Installation Guide Revision 1.0
ProtectionPilot
™
Maximum Protection. Simple Administration. version 1.0
COPYRIGHT Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved. No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or by any means without the written permission of Networks Associates Technology, Inc., or its suppliers or affiliate companies. To obtain this permission, write to the attention of the Network Associates legal department at: 5000 Headquarters Drive, Plano, Texas 75024, or call +1-972-963-8000. TRADEMARK ATTRIBUTIONS Active Firewall, Active Security, Active Security (in Katakana), ActiveHelp, ActiveShield, AntiVirus Anyware and design, Appera, AVERT, Bomb Shelter, Certified Network Expert, Clean-Up, CleanUp Wizard, ClickNet, CNX, CNX Certification Certified Network Expert and design, Covert, Design (stylized N), Disk Minder, Distributed Sniffer System, Distributed Sniffer System (in Katakana), Dr Solomon’s, Dr Solomon’s label, E and Design, Entercept, Enterprise SecureCast, Enterprise SecureCast (in Katakana), ePolicy Orchestrator, Event Orchestrator (in Katakana), EZ SetUp, First Aid, ForceField, GMT, GroupShield, GroupShield (in Katakana), Guard Dog, HelpDesk, HelpDesk IQ, HomeGuard, Hunter, Impermia, InfiniStream, Intrusion Prevention Through Innovation, IntruShield, IntruVert Networks, LANGuru, LANGuru (in Katakana), M and design, Magic Solutions, Magic Solutions (in Katakana), Magic University, MagicSpy, MagicTree, McAfee, McAfee (in Katakana), McAfee and design, McAfee.com, MultiMedia Cloaking, NA Network Associates, Net Tools, Net Tools (in Katakana), NetAsyst, NetCrypto, NetOctopus, NetScan, NetShield, NetStalker, Network Associates, Network Performance Orchestrator, NetXray, NotesGuard, nPO, Nuts & Bolts, Oil Change, PC Medic, PCNotary, PortalShield, Powered by SpamAssassin, PrimeSupport, Recoverkey, Recoverkey – International, Registry Wizard, Remote Desktop, ReportMagic, RingFence, Router PM, Safe & Sound, SalesMagic, SecureCast, SecureSelect, SecurityShield, Service Level Manager, ServiceMagic, SmartDesk, Sniffer, Sniffer (in Hangul), SpamKiller, SpamAssassin, Stalker, SupportMagic, ThreatScan, TIS, TMEG, Total Network Security, Total Network Visibility, Total Network Visibility (in Katakana), Total Service Desk, Total Virus Defense, Trusted Mail, UnInstaller, VIDS, Virex, Virus Forum, ViruScan, VirusScan, WebScan, WebShield, WebShield (in Katakana), WebSniffer, WebStalker, WebWall, What's The State Of Your IDS?, Who’s Watching Your Network, WinGauge, Your E-Business Defender, ZAC 2000, Zip Manager are registered trademarks or trademarks of Network Associates, Inc. and/or its affiliates in the US and/or other countries. Sniffer® brand products are made only by Network Associates, Inc. All other registered and unregistered trademarks herein are the sole property of their respective owners. LICENSE INFORMATION License Agreement NOTICE TO ALL USERS: CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE LICENSE YOU PURCHASED, WHICH SETS FORTH THE GENERAL TERMS AND CONDITIONS FOR THE USE OF THE LICENSED SOFTWARE. IF YOU DO NOT KNOW WHICH TYPE OF LICENSE YOU HAVE ACQUIRED, PLEASE CONSULT THE SALES AND OTHER RELATED LICENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANIES YOUR SOFTWARE PACKAGING OR THAT YOU HAVE RECEIVED SEPARATELY AS PART OF THE PURCHASE (AS A BOOKLET, A FILE ON THE PRODUCT CD, OR A FILE AVAILABLE ON THE WEB SITE FROM WHICH YOU DOWNLOADED THE SOFTWARE PACKAGE). IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT, DO NOT INSTALL THE SOFTWARE. IF APPLICABLE, YOU MAY RETURN THE PRODUCT TO NETWORK ASSOCIATES OR THE PLACE OF PURCHASE FOR A FULL REFUND.
Attributions This product includes or may include: ! Software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/).
! Cryptographic software written by Eric A. Young and software written by Tim J. Hudson. ! Some software programs that are licensed (or sublicensed) to the user under the GNU General Public License (GPL) or other similar Free Software licenses which, among other
rights, permit the user to copy, modify and redistribute certain programs, or portions thereof, and have access to the source code. The GPL requires that for any software covered under the GPL which is distributed to someone in an executable binary format, that the source code also be made available to those users. For any such software covered under the GPL, the source code is made available on this CD. If any Free Software licenses require that Network Associates provide rights to use, copy or modify a software program that are broader than the rights granted in this agreement, then such rights shall take precedence over the rights and restrictions herein. Software originally written by Henry Spencer, Copyright 1992, 1993, 1994, 1997 Henry Spencer.
! ! Software originally written by Robert Nordier, Copyright © 1996-7 Robert Nordier. All rights reserved. ! Software written by Douglas W. Sauder. ! Software developed by the Apache Software Foundation (http://www.apache.org/). ! International Components for Unicode (“ICU”) Copyright © 1995-2002 International Business Machines Corporation and others. All rights reserved. ! Software developed by CrystalClear Software, Inc., Copyright © 2000 CrystalClear Software, Inc. ! FEAD® Optimizer® technology, Copyright Netopsystems AG, Berlin, Germany. ! Outside In® Viewer Technology © 1992-2001 Stellent Chicago, Inc. and/or Outside In® HTML Export, © 2001 Stellent Chicago, Inc. ! Software copyrighted by Thai Open Source Software Center Ltd. and Clark Cooper, © 1998, 1999, 2000. ! Software copyrighted by Expat maintainers. ! Software copyrighted by The Regents of the University of California, © 1989. ! Software copyrighted by Gunnar Ritter. ! Software copyrighted by Sun Microsystems®, Inc. ! Software copyrighted by Gisle Aas. All rights reserved, © 1995-2003. ! Software copyrighted by Michael A. Chase, © 1999-2000. ! Software copyrighted by Neil Winton, © 1995-1996. ! Software copyrighted by RSA Data Security, Inc., © 1990-1992. ! Software copyrighted by Sean M. Burke, © 1999, 2000. ! Software copyrighted by Martijn Koster, © 1995. ! Software copyrighted by Brad Appleton, © 1996-1999. ! Software copyrighted by Michael G. Schwern, © 2001. ! Software copyrighted by Graham Barr, © 1998. ! Software copyrighted by Larry Wall and Clark Cooper, © 1998-2000. ! Software copyrighted by Frodo Looijaard, © 1997. PATENT INFORMATION Protected by US Patents 6,470,384; 6,493,756; 6,496,875; 6,553,377; 6,553,378.
