Symantec Critical System Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Sprzęt komputerowy Symantec Critical System. Symantec Critical System User Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj

Podsumowanie treści

Strona 1 - Protection Installation Guide

Symantec™ Critical System Protection Installation Guide

Strona 2 - Installation Guide

10 ContentsCopying files required for the policy conversion utility ...110Migrating legacy detection policy files ...

Strona 3 - Technical Support

100 Installing UNIX agentsTroubleshooting agent issues

Strona 4

Chapter5Migrating to the latest versionThis chapter includes the following topics: Migrating legacy installations of Symantec Critical System Protect

Strona 5

102 Migrating to the latest versionMigrating legacy installations of Symantec Critical System ProtectionWhen migrating legacy installations for Symant

Strona 6

103Migrating to the latest versionMigrating legacy installations of Symantec Critical System ProtectionIf you changed the name of the database owner a

Strona 7 - Contents

104 Migrating to the latest versionMigrating legacy installations of Symantec Critical System ProtectionTable 5-1 lists the management server-related

Strona 8 - 8 Contents

105Migrating to the latest versionMigrating other legacy agent installationsTo specify the management server list for an agent1 At a command prompt, l

Strona 9 - 9Contents

106 Migrating to the latest versionChecklist for migrating from Symantec Intruder AlertPolicy migration involves using a policy conversion utility tha

Strona 10 - 10 Contents

107Migrating to the latest versionChecklist for migrating from Symantec Intruder AlertSystem Protection authoring environment (and eventually conditio

Strona 11 - Critical System Protection

108 Migrating to the latest versionChecklist for migrating from Symantec Host IDSChecklist for migrating from Symantec Host IDSSymantec Critical Syste

Strona 12 - Protection

109Migrating to the latest versionMigrating legacy agent software(and each ungrouped agent), noting the stock policies and the custom policies that ar

Strona 13 - About the policy library

Chapter1Introducing Symantec™ Critical System ProtectionThis chapter includes the following topics: About Symantec Critical System Protection Compon

Strona 14 - Where to get more information

110 Migrating to the latest versionPreparing for detection policy migrationInstalling the authoring environment and policy conversion utilityThe Syman

Strona 15 - Planning the installation

111Migrating to the latest versionMigrating legacy detection policy filesMigrating legacy detection policy filesYour legacy detection policy files may

Strona 16 - System requirements

112 Migrating to the latest versionMigrating legacy detection policy filesTable 5-2 lists the policy conversion utility command line switches.Note: To

Strona 17 - Operating system requirements

113Migrating to the latest versionMigrating legacy detection policy files4 Type ITAHIDSpolicyMigration.exe, type the names of your source and destinat

Strona 18 - Solaris packages

114 Migrating to the latest versionMigrating legacy detection policy files3 In the right pane, on the General tab, in the Name box, type a name for yo

Strona 19 - Linux kernel driver support

115Migrating to the latest versionMigrating legacy detection policy filesYou should also check other migrated rule elements such as patterns and actio

Strona 20 - Hardware requirements

116 Migrating to the latest versionMigrating legacy detection policy files6 For rules that need to be changed, on the Rules tab, right-click the rule

Strona 21

117Migrating to the latest versionMigrating legacy detection policy filesApplying policies created and compiled in the authoring environmentYou use th

Strona 22

118 Migrating to the latest versionMigrating legacy detection policy files

Strona 23 - About name resolution

IndexAagentalternate management servers 27, 103fail back interval 26failover 25, 74groupscommon configuration 53, 63, 76, 81detection configuration 54

Strona 24 - About intrusion prevention

12 Introducing Symantec™ Critical System ProtectionComponents of Symantec Critical System ProtectionSymantec Critical System Protection agents detect

Strona 25 - About simple failover

120 IndexIP routing 24LLinux agentsdisabling and enabling 93kernel driver support 19monitoring and restarting 98uninstalling manually 87log filesagent

Strona 26 - About the fail back interval

121IndexSQL serverevaluation installation 44installation requirements 34installing to existing 34MDAC requirements 35production database installation

Strona 28 - About log files

13Introducing Symantec™ Critical System ProtectionHow Symantec Critical System Protection worksHow Symantec Critical System Protection worksSymantec C

