.

Figure 2-1. Creating the SERVER group 4

Answer Yes when asked Do you want to add more groups now?, then click Finish.

Evaluation Guide

15


Evaluating the ProtectionPilot Software

5

In the Add Group Wizard — Specify group name, select Group name, type WORKSTATION in the box, then click Next three times.

Figure 2-2. Creating the WORKSTATION group 6

Answer No when asked Do you want to add more groups now?, then click Finish. Groups appear in the console within – at the most – three minutes.

7

In the Add Computers Wizard, click Next.

8

In the Add Computers Wizard — Select computers to be managed, select the server test computer, so it appears in the right box, then click Next.

Figure 2-3. Selecting the server test computer

16

ProtectionPilot™ software version 1.0


Deploying the VirusScan software

9

In the Add Computers Wizard — Specify how the selected computers should be placed into groups, select In an existing group, select SERVER from the list, then click Next.

Figure 2-4. Putting the server test computer into the SERVER group

Deploy VirusScan to the server test computer: 1 In the Add Computers Wizard — Select products to deploy, select VirusScan Enterprise 7.1.0, then click Next.

Figure 2-5. Deploying VirusScan Enterprise 7.1.0 to the server test computer

Evaluation Guide

17


Evaluating the ProtectionPilot Software

Put the server test computer under management (deploy the agent): 1 In the Add Computers Wizard — Specify agent deployment options, select Push agent.

Figure 2-6. Putting the server test computer under management 2

Select Hide agent installation user interface for agent push to hide the user interface of the agent installation on the server test computer.

3

In Domain\User, type the credentials to use when installing the agent on the server test computer: If the computer is in a domain... Then, these permissions are needed...

Use this format in Domain\User...

Domain administrator (in that domain)

<DOMAIN>\<USER> Example: MAIN\ADMINISTRATOR

Local administrator (on the ProtectionPilot server)

.\<USER> Example: .\ADMINISTRATOR

If the computer is in a workgroup...

4

18

Then, these permissions are needed...

Use this format in Domain\User...

Local administrator (on the ProtectionPilot server)

.\<USER> Example: .\ADMINISTRATOR

Type the password of the user account you provided in Password.

ProtectionPilot™ software version 1.0


Deploying the VirusScan software

5

To save the agent package (FRAMEPKG.EXE) for manual installation, select Download agent, then click Browse to select a location. The agent must be manually installed on computers running supported versions of Windows 95, Windows 98, and Windows Me, and in Novell networks. For instructions, see Manually installing the agent in the ProtectionPilot 1.0 Product Guide or Help file.

6

Click Next twice.

7

Answer Yes when asked Do you want to add more computers now?, then click Finish. Computers appear in the console within – at the most – three minutes.

Evaluation Guide

19


Evaluating the ProtectionPilot Software

Define how to organize the workstation test computers: 1 In the Add Computers Wizard — Select computers to be managed, select the workstation test computers so they appear in the right box, then click Next.

Figure 2-7. Selecting the workstation test computers 2

In the Add Computers Wizard — Specify how the selected computers should be placed into groups, select In an existing group, select WORKSTATION from the list, then click Next.

Figure 2-8. Putting the workstation test computers into the WORKSTATION group

20

ProtectionPilot™ software version 1.0


Deploying the VirusScan software

Deploy VirusScan to the workstation test computers: 1 In the Add Computers Wizard — Select products to deploy, select both VirusScan 4.5.1 and VirusScan Enterprise 7.1.0, then click Next. VirusScan Enterprise 7.1.0 is installed on all computers except those using Windows 95, Windows 98, or Windows Me, on which VirusScan 4.5.1 is installed. VirusScan 4.5.1 is installed after the manual installation of agent. The agent is required to remotely manage products and it must be manually installed on computers running Windows 95, Windows 98, or Windows Me.

Figure 2-9. Deploying the VirusScan software to the workstation test computers

Evaluation Guide

21


Evaluating the ProtectionPilot Software

Put workstation test computers under management (deploy the agent): 1 To deploy the agent to computers running supported versions of Windows NT, Windows 2000, Windows XP, and Windows Server 2003, select Push agent in the Add Computers Wizard — Specify agent deployment options.

Figure 2-10. Putting the workstation test computers under management 2

Select Hide agent installation user interface for agent push to hide the user interface of the agent installation on the workstation test computers.