Issued March 2004 / ProtectionPilot™ software version 1.0 DBN 010-EN
Contents 1 Introducing ProtectionPilot . . . . . . 5 Supported products . . . . . . . . . . . . . . . . . . . 5 Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 Database . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
2 Installing the Server and Console . 9 What is installed . . . . . . . . . . . . . . . . . . . . . . 9 Before you begin . . . . . . . . . . . . . . . . . . . . . 9 Installing the server and console . . . . . . . . . 9 Defining how to organize computers . . 12 Deploying VirusScan software . . . . . . . 13 Putting computers under management . 14 Starting the console . . . . . . . . . . . . . . . . . . 15 What to do after installation . . . . . . . . . . . . 15 Automatic DAT and engine updates . . . 15 Existing update locations . . . . . . . . . . . 15 Novell environment . . . . . . . . . . . . . . . . 15 Proxy settings for the server . . . . . . . . . 16
3 Installing Remote Consoles . . . . . 17 What is installed . . . . . . . . . . . . . . . . . . . . . 17 Before you begin . . . . . . . . . . . . . . . . . . . . 17 Installing remote consoles . . . . . . . . . . . . . 17 Starting remote consoles . . . . . . . . . . . . . . 18
4 Migrating to a Licensed Version of the Software . . . . . . . . . . . . . . . . . . 19 5 Uninstalling the Software . . . . . . . 21
A Requirements and Recommendations . . . . . . . . . . . . 23 System requirements . . . . . . . . . . . . . . . . . 23 Server requirements . . . . . . . . . . . . . . . 23 Console requirements . . . . . . . . . . . . . . 23 Database requirements . . . . . . . . . . . . . 24 Agent for Windows requirements . . . . . 24 VirusScan 4.5.1, Service Pack 1 requirements . . . . . . . . . . . . . . . . . . . . . 25 VirusScan Enterprise 7.1, server requirements . . . . . . . . . . . . . . . . . . . . . 26 VirusScan Enterprise 7.1, workstation requirements . . . . . . . . . . . . . . . . . . . . . 26 Agent for NetWare requirements . . . . . . 27 NetShield 4.6 for NetWare, server requirements . . . . . . . . . . . . . . . . . . . . . 27 NetWare administrator computer requirements . . . . . . . . . . . . . . . . . . . . . 27 Server hardware and database recommendations . . . . . . . . . . . . . . . . . . . . 28
B Things to Know Before Installation . . . . . . . . . . . . . . . . . . . 29 Computer organization . . . . . . . . . . . . . . . . 29 Credentials . . . . . . . . . . . . . . . . . . . . . . . . . 29 Database software . . . . . . . . . . . . . . . . . . . 29 Firewall software . . . . . . . . . . . . . . . . . . . . . 31 Installing into a Novell environment . . . . . . 31 Putting existing McAfee Security products under management . . . . . . . . . . . . . . . . . . . 31 Replacing Symantec AntiVirus with VirusScan . . . . . . . . . . . . . . . . . . . . . . . . . . 31 Terminal Services . . . . . . . . . . . . . . . . . . . . 32
Installation Guide
iii
Contents
iv
ProtectionPilot™ software version 1.0
1
Introducing ProtectionPilot McAfee® ProtectionPilot™ software version 1.0 is a security management system that simplifies anti-virus management tasks for network administrators who manage up to 500 computers. Management consists of deploying (sending and installing) anti-virus products, configuring product settings, and keeping those products up-to-date.
Server Executing all console requests and handling the exchange of data from the console and agents to the database, the ProtectionPilot server does the majority of the work of the software.
Agents
Consoles
The software is a system made up of these components: server, console, database, and agent.
Supported products
Server
You can use the McAfee ProtectionPilot software to manage these McAfee products: "
Alert Manager 4.5 (client software only).
"
Alert Manager 4.7 (server and client software).
"
NetShield 4.6 for NetWare.
"
VirusScan 4.5.1, Service Pack 1.
"
VirusScan Enterprise 7.0 or later.
Database
Figure 1-1. How the server handles data received from agents and the console
Installation Guide
5
Introducing ProtectionPilot
Console
Database
The piece you interact with directly to execute tasks and view data is the ProtectionPilot console. Although a console is always installed with the server, you can also install it separately. In this case, it is called a remote console because it is used to access the server remotely (from a different computer). Remote consoles are useful if you need to access the server from another computer or location; for example, if access to the server room is restricted or isn’t set up as a work space.
The core component of ProtectionPilot is the database, which stores all data about those computers and products you are managing with the software. Typically, the database is installed on the same computer as the server (local database), but you can also install it on a different computer (remote database). You can even take advantage of an existing database.
Server
Console
Server
Computer
Database
Computer
Figure 1-3. Local database
Remote Consoles Server
Computer Computer Figure 1-2. Relationship between the console, remote consoles, and the server
Database
Computer Figure 1-4. Remote database
6
ProtectionPilot™ software version 1.0
Agent
Agent The ProtectionPilot agent is the key to remotely managing products. Installed on each
computer, it deploys products, updates virus definition (DAT) files and the virus-scanning engine, and upgrades existing products with service pack and patch releases. It also gathers data about installed anti-virus products, the computer, and infection and system activity. In addition, it ensures that requests from the server are executed and re-executed or enforced as needed. For example, if a user removes the anti-virus product you have defined for the computer, the agent will reinstall the product automatically.