Strona 29 - What to do after installation

14 Introducing Symantec™ Critical System ProtectionWhere to get more informationWhere to get more informationProduct manuals for Symantec Critical Sys

Strona 30 - 30 Planning the installation

Chapter2Planning the installationThis chapter includes the following topics: About planning the installation About network architecture and policy d

Strona 31 - Installing Symantec

16 Planning the installationSystem requirementsalong with a few agents, and become familiar with Symantec Critical System Protection operations. When

Strona 32 - Protection on Windows

17Planning the installationSystem requirementsOperating system requirementsTable 2-1 lists Symantec Critical System Protection component operating sys

Strona 33 - Bypassing prerequisite checks

18 Planning the installationSystem requirementsSolaris packagesThe agent installation checks for the presence of Solaris system packages.The following

Strona 34

19Planning the installationSystem requirements SUNWkvm Core Architecture, (Kvm) SUNWcsr Core Solaris, (Root) SUNWcsu Core Solaris, (Usr) SUNWcsd C

Strona 35

Symantec™ Critical System ProtectionInstallation GuideThe software described in this book is furnished under a license agreement and may be used only

Strona 36

20 Planning the installationSystem requirementsIf a system is configured with a different kernel, the agent will attempt to load the latest version av

Strona 37 - ■ Tomcat component only

21Planning the installationDisabling Windows XP firewallsDisabling Windows XP firewallsWindows XP and Windows 2003 Server contain firewalls that are e

Strona 38

22 Planning the installationAbout using firewalls with Symantec Critical System Protection4 On the Advanced tab, under Internet Connection Firewall, u

Strona 39 - ■ SQL Prod: NA

23Planning the installationAbout name resolutionto the instance using that port. Thus, your firewall must allow traffic from the management server to

Strona 40

24 Planning the installationAbout IP routingAbout IP routingAs bastion hosts, firewalls traditionally incorporate some form of network address transla

Strona 41

25Planning the installationAbout simple failoverBy default, the enable intrusion prevention option is selected during Symantec Critical System Protect

Strona 42 - ■ SQL Prod: variable

26 Planning the installationAbout simple failover Once the IPS Service fails away from the first server in the ordered list, it periodically checks i

Strona 43

27Planning the installationAbout the Windows NT agent installationSpecifying the management server list for an agentTo use simple failover for an agen

Strona 44

28 Planning the installationAbout log filesdrivers. To temporarily disable agents that run on Windows NT Server, you create an alternate hardware prof

Strona 45

29Planning the installationWhat to do after installationTable 2-5 lists the management server log files.What to do after installationYou can begin enf

Strona 46

Technical SupportSymantec Technical Support maintains support centers globally. Technical Support’s primary role is to respond to specific queries abo

Strona 47 - ■ server-cert.ssl

30 Planning the installationWhat to do after installation

Strona 48

Chapter3Installing Symantec Critical System Protection on WindowsThis chapter includes the following topics: About installing Symantec Critical Syste

Strona 49

32 Installing Symantec Critical System Protection on WindowsAbout installing Symantec Critical System Protection on WindowsAbout installing Symantec C

Strona 50

33Installing Symantec Critical System Protection on WindowsAbout installing Symantec Critical System Protection on WindowsBypassing prerequisite check

Strona 51 - Installing a Windows agent

34 Installing Symantec Critical System Protection on WindowsAbout installing a database to a SQL Server instanceAbout installing a database to a SQL S

Strona 52 - Setting Default Description

35Installing Symantec Critical System Protection on WindowsAbout installing a database to a SQL Server instanceAfter you install the instance of SQL S

Strona 53

36 Installing Symantec Critical System Protection on WindowsConfiguring the temp environment variableConfiguring the temp environment variableThe inst

Strona 54

37Installing Symantec Critical System Protection on WindowsInstalling the management server Evaluation installation using existing MS SQL instanceYou

Strona 55

38 Installing Symantec Critical System Protection on WindowsInstalling the management serverUsing the SQL Server Enterprise Manager, do the following:

Strona 56

39Installing Symantec Critical System Protection on WindowsInstalling the management serverDestination Folder C:\Program Files\Symantec\Critical Syste

Strona 57

Operating system Version and patch level Network topology Router, gateway, and IP address information Problem description: Error messages and l