3

In Domain\User, type the credentials to use when installing the agent on the workstation test computers: If the computers are in a domain... Then, these permissions are needed...

Use this format in Domain\User...

Domain administrator (in that domain)

<DOMAIN>\<USER> Example: MAIN\ADMINISTRATOR

Local administrator (on those computers)

<COMPUTER>\<USER> Example: WORKSTATION1\ADMINISTRATOR

Local administrator (on the ProtectionPilot server)

22

ProtectionPilot™ software version 1.0

.\<USER> Example: .\ADMINISTRATOR


Deploying the VirusScan software

If the computers are in a workgroup... Then, these permissions are needed...

Use this format in Domain\User...

Local administrator (on those computers)

<COMPUTER>\<USER> Example: WORKSTATION1\ADMINISTRATOR

NOTE

We recommend setting up the same local administrator user account on all computers, so you can put all of the computers under management at once. Local administrator (on the ProtectionPilot server)

.\<USER> Example: .\ADMINISTRATOR

NOTE

The local administrator user accounts on the server and on each computer must be the same. 4

Type the password of the user account you provided in Password.

5

To save the agent package (FRAMEPKG.EXE) for manual installation, select Download agent, then click Browse to select a location. The agent must be manually installed on computers running supported versions of Windows 95, Windows 98, and Windows Me, and in Novell networks. For instructions, see Manually installing the agent in the ProtectionPilot 1.0 Product Guide or Help file.

6

Click Next twice.

7

Answer No when asked Do you want to add more computers now?, then click Finish. Computers appear in the console within – at the most – three minutes.

8

In the Installation Complete dialog box, click Finish. The console starts automatically.

9

On the McAfee ProtectionPilot page, type the server password, then click Submit.

10 A dialog box appears identifying how long you are licensed to use the

software. Click OK to continue.

Evaluation Guide

23


Evaluating the ProtectionPilot Software

Seeing your coverage at-a-glance What’s my current level of protection? It’s the DAT version and Engine version under ProtectionPilot Server, which shows the version number of these files in the server repository.

3

1

#

Up-to-date — All product, agent, DAT, and engine versions are equal to or later than those in the server repository, and the agent has communicated recently.

#

Pending — An immediate update has been sent, but the agent has not yet returned the update status to the server.

#

Not communicating — The agent hasn’t communicated recently.

#

Not up-to-date — One or more product, agent, DAT, or engine versions are earlier than those in the server repository, and the agent has communicated recently.

2 When did I get the latest

updates? Last update under ProtectionPilot Server shows when files were last retrieved from Network Associates.

Are my computers up-to-date? Compliance reports break this question down into these categories:

1 2

5 3

4

4

Have there been any detections lately? Find the answer to this question by time and type under detection reports:

#

Cleaned / Blocked — Files where clean or block succeeded.

#

Deleted — Files where delete succeeded.

#

Quarantined — Files where move (quarantine) succeeded.

#

Error — Files where access was denied, or where clean, delete, or move (quarantine) failed.

24

ProtectionPilot™ software version 1.0

Are there any new threats or updates? Visit Resource Sites to learn about newly discovered and known threats, and whether new updates are available. 5


Seeing your coverage at-a-glance

Using the console The main user interface components of the ProtectionPilot console are described below.

1

3

2

4

Figure 2-11. User interface components Sections — Click the buttons at the top of the center pane of the console to go directly to the corresponding section (a group of related pages). For example, click the Server button to display the Server section. 1

Tree pane — You can also click the items in the tree pane (left pane of the console) to go directly to the corresponding section. This is the only way to go directly to the group and computer sections. 2

3

Back — Click

to go back to the page you last viewed.

Print — Click

to open a printer-friendly version of the contents of the center pane. The right pane of the console (contains the back, print, and help buttons, and Management Tasks) is excluded. Help — Click

to open the Help file. Descriptions of the options on the current

page appear. 4

Management Tasks — Provides quick access to tasks related to the current page.

Evaluation Guide

25


Evaluating the ProtectionPilot Software

Investigating detections You will be creating sample infections by copying the EICAR Standard Anti-Virus Test File to one of your test computers, then viewing the reported sample detections.