Managed Computer Agent
Managed Products
Server
Figure 1-5. Relationship between the agent, managed computer and products, and the server
Installation Guide
7
Introducing ProtectionPilot
8
ProtectionPilot™ software version 1.0
2
Installing the Server and Console What is installed
Before you begin
The server and console installation does more than simply install the server and console software. It also installs the database (optional, but recommended) and one agent on the same computer. The server computer appears in the group you specified during the installation or in the Lost&Found group within – at the most – three minutes.
"
Verify that all computers meet the minimum hardware and software requirements; see System requirements on page 23.
"
Decide how to organize the computers you want to manage; see Computer organization on page 29.
"
Make sure you have user accounts with the appropriate credentials; see Credentials on page 29.
"
If you want to use a database other than the one installed with the server and console; see Database software on page 29.
"
If you use firewall or personal firewall software; see Firewall software on page 31.
"
If you are installing into a Novell environment; see page 31.
"
To put existing McAfee products under management; see page 31.
"
To replace Symantec AntiVirus with VirusScan Enterprise; see page 31.
"
If you are using Terminal Services; see page 32.
During the installation, you can put your network computers under management (including those with existing McAfee products), and deploy the VirusScan software to them. You can even replace Symantec AntiVirus software with the VirusScan software. The ProtectionPilot software can be installed on the following language versions of supported operating systems: "
Brazilian Portuguese
"
Italian
"
Chinese (Simplified)
"
Japanese
"
Chinese (Traditional)
"
Korean
"
Dutch
"
Polish
"
English
"
Spanish
"
French
"
Swedish
"
German
If you install to a language other than English, French, German, Japanese, or Spanish, the console appears in English. You might need to restart the computer once or twice during the installation.
Installing the server and console For beta and evaluation versions of the software, the installation process differs slightly from the steps presented here. For more information, see Beta and evaluation software on page 19. 1
Insert the CD into the CD-ROM drive of the computer.
2
In the autorun window, select the desired language, then select Install ProtectionPilot 1.0.
3
In the McAfee ProtectionPilot 1.0.0 Setup wizard, click Next to begin the installation.
Installation Guide
9
Installing the Server and Console
4
In the Network Associates End User License Agreement dialog box, select the appropriate license type and the country in which you purchased the software. The license type must match the license you purchased. If you are unsure which license you purchased, contact the person who sold you the software. NOTE
If the license agreement does not display correctly, read the appropriate license in the NETWORK_ASSOCIATES_ LICENSE_AGREEMENT.PDF file supplied with the software. 5
6
Read the entire license agreement carefully, select I accept the terms in the license agreement to agree to the license terms, then click OK.
Figure 2-2. Server Installation Options dialog box
8
In the Select Database Server dialog box, specify the desired database:
In the Installation Options dialog box: a Select Install server and console. b Accept the default installation path
(C:\PROGRAM FILES\NETWORK ASSOCIATES\PROTECTIONPILOT), or click Browse to select a different location.
Figure 2-3. Select Database Server dialog box
# To install the default MSDE 2000 database, select Install a database server on this computer and use it. The system administrator (sa) user account on the Figure 2-1. Installation Options dialog box
7
10
In the Server Installation Options dialog box, type and confirm the password you want to use when starting consoles.
ProtectionPilot™ software version 1.0
database is assigned the server password you specified in Step 7. NOTE
If you select this option, skip to Step 10 on page 11. # To use a local SQL Server database, select Use the existing database server on this computer.
Installing the server and console # To use a remote SQL Server database, select Use an existing database server on the network. The drop-down list displays all
remote SQL Server database servers in the same domain as this computer. Select the desired database server, or type its name in the list box. 9
In the Database Server Account dialog box, specify the user account that the server will use to connect to the database:
10 In the HTTP Configuration dialog box, specify
the port numbers used for communication to and from the server. When you click Next, the Setup program verifies whether any of these ports are already in use on this computer. If you don’t know which port numbers are already being used by other services, we recommend incrementing the number by one until no conflicts are found.
# Specify the authentication method of the database by selecting This is an NT account or This is a SQL Server account. If
you don’t know the authentication method or password on the system administrator (sa) user account, we recommend selecting Windows NT authentication.
Figure 2-5. HTTP Configuration dialog box
# Use the default HTTP ports — Unless you
know which port numbers are available, we recommend using the default port numbers by selecting this option. # Agent-to-server communication — Figure 2-4. Database Server Account dialog box
For Windows authentication: # In a domain environment, type the
NetBIOS name of the domain to which the database server belongs, and a user account with domain administrator permissions in that domain. # In a workgroup environment, type the
workgroup name and a user account with local administrator permissions on the database server computer. For SQL Server authentication: # Type the system administrator (sa) user
account.
Specifies the port number (default is 81) that the server uses for inbound communication with agents. # Console-to-server communication —
Specifies the port number (default is 82) that the server uses for inbound communication with the console and remote consoles. # Server-to-agent communication —
Specifies the port number (default is 8081) that the server uses for outbound communication to agents. NOTE
This port must also be available on all managed computers. The Setup program can only verify whether it is in use on this computer.
Installation Guide
11
Installing the Server and Console 11 In the Update DAT and Engine dialog box,
specify whether you want to retrieve the latest virus definition (DAT) files and virus-scanning engine from the Network Associates web site right now. If this computer doesn’t have Internet access, deselect Update DAT and Engine files on my McAfee ProtectionPilot server.
Using logical groupings: # Select Group name, type a descriptive and unique name in the box, then click Next
three times. Examples of logical groupings include geographic location or computer type, such as server versus workstation.
Figure 2-7. Add Group Wizard — Specify group name
Figure 2-6. Update DAT and Engine dialog box
12 In the Ready To Install dialog box, click Install
to begin the installation. This dialog box includes the estimated time needed to complete the installation. The Executing Setup dialog box appears and provides the status of the installation.
Defining how to organize computers 1
In the Welcome dialog box, click Next to begin.
