VMware VCENTER CONFIGURATION MANAGER 5.3 - SOFTWARE CONTENT REPOSITORY TOOL GUIDE Guide de l'utilisateur

Naviguer en ligne ou télécharger Guide de l'utilisateur pour Logiciel VMware VCENTER CONFIGURATION MANAGER 5.3 - SOFTWARE CONTENT REPOSITORY TOOL GUIDE. VMware VCENTER CONFIGURATION MANAGER 5.3 - SOFTWARE CONTENT REPOSITORY TOOL GUIDE Product guide Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer

Résumé du contenu

Page 1 - Product Guide

Product GuideMcAfee MOVE AntiVirus (Agentless) 3.6.0For use with McAfee ePolicy Orchestrator

Page 2 - COPYRIGHT

VMware vCenter — Console that manages the ESXi servers, which host the guest VMs that requireprotection.Hypervisor (ESXi) — Allows multiple operating

Page 3 - Contents

Greater Data Center visibilityMcAfee Data Center Connector, which is also part of the Data Center Security suite, provides acomplete view into virtual

Page 4 - Index 71

1IntroductionFeatures12McAfee MOVE AntiVirus (Agentless) 3.6.0 Product Guide

Page 5 - About this document

2Installation and configurationTo set up your environment for MOVE AV Agentless, you install VMware vShield Endpoint, configurethe Security Virtual Ap

Page 6 - Find product documentation

These items come pre-installed:Operating system Ubuntu 12.0.4Software VirusScan Enterprise for Linux 2.0McAfee Agent 4.8McAfee MOVE AV AgentlessWe rec

Page 7

• VMware vSphere 5.1, 5.5• VMware NSX Manager 6.0.5 and laterFor details about system requirements and instructions for setting up the ePolicy Orchest

Page 8

• McAfee MOVE AV (Agentless) restore tool (MOVE‑AV‑AL_RestoreTool_3.6.0.zip)• McAfee MOVE AV (Agentless) multiple OVF deployment tool (MOVE‑AV‑AL_SVA_

Page 9 - Components and what they do

TaskFor option definitions, click ? in the interface.1From the ePolicy Orchestrator console, click Menu | Software | Extensions | Install Extension.2B

Page 10 - Features

Setting up the SVAYou must deploy the OVF and configure the SVA before you can begin using the Agentless deploymentoption.OVF deployment optionsThe pr

Page 11 - Introduction

Product trial version — Allows you to use the McAfee ePO-based SVA deployment feature to managean environment with 10 hypervisors or fewer. If you use

Page 12

COPYRIGHTCopyright © 2015 McAfee, Inc., 2821 Mission College Boulevard, Santa Clara, CA 95054, 1.888.847.8766, www.intelsecurity.comTRADEMARK ATTRIBUT

Page 13 - Requirements

Set up a common configuration for SVA deploymentBefore deploying the SVA, complete this common configuration on the McAfee ePO server, so thatthese se

Page 14

3From the Configuration tab, click IP Pool to open the IP Pool: IP Pool Details page with these SVA details andactions:4Click Actions | Add IP Pool to

Page 15 - Firewall settings

4Click Actions | Add SVA to open the Check-in SVA (zip) file page.5From Select SVA (zip) file to check-in, browse to and select the SVA package, then

Page 16

4Click Edit under Action to open the vShield Manager Configuration dialog box and edit these vShieldManager account details.Make sure that your vShiel

Page 17 - Install VMware Endpoint

The SVA deployment process using McAfee ePO involves these three simple steps:1Common configuration — Before deploying the SVA, complete this common c

Page 18 - McAfee ePO-based deployment

• SVA Host Name — Displays the name of the SVA host. Example: SVA-1- host-5421.• Here, SVA — Indicates the SVA Hostname Prefix, which is defined in th

Page 19

• Warning — Check for specific warnings like:• VM Tools are not running.• Compatibility checking failed.• VMs are not part of the domain as McAfee ePO

Page 20 - Configure the IP Pool details

3From the Status tab, you can view the SVA deployment or upgrade details.4Click any of the SVA deployment jobs to view these Job Status Details and it

Page 21

Table 2-5 During SVA deployment (continued)Task type DescriptionEnabling vShield DriverEnables vShield Driver on the client machines.Testing EICARTes

Page 22

Table 2-7 During SVA upgrade (continued)Task type DescriptionRemoving SVARemoving the powered off old SVA from hypervisorEnabling vShield DriverEnabl

Page 23 - Deploy SVA using McAfee ePO

ContentsPreface 5About this document ...5Conventions ... 5Find product documentation ...