Creating sample detections 1

Download EICAR.COM to one of the workstation test computers. Each time you download this file, you are creating a sample detection. At press time, this file was available on the EICAR web site: http://www.eicar.org/anti_virus_test_file.htm NOTE

This file is not a virus. 2

The on-access scanner detects and quarantines the EICAR test virus at the same time that EICAR.COM is downloaded.

Viewing the reported sample detections 1

From the Home section under All Computers, notice the Quarantined detection category increasing to match the number of times you copied EICAR.COM to the workstation test computer. Detections are reported immediately.

Figure 2-12. EICAR test viruses appear in detection report within minutes

26

ProtectionPilot™ software version 1.0


Investigating detections

2

To view reported detections, grouped by computer name, click Quarantined.

Figure 2-13. Reported detections, grouped by computer name 3

To view what has been detected, click Detection detail grouped by detections.

Figure 2-14. What has been detected 4

To view which files have been impacted, click Detection Count.

Figure 2-15. Which files have been impacted

Evaluation Guide

27


Evaluating the ProtectionPilot Software

5

You can print any of these detection reports by clicking . A printer-friendly version of the report opens in Internet Explorer. Use the browser to print the report or save it to a file; for example, File | Print or File | Save As.

Figure 2-16. Detection report from the Home section

Resolving compliance issues First, you will be simulating an issue with product compliance by forcing the virus definition (DAT) file to be downgraded to an older version. Since you can only retrieve the latest DAT files from Network Associates, an old version has been supplied with the software. Once the updated product properties have been collected, you will be viewing the compliance issue, then resolving it.

Simulating a compliance issue To run the SuperDAT package (SDAT<DAT>.EXE; where DAT is the DAT version number), you must be logged on as a local administrator or a member of the Administrators group. 1

Copy SDAT<DAT>.EXE to a temporary location (for example; C:\TEMP) on one of the workstation test computers. This file is located in the documentation folder (for example, ENGLISH_DOCUMENTATION) on the product CD or in the downloaded product package.

2

Run the following command: “C:\TEMP\SDAT<DAT>.EXE /F”

3

28

Click Next, then Finish.

ProtectionPilot™ software version 1.0


Resolving compliance issues

Collecting updated product properties You can wait for the software to collect the updated product properties or force their immediate collection from either the managed computer or the server. Automatic product properties collection: "

The automatic collection of product properties occurs within – at the most – six minutes.

Force immediate collection of properties from the managed computer: "

If the agent system tray icon appears on the workstation test computer, right-click the agent system tray icon, select Status Monitor, then click Collect and Send Props.

Force immediate collection of properties from the server: "

From the All Computers section on the General tab, click Enforce under Management Tasks.

Viewing and resolving the compliance issue 1

On the Home section under All Computers, notice that one of your test computers is now reported as out-of-date.

Figure 2-17. The simulated compliance issue now appears on the Home page

Evaluation Guide

29


Evaluating the ProtectionPilot Software

2

To view the compliance details for the out-of-date computers, click Not up-to-date. Notice that the version number in the DAT column appears in red. Cells that appear in red indicate that one or more product versions are earlier than those in the server repository, or that the agent has not communicated recently.

Figure 2-18. The DAT version for the test computer is out-of-date 3

To force an immediate DAT update, select the computer, then click Update.

4

Go back to the Home section under All Computers. Notice that the compliance category has changed from Not up-to-date to Pending. This indicates that an immediate update has been sent, but the updated product properties haven’t been received yet.

Figure 2-19. The immediate update is pending

30

ProtectionPilot™ software version 1.0


Resolving compliance issues

5

Once the updated product properties have been collected, you’ll notice that all of your test computers are now reported as up-to-date.

Figure 2-20. All test computers are now up-to-date 6

You can print any of these compliance reports by clicking . A printer-friendly version of the report opens in Internet Explorer. Use the browser to print the report or save it to a file; for example, File | Print or File | Save As.

Figure 2-21. Compliance report from the Home section

Evaluation Guide

31


Evaluating the ProtectionPilot Software

Responding to a suspected outbreak By default, ProtectionPilot automatically retrieves virus definition (DAT) files and the virus-scanning engine from Network Associates hourly, then begins updating managed products immediately. If you suspect that an outbreak is occurring on your network, or when you hear news about a newly discovered threat (for example, via a DAT notification message from AVERT), you can’t wait an hour. You will be immediately updating and scanning all of your test computers.