2
In the Add Group Wizard, click Next to define how to organize the computers you want to manage into groups. A group is a collection of computers that share common characteristics. Groups simplify management by allowing you to perform tasks on all computers in a group at once. You’ll need to repeat these steps for each group you want to create.
By IP address: a Select Group name, type a descriptive and unique name in the box, then click Next. b In the Add Group Wizard — Specify IP settings, click Add to open the IP Management dialog box. You can define
multiple IP settings for a group by repeating this step. NOTE
IP addresses cannot overlap between or within groups.
By domain or workgroup membership: # Select Domain name, select the domain or
workgroup from the list box, then click Next.
12
ProtectionPilot™ software version 1.0
Figure 2-8. Add Group Wizard — Specify IP settings
Installing the server and console
To specify an IP address range, type the beginning and ending IP addresses in the range in IP range, then click OK. Use this format: XXX.XXX.XXX.XXX, where X is 0 – 255; for example, 161.69.0.0 – 161.69.255.255. To specify an address mask, type the address mask and number of significant bits in IP subnet mask, then click OK. Use this format: XXX.XXX.XXX.XXX/YY, where X is 0 – 255 and Y is 0 – 32. For example, the address mask of 161.69.0.0/16 equals the range 161.69.0.0 – 161.69.255.255. The address mask of 161.69.255.0/18 equals the range 161.69.192.0 – 161.69.255.255. c When you’re done defining the IP settings, click Next twice. 3
To add another group, answer Yes when asked Do you want to add more groups now?, then click Finish. For instructions, see Defining how to organize computers on page 12. When you’re done adding groups, answer No when asked Do you want to add more groups now?, then click Finish. Groups appear in the console within – at the most –
Figure 2-9. Add Computers Wizard — Select computers to be managed
3
Specify how to organize the selected computers, then click Next. # By domain or workgroup membership: select According to group IP settings or domain names. # Using logical groupings: select In an existing group, then select the desired group from
the list. # By IP address: select According to group IP settings or domain names.
three minutes.
Deploying VirusScan software 1
In the Add Computers Wizard, click Next to select which computers belong in the groups you just created, and to deploy the VirusScan software to them after putting them under management. You’ll need to repeat these steps and those in Putting computers under management on page 14 for each group you created. If you are installing into a Novell environment, click Cancel, then skip to Step 8 on page 15.
2
Figure 2-10. Add Computers Wizard — Specify how the selected computers should be placed into groups
Select all of the computers for a single group, then click Next.
Installation Guide
13
Installing the Server and Console
4
Select one, both, or none, then click Next. If you select both, VirusScan Enterprise 7.1 is installed on all computers except those using Windows 95, Windows 98, or Windows Me, on which VirusScan 4.5.1 is installed. VirusScan 4.5.1 is installed after the manual installation of agent. The agent is required to remotely manage products and it must be manually installed on computers running Windows 95, Windows 98, or Windows Me. NOTE
When upgrading from VirusScan 4.5.1 to VirusScan Enterprise 7.1, the VirusScan system tray icon doesn’t re-appear until the next time users log on to their computers.
Figure 2-12. Add Computers Wizard — Specify agent deployment options
If the computers are in a domain... Then, these permissions are needed...
Use this format in Domain\User...
Domain administrator (in that domain)
<DOMAIN>\<USER> Example: MAIN\ADMINISTRATOR
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ADMINISTRATOR
Figure 2-11. Add Computers Wizard — Select products to be deploy
If the computers are in a workgroup...
Putting computers under management 1
To deploy the agent to computers running supported versions of Windows NT, Windows 2000, Windows XP, and Windows Server 2003, select Push agent.
2
To hide the agent installation, select Hide agent installation user interface for agent push.
3
In Domain\User, type the credentials to use when installing the agent on the selected computers:
Then, these permissions are needed...
Use this format in Domain\User...
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
NOTE We recommend setting up the same local administrator user account on all computers, so you can put all of the computers under management at once. Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ADMINISTRATOR
NOTE The local administrator user accounts on the server and on each computer must be the same.
14
ProtectionPilot™ software version 1.0
Starting the console
4
Type the password of the user account you provided in Password.
What to do after installation
5
To save the agent package (FRAMEPKG.EXE) for manual installation, select Download agent, then click Browse to select a location. The agent must be manually installed on computers running supported versions of Windows 95, Windows 98, and Windows Me, and in Novell networks. For instructions, see Manually installing the agent in the ProtectionPilot 1.0 Product Guide or Help file.
Automatic DAT and engine updates
6
Click Next twice.
7
To add more computers, answer Yes when asked Do you want to add more computers now?, then click Finish. For instructions, see Deploying VirusScan software on page 13. When you’re done adding computers, answer No when asked Do you want to add more computers now?, then click Finish. Computers appear in the console within – at the most – three minutes.
8
In the Installation Complete dialog box, specify the desired options listed below, then click Finish to complete the installation. # To open the console after completing the installation, select Start McAfee ProtectionPilot console. # To learn about the latest product
information, resolved issues, any known issues, and last-minute additions or changes to the product or its documentation, click View Readme. # To create a shortcut for starting the console on the desktop, select Create a shortcut on your Desktop.
Starting the console 1
Click the Start button, then point to Programs | Network Associates | McAfee ProtectionPilot 1.0.0 Console.
2
On the McAfee ProtectionPilot page, type the server password, then click Submit.
By default, ProtectionPilot automatically retrieves virus definition (DAT) files and the virus-scanning engine from Network Associates hourly, then begins updating managed products immediately. This default setup
ensures that the latest DAT and engine files are protecting your network as soon as they are available. You can change how often DAT and engine files are updated. For instructions, see Changing the frequency of DAT and engine updates in the ProtectionPilot 1.0 Product Guide or Help file.
Existing update locations If you have been using update locations (repositories) to centrally distribute virus definition (DAT) files and the virus-scanning engine to computers, this updating strategy is no longer used once you install the server and console. Instead, new DAT and engine files are automatically retrieved from Network Associates every hour, and the updating of managed products begins immediately following. Although we recommend using this default updating strategy, there are situations in which using AutoUpdate repositories are recommended. For more information, see Managing AutoUpdate Repositories in the ProtectionPilot 1.0 Product Guide or Help file.