Strona 58

40 Installing Symantec Critical System Protection on WindowsInstalling the management serverMSDE Data Path C:\Program Files\Symantec\Critical System P

Strona 59 - Unattended agent installation

41Installing Symantec Critical System Protection on WindowsInstalling the management serversa password noneYou have the following options: MSDE Eval:

Strona 60

42 Installing Symantec Critical System Protection on WindowsInstalling the management serverInstalling evaluation installation that runs MSDE on the l

Strona 61 - Installation properties

43Installing Symantec Critical System Protection on WindowsInstalling the management server4 In the Installation Type panel, click Evaluation Installa

Strona 62

44 Installing Symantec Critical System Protection on WindowsInstalling the management server7 In the Database Selection panel, change the default serv

Strona 63

45Installing Symantec Critical System Protection on WindowsInstalling the management server3 In the License Agreement panel, select I accept the terms

Strona 64

46 Installing Symantec Critical System Protection on WindowsInstalling the management server All other accounts (owner, guest, and internal accounts)

Strona 65

47Installing Symantec Critical System Protection on WindowsInstalling the management server9 In the Database Configuration panel, specify the database

Strona 66

48 Installing Symantec Critical System Protection on WindowsInstalling and configuring the management consoleNote: If the management server database i

Strona 67

49Installing Symantec Critical System Protection on WindowsInstalling and configuring the management consoleC:/Program Files/Symantec/Critical System

Strona 68

Maintenance agreement resourcesIf you want to contact Symantec regarding an existing maintenance agreement, please contact the maintenance agreement a

Strona 69 - ■ Symantec IPS driver

50 Installing Symantec Critical System Protection on WindowsInstalling and configuring the management consoleTo configure the management console1 Clic

Strona 70

51Installing Symantec Critical System Protection on WindowsInstalling a Windows agentInstalling a Windows agentThe Symantec Critical System Protection

Strona 71 - Reinstalling Windows agents

52 Installing Symantec Critical System Protection on WindowsInstalling a Windows agentLogs File DirectoryC:\Program Files\Symantec\Critical System Pro

Strona 72

53Installing Symantec Critical System Protection on WindowsInstalling a Windows agentPrimary Management Serverlocalhost The IP address or fully qualif

Strona 73 - Installing UNIX agents

54 Installing Symantec Critical System Protection on WindowsInstalling a Windows agentPrevention Policy Groupnone The name of an existing prevention p

Strona 74

55Installing Symantec Critical System Protection on WindowsInstalling a Windows agentInstalling the Windows agent softwareThe installation CD contains

Strona 75

56 Installing Symantec Critical System Protection on WindowsInstalling a Windows agent4 In the Destination Folder panel, change the folders if necessa

Strona 76

57Installing Symantec Critical System Protection on WindowsInstalling a Windows agentIf you changed the Agent Port setting during management server in

Strona 77

58 Installing Symantec Critical System Protection on WindowsInstalling a Windows agentYou may add multiple detection policy group names separated with

Strona 78 - 78 Installing UNIX agents

59Installing Symantec Critical System Protection on WindowsUnattended agent installationUnattended agent installationYou must log on to an Administrat

Strona 80

60 Installing Symantec Critical System Protection on WindowsUnattended agent installation3 Type and run one of the following commands:agent.exe ?orage

Strona 81

61Installing Symantec Critical System Protection on WindowsUnattended agent installationInstallation propertiesTable 3-6 describes the Windows agent i

Strona 82

62 Installing Symantec Critical System Protection on WindowsUnattended agent installationLOG_DIR=<val> C:\Program Files\Symantec\Critical System

Strona 83

63Installing Symantec Critical System Protection on WindowsUnattended agent installationCOMMON_CONFIG_GROUP=<val>Common Configuration The name o

Strona 84

64 Installing Symantec Critical System Protection on WindowsInstalling the Windows NT policyInstalling the Windows NT policyThe Windows NT prevention

Strona 85 - Uninstalling agents manually

65Installing Symantec Critical System Protection on WindowsUninstalling Symantec Critical System Protection You must install the Symantec Critical Sy

Strona 86

66 Installing Symantec Critical System Protection on WindowsUninstalling Symantec Critical System ProtectionUninstalling an agent using Add or Remove

Strona 87

67Installing Symantec Critical System Protection on WindowsUninstalling Symantec Critical System ProtectionSee “Unattended agent installation” on page

Strona 88

68 Installing Symantec Critical System Protection on WindowsTemporarily disabling Windows agents3 Click Symantec Critical System Protection Management

Strona 89

69Installing Symantec Critical System Protection on WindowsTemporarily disabling Windows agentsC:\Program Files\Symantec\Critical System Protection\Ag

Strona 90

ContentsTechnical SupportChapter 1 Introducing Symantec™ Critical System ProtectionAbout Symantec Critical System Protection ...