Page 24

After initiating the SVA removal process, you can view the Job Status Details and Task Status Details for theremoval on the McAfee ePO server.Table 2-

Page 25

7On the Select storage page, select the Datastore where you want to add the SVA service virtualmachines storage, or select Specified on host.The selec

Page 26

3From the Server Type drop-down list on the Description page, select NSX Manager, and specify a uniqueuser‑friendly name and some details that can hel

Page 27 - Task type and status details

Check in the SVA package to McAfee ePOYou must check in and host the SVA package in McAfee ePO, so that you can use it with VMware NSXManager, then de

Page 28

TaskFor option definitions, click ? in the interface.1Log on to McAfee ePO as an administrator.2Click Menu | Configuration | MOVE Service Registration

Page 29 - Remove SVA using McAfee ePO

7On the Select storage page, select the Datastore where you want to add the SVA service virtualmachines storage, or select Specified on host.The selec

Page 30 - Deploy VMware Endpoint

Create a global security groupYou can select all data centers from the available vCenter and configure them as a security group, sothat you can assign

Page 31

For this... Do this...NameType the name of the MOVE service.DescriptionType some details about the MOVE service, which help you to identify the SVA.Ac

Page 32

Task1Gather this information, which you require to run the configuration script:SVA IP addressvCloud Networkingand SecurityManagerIP address or DNS na

Page 33

Column header OVF propertyePO Server NetworkThe name of the ESXi network that the McAfee ePO server uses to managethe McAfee SVA.To successfully deplo

Page 34

3 Monitoring and managing your environment 45Integration with ePolicy Orchestrator ...45Policy management ...

Page 35

Task1From the vSphere Client, select the resource pool on the hypervisor where you want to deploy theOVF, then click File | Deploy OVF Template to ope

Page 36

• If you select the Manual Deployment option and don't provide the configuration information aboutthe Properties page, you must manually configur

Page 37 - Deploy multiple OVFs

3At the prompt, log on with these credentials:• User name: svaadmin• Password: adminThe configuration script runs automatically the first time you log

Page 38 - CSV file properties

Category Setting DescriptionSVA Host name The host name of the SVA.SVA savaadminPasswordThe password of the svaadmin account.vCloud Networkingand Secu

Page 39 - Manually deploy the OVF

Unregister the VMware NSX Manager from McAfee ePOSelect the registered VMware NSX Manager and unregister it from the McAfee ePO server.Task1Log on to

Page 40 - Configure the SVA

3Monitoring and managing yourenvironment The Agentless deployment option monitors the status of virtual desktops and changes behavior fromthe ePolicy

Page 41 - Manually configure the SVA

Policies and their categoriesPolicy information is grouped into two categories: SVA and Scan. You can create, modify, or delete asmany policies as nee

Page 42 - OVF properties

• User — Enter the user name credentials to connect with the server.• Password — Enter the password associated with the user.After you save and reopen

Page 43

Table 3-1 Scan Items Option DefinitionOn-Access ScanfilesWhen an attempt is made to open, close, or rename a file, the scanner interceptsthe operatio

Page 44 - Uninstall the extension

9In the Actions tab, configure When a threat is found behavior. You must select a first action and asecondary action.For the first action, available o

Page 45 - Monitoring and managing your

PrefaceThis guide provides the information you need to configure, use, and maintain your McAfee product.Contents About this document Find produc

Page 46 - Configuring policies

2From the ePolicy Orchestrator console, click Menu | Systems | System Tree.3Select the system from the list, then select Actions | Agent | Wake Up Age

Page 47 - Create a scan policy

The restore tool at-a-glanceThis diagram provides an overview of how the quarantine restore tool works.The restore tool requires Java Runtime Environm