Novell environment You must manually install the agent to computers in Novell networks before you can deploy the VirusScan software. For instructions, see Manually installing the agent and Deploying products to new computers and putting them under management in the ProtectionPilot 1.0 Product Guide or Help file.
For more information on managing NetShield 4.6 for NetWare, see Managing NetShield for NetWare in the ProtectionPilot 1.0 Product Guide or Help file.
Installation Guide
15
Installing the Server and Console
Proxy settings for the server If the ProtectionPilot server connects to the Internet via a proxy server, you need to add these settings before the automatic updating of virus definition (DAT) files and the virus-scanning engine can begin. For instructions, see Adding proxy settings for the server in the ProtectionPilot 1.0 Product Guide or Help file.
16
ProtectionPilot™ software version 1.0
3
Installing Remote Consoles What is installed
Installing remote consoles
The console-only installation does just that: it installs only a console (called a remote console). For more information, see Console on page 6.
For beta and evaluation versions of the software, the installation process differs slightly from the steps presented here. For more information, see Beta and evaluation software on page 19.
The ProtectionPilot software can be installed on the following language versions of supported operating systems: "
Brazilian Portuguese
"
Italian
"
Chinese (Simplified)
"
Japanese
"
Chinese (Traditional)
"
Korean
"
Dutch
"
Polish
"
English
"
Spanish
"
French
"
Swedish
"
German
1
Insert the CD into the CD-ROM drive of the computer.
2
In the autorun window, select the desired language, then select Install ProtectionPilot 1.0.
3
In the McAfee ProtectionPilot 1.0.0 Setup wizard, click Next to begin the installation.
4
In the Network Associates End User License Agreement dialog box, select the appropriate license type and the country in which you purchased the software. The license type must match the license you purchased. If you are unsure which license you purchased, contact the person who sold you the software.
If you install to a language other than English, French, German, Japanese, or Spanish, the console appears in English.
NOTE
Before you begin "
You need to know the name of the computer where the ProtectionPilot server and console was installed.
"
You need to know the console-to-server communication port (default is 82) used during the installation of the server and console.
"
Verify that all computers meet the minimum hardware and software requirements; see System requirements on page 23.
"
Make sure you have user accounts with the appropriate credentials; see Credentials on page 29.
"
If you are installing into a Novell environment; see page 31.
"
If you are using Terminal Services; see page 32.
If the license agreement does not display correctly, read the appropriate license in the NETWORK_ASSOCIATES_ LICENSE_AGREEMENT.PDF file supplied with the software. 5
Read the entire license agreement carefully, select I accept the terms in the license agreement to agree to the license terms, then click OK.
Installation Guide
17
Installing Remote Consoles
6
In the Installation Options dialog box:
8
a Select Install console only. b Accept the default installation path
(C:\PROGRAM FILES\NETWORK ASSOCIATES\PROTECTIONPILOT), or click Browse to select a different location.
In the Ready To Install dialog box, click Install to begin the installation. This dialog box includes the estimated time needed to complete the installation. The Executing Setup dialog box appears and provides the status of the installation.
9
In the Installation Complete dialog box, specify the desired options listed below, then click Finish to complete the installation. # To open the console after completing the installation, select Start McAfee ProtectionPilot console. # To learn about the latest product
information, resolved issues, any known issues, and last-minute additions or changes to the product or its documentation, click View Readme. # To create a shortcut for starting the console on the desktop, select Create a shortcut on your Desktop. Figure 3-1. Installation Options dialog box
7
In the Console Installation Options dialog box, type the name of the server and the console-to-server communication port (default is 82).
Starting remote consoles 1
McAfee ProtectionPilot 1.0.0 Console. 2
Figure 3-2. Console Installation Options dialog box
18
ProtectionPilot™ software version 1.0
Click the Start button, then point to Programs | Network Associates | On the McAfee ProtectionPilot page, type the server password, then click Submit.
4
Migrating to a Licensed Version of the Software If you have pre-release software (beta or release candidate), you must uninstall the existing version of the software before you can install a licensed version. For instructions, see Uninstalling the Software on page 21. If you have an evaluation version of the software, you can migrate it to a licensed version. To do so, you must be logged on as a local administrator or a member of the Administrators group. 1
Close all ProtectionPilot consoles.
2
Insert the CD into the CD-ROM drive of the computer.
3
In the autorun window, select the desired language, then select Install ProtectionPilot 1.0. NOTE
Be sure that the Setup program you are using is for the licensed version of the software. 4
In the ProtectionPilot 1.0.0 Setup wizard, click Next to begin the migration. A message appears indicating that the migration was completed successfully.
Beta and evaluation software
For beta and evaluation versions of the software, the installation process differs slightly from the steps presented in this guide, as follows: "
A dialog box appears before the license agreement, identifying how long you are licensed to use the beta or evaluation software. Click OK to continue to the license agreement.
"
The license agreement always displays in English – regardless of your computer’s system language – and the license type options are disabled.
When you are using the software, a reminder dialog box appears near the end of the license period, showing the number of days remaining before the license expires. Depending on the type of software, you can: "
Beta software — Click Beta Contact to access the beta feedback page on the Network Associates web site, where you can supply your comments about the beta software.
"
Evaluation software — Click Buy to access a
page on the Network Associates web site, where you can purchase a licensed version of the software. The reminder dialog box appears a number of times before the license expires. If you are not ready to purchase a licensed version or provide beta feedback, you can click OK to close the dialog box. If the license expires, you can no longer log on to the ProtectionPilot server, but can choose to uninstall the agent for Windows. If you leave the agent installed, it continues to enforce policies locally, run scheduled tasks, and send properties and events to the server.
Installation Guide
19
Migrating to a Licensed Version of the Software
20
ProtectionPilot™ software version 1.0
Uninstalling the Software 1
Close all ProtectionPilot consoles.
2
Close all database management software; for example, SQL Enterprise Manager.