Updating DAT files immediately You can retrieve the new virus definition (DAT) file from Network Associates on-demand, then begin updating managed products immediately. "

From the Home section, click Update All under Management Tasks. Click Finish to begin the update.

Figure 2-22. Immediately update all managed products with new DAT file

Scanning for possible infections immediately Next, you can immediately scan all of your managed computers for possible infections. "

32

From the Home section, click Scan All Computers under Management Tasks.

ProtectionPilot™ software version 1.0


Changing a VirusScan Enterprise policy setting

Changing a VirusScan Enterprise policy setting Policies are the configuration settings for each product that can be managed via ProtectionPilot. These settings determine how the product behaves on managed computers. You can change policy settings for all computers, a group of computers, or an individual computer. An an example, you will be enabling the policy setting to detect potentially unwanted and joke programs on both of your workstation test computers. 1

In the tree pane under McAfee ProtectionPilot, select the WORKSTATION group.

2

Click the Policies tab.

3

Click VirusScan Enterprise 7.1 to open the Policy Settings dialog box.

4

Select Default Processes Policies in Select policy categories.

5

Click the Advanced tab.

6

Deselect Inherit.

7

Under Non-viruses, select Find potentially unwanted programs and Find joke programs.

8

Click Apply All to save the current entries.

9

Click Close to return to the Policies page. Changes are applied immediately.

Managing computers remotely Following are some of the basic tools provided by ProtectionPilot for managing computers remotely. From the ProtectionPilot console, you can verify that managed computers are online and that the agent is communicating with the server, view the agent activity log file, and view computer and product properties.

Checking computer and agent connectivity 1

Unplug one of the workstation test computers from the network.

2

In the tree pane under McAfee ProtectionPilot | All Computers, select the computer you unplugged from the WORKSTATION group.

3

Click Check Connection under Management Tasks.

4

A message appears indicating that the agent is offline.

Evaluation Guide

33


Evaluating the ProtectionPilot Software

Viewing agent log files 1

In the tree pane under McAfee ProtectionPilot| All Computers, select a computer from its group.

2

Click the Agent Log tab to view the agent activity log file. To view the current or previous agent installation log file, click current or previous next to FrameSvc.

To view the current client tasks log file, click current next to NaPrdMgr. To print a log file: a

Click

to open a printer-friendly version of the log.

b

Use the browser to print the log or save it to a file; for example, File | Print or File | Save As.

To refresh the contents of a log file:

# Click Refresh under Management Tasks.

Viewing computer properties 1

In the tree pane under McAfee ProtectionPilot | All Computers, select one of your test computers from its group. An abbreviated list of computer properties appears under Computer Conditions, including the most recent agent-to-server communication (Last Contact).

Figure 2-23. Abbreviated set of computer properties

34

ProtectionPilot™ software version 1.0


Managing computers remotely

2

To view the complete set of computer properties, click View detailed properties.

Figure 2-24. Complete set of computer properties

Viewing product properties 1

In the tree pane under McAfee ProtectionPilot | All Computers, select one of your test computers from its group.

2

Click View compliance summary under Compliance, then click one of the listed products, such as VirusScan Enterprise.

Figure 2-25. List of installed products

Evaluation Guide

35


Evaluating the ProtectionPilot Software

3

Click the desired Section Name to view those properties.

Figure 2-26. Detailed product properties

Additional areas to explore "

Scanning managed computers for possible infections — You can immediately

scan computers, modify the settings of this immediate scan, and schedule scans to take place periodically. For instructions, see Scanning managed computers for possible infections, Modifying default On-Demand Scan client tasks, and Performing scheduled scans in the ProtectionPilot 1.0 Product Guide or Help file.

36

"

When to use AutoUpdate repositories and how to set them up — Find out whether we recommend using AutoUpdate repositories (update locations) in your environment. For more information, see When to use AutoUpdate repositories in the ProtectionPilot 1.0 Product Guide or Help file. For instructions on setting them up, see Managing AutoUpdate Repositories in the ProtectionPilot 1.0 Product Guide or Help file.

"

Putting existing McAfee Security products under management — You can easily put computers with existing McAfee Security products under management. For instructions, see Putting existing McAfee Security products under management in the ProtectionPilot 1.0 Product Guide or Help file.

ProtectionPilot™ software version 1.0