ProtectionPilot ™
version 1.0
Quick Reference Card 3 Are my computers up-to-date? Compliance reports break this question down into these categories:
! Up-to-date — All product, agent, DAT, and engine versions are ! ! !
1 What’s my current level of protection? It’s the DAT version
and Engine version under ProtectionPilot Server, which shows the version number of these files in the server repository.
2 When did I get the latest updates? Last update under ProtectionPilot Server shows when files were last retrieved from Network Associates.
equal to or later than those in the server repository, and the agent has communicated recently. Pending — An immediate update has been sent, but the agent has not yet returned the update status to the server. Not communicating — The agent hasn’t communicated recently. Not up-to-date — One or more product, agent, DAT, or engine versions are earlier than those in the server repository, and the agent has communicated recently.
1 2
3
5
4
4 Have there been any detections lately? Find the answer to this question by time and type under detection reports:
! Cleaned / Blocked — Files where clean or block succeeded. ! Deleted — Files where delete succeeded. ! Quarantined — Files where move (quarantine) succeeded. ! Error — Files where access was denied, or where clean, block, delete, or move (quarantine) failed.
mcafeesecurity.com
Are there any new threats or updates? Visit the Resource 5 Sites to learn about newly discovered and known threats, and whether new updates are available.
Keeping your anti-virus products up-to-date automatically Updating DAT and engine files automatically
Taking immediate actions on computers
By default, ProtectionPilot automatically retrieves virus definition (DAT) files and the virus-scanning engine from Network Associates hourly, then begins updating managed products immediately. This default setup ensures that the latest DAT and engine files are protecting your network as soon as they are available.
"
To change how often this happens: 1
From the Server section on the Summary tab, click Server Update under Server Tasks to expand the task options.
2
Select the desired frequency options. For example, let’s say you want to retrieve updates from Network Associates every Wednesday at noon. Select the Weekly interval, then indicate that the task should run every Wednesday at 12:00 pm.
3
Be sure that the Enabled box is selected.
4
Click Apply Settings under Management Tasks to save the current entries.
Upgrading products Use this procedure to deploy (send and install) new versions of the VirusScan software or other products to managed computers. Periodically, you might also want to upgrade existing products with service pack or patch releases. 1
Locate the package (PKGCATALOG.Z) file on the product CD, or download it from the Network Associates web site (requires a Network Associates grant number): https://secure.nai.com/us/forms/downloads/upgrades/ login.asp
2
From the Server section, click the Repository tab. The Manage AutoUpdate Repositories page appears.
3
Click Check In Package under Management Tasks.
4
Click Next in the Check In Package wizard.
5
Select Products and updates, then click Next.
6
Click Browse to select the package (PKGCATALOG.Z) file for the product release.
7
Click Finish, then OK. Managed products are immediately updated.
Enforce — Reapplies (enforces) the existing product policy
settings and tasks on managed computers and collects the complete set of computer and product properties. "
Deploy — Deploys selected products and optionally reinstalls the agent to selected computers. Available for All Computers, a group of computers, or an individual computer.
"
Refresh — Refreshes the data that appears in the console.
"
Scan — Scans selected computers for possible infections using the task settings of the default On-Demand Scan client tasks. Available for All Computers, a group of computers, or an individual computer. You can also scan all computers from the Home section.
"
Update All — Retrieves virus definition (DAT) files and the
virus-scanning engine from Network Associates, then begins updating managed products immediately. Available from the Home or Server sections. "
Update — Begins the updating of managed products immediately. Managed products are updated with all product updates in the server repository. Available for All Computers, a group of computers, or an individual computer.
Make sure new and existing computers are managed and protected Deploying products to new computers and putting them under management Use this procedure to put your network computers under management (including those with existing McAfee Security products), and deploy the VirusScan software to them. 1
From the All Computers section on the General tab, click Add Computers under Management Tasks.
2
Click Next in the Add Computers Wizard.
3
Select the desired domains or individual computers, then click Next.
4
Specify how to organize computers under All Computers, then click Next.
5
Select the desired products, then click Next.
6
To deploy the agent to computers running supported versions of Windows NT, Windows 2000, Windows XP, and Windows Server 2003, select Push agent. a b
8
Click Next, then Finish. Computers appear in the console within – at the most – three minutes.
Adding computers that use a system image of a managed computer You can install the agent and McAfee Security products on computers used to create system images of software. The first time you log on to a computer built using a system image – that includes the agent – the agent immediately contacts the ProtectionPilot server. If this computer meets the criteria of existing groups (domain or workgroup membership or IP settings), it appears in those groups; otherwise, it appears in Lost&Found.
Manually installing the agent You need to distribute the agent package (FRAMEPKG.EXE) to users for them to install when any of the following are true:
To hide the agent installation, select Hide agent
"
You don’t have remote access to computers.
installation user interface for agent push.
"
In Domain\User, type the credentials to use when installing the agent on the selected computers:
Computers are running supported versions of Windows 95, Windows 98, or Windows Me.