3
Use Add/Remove Programs in the Control Panel to remove the software. For
5
instructions, see the Windows Help File. To open this file, click the Start button, then point to Help. To remove the existing MSDE database, select Remove MSDE.
Figure 5-1. Remove McAfee ProtectionPilot dialog box
Installation Guide
21
Uninstalling the Software
22
ProtectionPilot™ software version 1.0
A
Requirements and Recommendations System requirements
Console requirements Browser — Internet Explorer 6.0 or later.
Server requirements Browser — Microsoft Internet Explorer 6.0 or
File system — NTFS or FAT file system partition.
later.
Free disk space — 120MB.
File system — NTFS (NT file system) partition
Memory — 128MB RAM.
(recommended).
Monitor — 1024x768, 256-color, VGA monitor.
Free disk space — 250MB (minimum); 1GB
Operating system:
(recommended).
"
Windows 2000 Advanced Server, Service Pack 3 or later.
"
Windows 2000 Professional, Service Pack 3 or later.
"
Windows 2000 Server, Service Pack 3 or later.
"
Windows XP Professional, Service Pack 1 or later.
"
Windows Server 2003 Standard with or without service packs.
IP address — Static IP address (recommended). Memory — 256MB RAM. Monitor — 1024x768, 256-color, VGA monitor. Network environment — TCP/IP. Operating system: "
Windows 2000 Advanced Server, Service Pack 3 or later.
"
Windows 2000 Professional, Service Pack 3 or later.
"
Windows 2000 Server, Service Pack 3 or later.
"
Windows XP Professional, Service Pack 1 or later.
"
Windows Server 2003 Standard with or without service packs.
Processor — Pentium II-class (or higher) compatible. Processor speed — 400MHz or higher.
Other — Internet connection (recommended). Processor — Intel Pentium II-class (or higher) compatible. Processor speed — 400MHz or higher; 550MHz
(minimum on Windows Server 2003 Standard).
Installation Guide
23
Requirements and Recommendations
Database requirements Database software: "
MSDE 2000, Service Pack 3 or later. NOTE
MSDE 2000, Service Pack 3 cannot be installed on backup or secondary domain controllers. "
SQL Server 7 Standard or Enterprise, Service Pack 3 or later. NOTE
If using SQL Server, you must use a case-insensitive instance. "
SQL Server 2000 Standard or Enterprise, Service Pack 3 or later.
Named instance (SQL Server only) — If using a named instance, the database must be remote (installed on a different computer than the ProtectionPilot server). Remote database — Microsoft Data Access
Components (MDAC) 2.7 or later.
Agent for Windows requirements Free disk space — 5MB. Memory — 8MB RAM. Network environment — Microsoft or Novell
NetWare networks. NetWare networks require TCP/IP.
Operating system:
NOTE
"
If using SQL Server, you must use a case-insensitive instance.
Windows 95 with or without service packs.
"
Windows 98 Second Edition (SE) with or without service packs.
"
Windows 98 with or without service packs.
"
Windows NT Server 4.0, Service Pack 4 or later.
"
Windows NT Workstation 4.0, Service Pack 4 or later.
"
Windows Millennium Edition (Me) with or without service packs.
"
Windows 2000 Advanced Server, Service Pack 3 or later.
"
Windows 2000 Professional, Service Pack 3 or later.
"
Windows 2000 Server, Service Pack 3 or later.
"
Windows XP Professional, Service Pack 1 or later.
"
Windows Server 2003 Standard with or without service packs.
"
Windows Server 2003 Web with or without service packs.
Licenses (SQL Server only) — A license is needed
for each processor on the computer where SQL Server is installed, regardless of whether the processor is running SQL Server. The Per Processor licensing model allows unlimited access to SQL Server. For the most current information on SQL Server licensing, see the Microsoft product documentation. At press time, information for United States and Canadian customers was available on the Microsoft web site: www.microsoft.com/sql/howtobuy/producti on.asp WARNING
You cannot start the software, if the minimum number of SQL Server licenses is not available after you install the software. Local database server (SQL Server only) —
Specify a fixed memory size that is approximately two-thirds of the total memory for SQL Server (recommendation). For example, if using 256MB of RAM, set 150MB as the fixed memory size. For instructions, see the Enterprise Manager product documentation. Maintenance settings — Specify maintenance
settings (recommendation). For instructions, see Maintaining ProtectionPilot databases in the ProtectionPilot 1.0 Help file.
24
ProtectionPilot™ software version 1.0
Processor — Pentium-class or Celeron (or higher) compatible. Processor speed — 166MHz or higher. Windows 95 — Computers using Windows 95A, Windows 95B, or Windows 95C must meet these additional requirements:
System requirements
"
VCREDIST.EXE, available at no charge from Microsoft. At press time, this program and instructions for installation were available on the Microsoft web site:
support.microsoft.com/directory/article.as p?ID=KB;EN-US;Q259403& NOTE
After you install VCREDIST.EXE, you must restart the computer. "
Browser — Internet Explorer 4.0.1 or later. Free disk space — 55MB. Memory — 16MB RAM. Operating system: "
Windows 95.
"
Windows 98.
"
Windows 98 SE.
"
Windows NT Workstation 4.0, Service Pack 4 or later.
"
Windows Me.
NOTE
"
After you install DCOM95 1.3, you must restart the computer.
Windows 2000 Professional.
"
Windows XP Home (Fast user switching is not supported).
"
Windows XP Professional (Fast user switching is not supported).
DCOM95 1.3, available at no charge from
Microsoft. At press time, this program and instructions for installation were available on the Microsoft web site: www.microsoft.com/com/dcom/dcom95/ dcom1_3.asp
Windows 98 — Computers using Windows 98 must meet these additional requirements. Client computers using Windows 98 SE do not need this program installed on them. "
VirusScan 4.5.1, Service Pack 1 requirements
VCREDIST.EXE, available at no charge from
Microsoft. At press time, this program and instructions for installation were available on the Microsoft web site: support.microsoft.com/directory/article.as p?ID=KB;EN-US;Q259403& NOTE
After you install VCREDIST.EXE, you must restart the computer.