Page 48 - Policy management

Task1From the folder where you extracted MOVE-AV-AL_RestoreTool.3.6.0.zip, run quarantine_restore.cmd tolaunch the quarantine restore tool.The Connect

Page 49 - Test the installation

Using the SVA policy quarantine settingsThe Quarantine settings tab is located on the SVA Policy page. The malware that is detected on any virtualmach

Page 50 - How quarantine works

3In the Advanced Sharing dialog box, select Share this folder, then change Share name to quarantine$. The $symbol hides the share.4Click Permissions,

Page 51 - Restore a file

Follow these steps to run the policy collection immediately:aClick Menu | Configuration | Server Settings, then click MOVE AV [Agentless] under Settin

Page 52

8Click Menu | Reporting | Queries & Reports and select MOVE AV [Agentless] under McAfee Groups to view and runthese scan diagnostic queries:• MOVE

Page 53

At the end of specified minutes, the tool completes the analysis and displays the results. Thedefault allowed time limit is 1 minute.You can also chan

Page 54

Monitoring the SVAMonitor the status of the SVA using the Threat Event Log in ePolicy Orchestrator, or the Health andAlarms feature in VMware vShield

Page 55 - Scan diagnosis

To create reports, your assigned permission set must include the ability to create and edit reports. Youcan restrict access to reports using groups an

Page 56

Find product documentationAfter a product is released, information about the product is entered into the McAfee online KnowledgeCenter.Task1Go to the

Page 57

3Monitoring and managing your environmentQueries and reports60McAfee MOVE AntiVirus (Agentless) 3.6.0 Product Guide

Page 58 - Queries and reports

4Managing the SVAsDeploying a new SVA to the hypervisor in the previous version of McAfee MOVE AV (Agentless)requires you to unregister the existing S

Page 59

TaskFor option definitions, click ? in the interface.1Log on to McAfee ePO as an administrator.2Click Menu | Queries and Reports | Actions | Import De

Page 60

Task1Gather this information, which you need to run the unregister script:ePolicy OrchestratorServer IP address and portUser name and passwordYou must

Page 61 - Managing the SVAs

2From the folder where you extracted MOVE‑AV‑AL_SVA_Deployment_3.6.0.zip, run launch.bat tostart the command prompt.4Managing the SVAsUnregister the S

Page 62

3Enter 1 to unregister the existing SVA from the selected vCloud Networking and Security Manager.You can enter 2 to deploy the new SVA. For details ab

Page 63

6Turn off the SVA.Do not delete this SVA until the 3.6.0 version is successfully deployed. This SVA can be used to helptroubleshoot deployment issues.

Page 64

3Delete the version 3.5 SVA from the cluster in the vCenter.4Remove all McAfee MOVE AV policy from Security policies in the VMware vCenter Web Clientc

Page 65 - Deploy a new SVA manually

4Managing the SVAsUpgrade the SVA using NSX Manager68McAfee MOVE AntiVirus (Agentless) 3.6.0 Product Guide

Page 66 - Assign a policy

ASVA security requirementsThe following security measures are implemented on the SVA.SecuritymeasureDescriptionapparmorapparmor is a kernel module tha

Page 67

1IntroductionMcAfee Management for Optimized Virtual Environments AntiVirus (McAfee® MOVE AntiVirus) is ananti-virus solution for virtual environments

Page 68

ASVA security requirements70McAfee MOVE AntiVirus (Agentless) 3.6.0 Product Guide

Page 69 - SVA security requirements

IndexAaccountvShield Manager 22Agentless deployment optioninstall extension 16integration with ePolicy Orchestrator 45policy management 45Ccommon conf

Page 70

Oopen virtualization formatdeployment options 18manual deployment 39properties 42PpermissionsVMware vCenter 18policiesAgentless 45applying 49assigning

Page 72

The Multi-Platform deployment option:• Uses McAfee ePO to manage the MOVE configuration on the client systems, offload scan server, andSVA Manager (OS

Page 73

Components and what they doEach component performs specific functions to keep your environment protected.ePolicy Orchestrator — Allows you to configur

Commentaires sur ces manuels

Pas de commentaire