"
Computers are in a Novell network.
If the computers are in a domain... Then, these permissions are needed...
Use this format...
Domain administrator (in that domain)
<DOMAIN>\<USER> Example:
MAIN\ADMINISTRATOR
Local administrator (on those computers)
<COMPUTER>\<USER> Example: SHULL\ADMINISTRATOR
Local administrator (on the ProtectionPilot server)
.\<USER> Example: .\ADMINISTRATOR
Once installed, the agent contacts the ProtectionPilot server within – at the most – three minutes, and the computer appears in Lost&Found. To save agent package for manual installation: 1
From the Home section, click Download Agent Package under Management Tasks.
2
Click Save when asked whether you want to open or save the file.
3
Specify a location, then click Save.
4
Once the file has been downloaded, click Close in the Download Complete dialog box.
If the computers are in a workgroup... Then, these permissions are needed...
Use this format...
To manually install the agent:
Local administrator (on those computers)
<COMPUTER>\<USER> Example:
"
NOTE
We recommend setting up the same local administrator user account on all computers, so you can put all of the computers under management at once. Local administrator (on the ProtectionPilot server)
NOTE
The local administrator user accounts on the server and on each computer must be the same.
c 7
— OR —
SHULL\ADMINISTRATOR
"
.\<USER> Example:
.\ADMINISTRATOR
Type the password associated with the user account that you provided in Password.
To save the agent package (FRAMEPKG.EXE) for manual installation, select Download agent, then click Browse to select a location. The agent must be manually installed on computers running supported versions of Windows 95, Windows 98, and Windows Me, and in Novell networks. For instructions, see Manually installing the agent.
Install the agent via a logon script.
Distribute the file to users using one of these methods, and ask them to install the agent by double-clicking the FRAMEPKG.EXE file:
#
Network directory — Copy the package to a network directory (for example, \\<COMPUTER>\<FOLDER>) to which users have permissions.
#
Removable media — Copy the package to removable media (for example, 3.5-inch disk).
#
E-mail — Attach the package to an e-mail message.
Investigating detections Listing computers with reported detections
Listing which files have been impacted
1
From the All Computers section, click the General tab.
1
From the All Computers section, click the General tab.
2
Select a time frame, such as Today or This week.
2
Select a time frame, such as Today or This week.
3
Click a detection category, such as Quarantined or Error, to view detections reported within that time frame, grouped by computer name.
3
Click a detection category, such as Quarantined or Error.
4
Click Detection Count to view the files that were impacted by that detection.
Scanning managed computers for possible infections 1
Listing what has been detected 1
From the All Computers section, click the General tab.
2
Select a time frame, such as Today or This week.
3
Click a detection category, such as Quarantined or Error.
4
Click Detection detail grouped by detections.
In the tree pane under McAfee ProtectionPilot, select All Computers, a group of computers, or an individual computer.
2
Click Scan under Management Tasks.
Getting information Product documentation Evaluation Guide *^
Procedures on preparing for, installing, and deploying the software in a test environment, and detailed instructions for common tasks.
Quick Reference Card *^
Detailed instructions for both common and infrequent, but important tasks.
Installation Guide *^
Procedures on preparing for, installing, and deploying the software in a production environment.
Product Guide *
Procedures on customizing the software for your environment and maintaining the software. Product introduction and features, detailed instructions for configuring the software, information on deployment, recurring tasks, and operating procedures.
Help §
Context-sensitive help topics accessible from most pages that list the procedures related to that page, reference information, and all information found in the Product Guide.
Release Notes ‡
ReadMe. Product information, resolved issues, any known issues, and last-minute additions or changes to the product or its documentation.
Contacts ‡
Contact information for McAfee Security and Network Associates services and resources: technical support, customer service, AVERT (Anti-Virus Emergency Response Team), beta program, and training. This file also includes phone numbers, street addresses, web addresses, and fax numbers for Network Associates offices in the United States and around the world.
* An Adobe Acrobat .PDF file on the product CD, or the McAfee Security download site. ^ A printed manual that accompanies the product CD. Note: Some language manuals may be available only as a .PDF file. ‡ Text files included with the software application and on the product CD. § Help accessed from the software application: Help menu and/or Help button for page-level help.
Getting help There are a variety of resources available to you when you need more information about the product. "
Click Help or
from anywhere in the application.
"
Review the ProtectionPilot 1.0 Release Notes (README.TXT) for a list of known issues and last-minute updates to the product and its documentation. The default location is: C:\PROGRAM FILES\NETWORK ASSOCIATES\PROTECTIONPILOT\1.0.0
"
Click McAfee Support under Resource Sites on the Welcome to McAfee ProtectionPilot page for access to a free knowledge
base of known issues and supplemental documentation.
ProtectionPilot ™ Maximum Protection. Simple Administration.
DBN 008-EN
3965 Freedom Circle
|
Santa Clara, CA 95054
|
888.VIRUSNO (888.847.8766)
Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved.
mcafeesecurity.com