Processor — Pentium-class or compatible; Pentium or Celeron (recommended). Processor speed — 166MHz or higher. Upgrade path — You can upgrade from McAfee VirusScan 4.0.3, 4.0.3a, or 4.5 to VirusScan 4.5.1. To upgrade from versions earlier than 4.0.3 or from VirusScan ThinClient (TC) 6.0, you must manually uninstall them before installing version 4.5.1.
Installation Guide
25
Requirements and Recommendations
VirusScan Enterprise 7.1, server requirements
VirusScan Enterprise 7.1, workstation requirements
Browser — Internet Explorer 4.0 or later.
Browser — Internet Explorer 4.0 or later.
Free disk space — 20MB (complete installation) plus 25MB (temporary space needed for installation).
Free disk space — 20MB (complete installation)
Memory — 32MB RAM. For information on
optimal operating system performance, review the Microsoft guidelines for minimum RAM configuration.
optimal operating system performance, review the Microsoft guidelines for minimum RAM configuration. Operating system:
plus 25MB (temporary space during installation). Memory — 32MB RAM. For information on
Operating system: "
Windows NT Workstation 4.0, Service Pack 6 or 6a.
Windows NT Enterprise Server 4.0, Service Pack 6 or 6a.
"
Windows 2000 Professional, Service Pack 1, 2, or 3.
"
Windows NT Terminal Server 4.0, Service Pack 6.
"
Windows XP Home, Service Pack 1.
"
Windows XP Professional, Service Pack 1.
"
Windows 2000 Server, Service Pack 1, 2, or 3.
"
Windows XP Tablet PC, Service Pack 1.
"
Windows 2000 Advanced Server, Service Pack 1, 2, or 3.
"
Windows 2000 Datacenter Server, Service Pack 1, 2, or 3.
"
Windows Server 2003 Standard.
"
Windows Server 2003 Enterprise.
"
Windows Server 2003 Web.
"
Windows Server 2003 Datacenter.
"
Windows NT Server 4.0, Service Pack 6 or 6a.
"
Processor — Intel or compatible; Intel Pentium or Celeron (recommended). Processor speed — 166MHz or higher.
26
ProtectionPilot™ software version 1.0
Processor — Intel or compatible; Pentium or Celeron (recommended). Processor speed — 166MHz or higher.
System requirements
Agent for NetWare requirements
Volume:
NetWare 4.11 and 4.2:
"
Standard traditional volume.
NW4WSOCK.EXE, available at no charge from
"
Novell. At press time, this program and instructions for installation were available on the Novell web site:
Compressed traditional volume.
"
Standard Novell Storage Services (NSS) volume.
"
http://support.novell.com/servlet/tidfind er/2958994 Network environment — TCP/IP. Operating system: "
NetWare 4.11 with Support Pack 9.
"
NetWare 4.2 with Support Pack 9.
"
NetWare 5.0 with Support Pack 6a.
"
NetWare 5.1 with Support Pack 5.
"
NetWare 6.0.
NetWare administrator computer requirements This is the computer from which you are installing the agent for NetWare and the NetShield for NetWare product. Novell Client:
We recommend using the latest Novell client software. The NetShield software has been tested and found compatible with the following versions of the Novell Client:
Product — McAfee NetShield 4.6 for NetWare.
Operating System
Novell Client Version 3.3
NetShield 4.6 for NetWare, server requirements
Windows 95 Windows 98 Windows 98 SE Windows Me Windows NT 4.0
4.8
Windows 2000 Server Windows Professional Windows XP Professional
4.8
Free disk space — 4MB plus enough free disk
space to accommodate a duplicate of the largest compressed file on any volume on the server. The default installation directory is: SYS:MCAFEEE\NETSHLD
Memory — 4MB RAM. Network environment — TCP/IP. Operating system: "
NetWare 4.11, Support Pack 9.
"
NetWare 4.2, Support Pack 9.
"
NetWare 5.0, Support Pack 6a.
"
NetWare 5.1, Support Pack 5.
"
NetWare 6.0.
Java Runtime Environment (JRE): "
Sun Java 2 Standard Edition Runtime Environment 1.1.7b or later. — OR —
"
Microsoft Java Virtual Machine (JVM) 4.79.2436 or later. JVM is installed as a component of Internet Explorer 4.0, Service Pack 2 or later, and can be activated for use.
Processor — Pentium-II (or higher) compatible.
Installation Guide
27
Requirements and Recommendations
Server hardware and database recommendations For optimum performance, we recommend the following database software and hardware for the computer on which you install the ProtectionPilot server and console. These recommendations are based on the number of computers being managed by the server. Computers
Processor
Processor Speed
> 50
Pentium III or higher
400MHz or higher
51 – 250
Pentium III or higher
500MHz or higher
251 – 500
Pentium III or higher
700MHz or higher
Memory
Disk space (database)
Database
256MB
250MB
MSDE
256MB
500MB
MSDE
512MB
1GB
SQL Server
28
ProtectionPilot™ software version 1.0
B
Things to Know Before Installation Computer organization You can organize computers into groups by domain or workgroup membership, using logical groupings (for example, geographic location or computer type, such as server versus workstation), or by IP address. Groups simplify management by allowing you to perform tasks on all computers in a group at once. You don’t need to pick a single method; you can organize each group of computers as you see fit. To organize computers by...
You need...
Domain
#
Domain name
Workgroup
#
Workgroup name
Logical grouping
#
Descriptive name Names and network locations of computers
#
IP address
# # #
Descriptive name Names and network locations of computers Address mask or range of IP addresses.
NOTE IP addresses cannot overlap between or within groups.
Credentials To install the server and console or remote consoles, you must be logged on as a local administrator or a member of the Administrators group.
To put computers under management (deploy the agent), you need to provide a user account with local or domain administrator permissions on those computers. NOTE
If you are deploying the agent to computers in a workgroup using the local administrator user account on those computers, we recommend setting up the same local administrator user account on all computers. This will allow you to put all of the computers under management at once. If you are deploying the agent to computers in a workgroup using the local administrator user account on the server, the local administrator user accounts on the server and on each computer must be the same. To deploy the agent to another domain, the server must have a trust relationship with the Primary Domain Controller (PDC) on the network. For instructions on setting up trust relationships between domains, see the Microsoft product documentation.
Database software Although you can use MSDE 2000, SQL Server 7, or SQL Server 2000 as the ProtectionPilot database, we recommend that you use the MSDE 2000 database that can be automatically installed when you install the server and console. However, if you have an existing SQL Server database that you want to use, complete the following procedures before you install the software. Small Business Server 2003 Premium
You can use the SQL Server 2000 database included in Microsoft Small Business Server 2003 Premium as the database. It is handled in the same manner as other SQL Server databases.
Installation Guide
29
Things to Know Before Installation Local SQL Server database 1
Install the database software as needed. For instructions, see the SQL Server product documentation.
2
If you are using SQL Server 2000, verify that the SQL Server 2000 service (MSSQLSERVER) is running. Depending on the operating system that you are using, this procedure varies. For instructions, see the Microsoft product documentation.
3
During the installation, you’ll need to provide the authentication method being used for the database (default is Windows), and the user account that the ProtectionPilot server will use to connect to the database.
Remote SQL Server database 1
Install the database software as needed. For instructions, see the SQL Server product documentation.
2
Install MDAC 2.7 as needed. For instructions, see Determining the version number of MDAC on page 30 and Installing MDAC on page 30.
3
Verify that the database server is visible on network.
4
If the server connects to the database server through a firewall, you need to ensure that the database server accepts inbound communication on the database communication port (default is 1433).
5
If you are using SQL Server 2000, verify that the SQL Server 2000 service (MSSQLSERVER) is running. For instructions, see the SQL Server product documentation.
6
Verify that the SQL Server Agent service (SQLServerAgent) is running. For instructions, see the SQL Server product documentation.
30
ProtectionPilot™ software version 1.0
7
During the installation, you’ll need to provide the name of the database server, the authentication method being used for the database (default is Windows), and the user account that the ProtectionPilot server will use to connect to the database.
Determining the version number of MDAC 1 Locate the MSDADC.DLL file that corresponds
to the database software. The default location is: C:\PROGRAM FILES\COMMON FILES\SYSTEM\OLE DB
2
Right-click the MSDADC.DLL file, then select Properties. The <FILE> Properties dialog box appears.
3
Click the Version tab.
4
Under Item name, select Product Version. The version number appears under Value.
Installing MDAC
We distribute the MDAC 2.7, Service Pack 1 Refresh Setup program on the product CD and in the product package available for download. It can be found in these locations: On the product CD: SETUP\MDAC\MDAC_TYP_<LANGUAGE>.EXE "
Where <LANGUAGE> equals EN for English, FR for French, DE for German, JP for Japanese, and ES for Spanish.
In the downloaded product package: SETUP\MDAC\MDAC_TYP.EXE
At press time, instructions for installation were available on the Microsoft web site: http://www.microsoft.com/downloads/detail s.aspx?FamilyID=9ad000f2-cae7-493d-b0f3-ae3 6c570ade8&DisplayLang=en
Firewall software
Firewall software If you use firewall or personal firewall software, you need to ensure that the communication ports you specify during the installation accept the appropriate type of communication. The software uses these ports to communicate between its components. Communication
Inbound or Outbound *
Default Port
Agent-to-server
Inbound
81
Console-to-server
Inbound
82
Server-to-agent
Outbound
8081
* Communication is relative to the ProtectionPilot server.
Installing into a Novell environment To install the software into a Novell environment, TCP/IP must be installed and enabled on these computers: "
The ProtectionPilot server.
"
The NetShield 4.6 for NetWare server.
"
Computers running NetShield 4.6 for NetWare.
In addition, the following services must be enabled or started on the ProtectionPilot server: "
The NT LM Security Support Provider service must be enabled.
"
The Server service must be started. To install this service, install the File and Printer Sharing for Microsoft Networks network component.
"
The Workstation service must be started. To install this service, install the Client for Microsoft Networks network component.
Putting existing McAfee Security products under management During the installation, you can put computers that already have McAfee VirusScan Enterprise 7.0 or later installed on them under management in the same way as unprotected computers. You can also do this after the installation. For instructions, see Putting existing McAfee Security products under management in the ProtectionPilot 1.0 Product Guide or Help file.
Replacing Symantec AntiVirus with VirusScan During the installation, you can automatically replace Symantec AntiVirus Corporate Edition 7.50, 7.51, 7.6, 8.0, 8.01, or 8.1 (English language version only) with the VirusScan software. This includes primary and secondary Symantec AntiVirus servers, and managed and unmanaged Symantec AntiVirus computers – including password-protected computers. NOTE
On computers running Windows 98, you must manually uninstall Symantec AntiVirus Corporate Edition 8.1 before VirusScan 4.5.1 can automatically replace it. You can also replace Symantec AntiVirus with the VirusScan software after the installation. For instructions, see Replacing Symantec AntiVirus with VirusScan in the ProtectionPilot 1.0 Help file.
Depending on the operating system that you are using, the steps to enable or start services, and to install network components vary. For instructions, see the Microsoft product documentation.
Installation Guide
31
Things to Know Before Installation
Terminal Services Install the server and console
Although you can install the server and console or remote consoles on computers with Terminal Services, you cannot use Terminal Services to install this software. You must use Add/Remove Programs. For instructions, see the Microsoft product documentation. Install the agent
You can use Terminal Services on these operating systems to install the agent: "
Windows NT 4.0 Terminal Services.
"
Windows 2000 Terminal Services.
"
Windows Server 2003 Terminal Services.
"
Windows XP Terminal Services.
32
ProtectionPilot™ software version 1.0
Connect to consoles remotely
You can use Terminal Services on the following operating systems to manage the server remotely. (You can also use remote consoles to manage the server remotely. For instructions, see Installing Remote Consoles on page 17.) "
Windows 2000 Terminal Services.
"
Windows Server 2003 Terminal Services.
"
Windows XP Terminal Services.