Strona 91

70 Installing Symantec Critical System Protection on WindowsTemporarily disabling Windows agentsUse one of the following methods to disable intrusion

Strona 92

71Installing Symantec Critical System Protection on WindowsReinstalling Windows agentsReinstalling Windows agentsYou can perform an unattended reinsta

Strona 93

72 Installing Symantec Critical System Protection on WindowsReinstalling Windows agents

Strona 94

Chapter4Installing UNIX agentsThis chapter includes the following topics: About installing UNIX agents Installing an agent in verbose mode Installi

Strona 95

74 Installing UNIX agentsAbout installing UNIX agents If you are installing a Solaris, Linux, HP-UX, AIX, or Tru64 agent on a system that supports no

Strona 96 - Enabling a disabled AIX agent

75Installing UNIX agentsAbout installing UNIX agentsAgent Port 443 The Agent Port number that was used during management server installation.See Table

Strona 97

76 Installing UNIX agentsAbout installing UNIX agentsCommon Config Groupnone The name of an existing common configuration group for this agent to join

Strona 98

77Installing UNIX agentsAbout installing UNIX agentsBypassing prerequisite checksThe UNIX installation kit lets you bypass some of the prerequisite ch

Strona 99

78 Installing UNIX agentsInstalling an agent in verbose modeYou can use the bypass prerequisite checks feature to bypass the following prerequisite ch

Strona 100 - Troubleshooting agent issues

79Installing UNIX agentsInstalling an agent in silent mode On the computer on which the agent will be installed, create a directory and then copy the

Strona 101 - Migrating to the latest

8 ContentsBypassing prerequisite checks ... 33About installing a database to a SQL Ser

Strona 102

80 Installing UNIX agentsInstalling an agent in silent modeTable 4-2 describes the settings that are used with the installation commands.Table 4-2 UNI

Strona 103

81Installing UNIX agentsInstalling an agent in silent mode-cert=<file> /tmp/agent-cert.ssl The directory location of the SSL certificate file, a

Strona 104 - Command Syntax Description

82 Installing UNIX agentsInstalling an agent in silent mode-idsPolGrp=<group> OS-specific groupThe OS-specific group is one of the following: A

Strona 105 - ■ UNIX: sisipsconfig.sh -t

83Installing UNIX agentsInstalling an agent in silent modeUse the -silent option and other options to perform a silent installation.The following comm

Strona 106

84 Installing UNIX agentsUninstalling agents using package commandsTo install an agent in silent mode1 Follow the procedures and steps that are used t

Strona 107

85Installing UNIX agentsUninstalling agents manually6 On HP-UX, type and run the following command:swremove SYMCcsp7 On Tru64, type and run the follow

Strona 108 - ■ Template_FileWatch policy

86 Installing UNIX agentsUninstalling agents manuallypgrep -U sisips -P1 -f sisipsdaemonpgrep -U sisips -P1 -f sisipsutildaemonpgrep -U root -P1 -f si

Strona 109

87Installing UNIX agentsUninstalling agents manuallyUninstalling Linux agents manuallyYou can manually uninstall Linux agents.To uninstall Linux agent

Strona 110 - ◆ Do one of the following:

88 Installing UNIX agentsUninstalling agents manually7 Remove the following lines from the initialization scripts:Remove the lines (including comments

Strona 111

89Installing UNIX agentsUninstalling agents manuallyrm -rf /var/log/scsplog (default directory)rm -f /var/run/sisipsdaemon.pidrm -f /var/run/sisidsdae

Strona 112

9ContentsInstalling an agent in silent mode ... 79Uninstalling agents using package

Strona 113 - Creating a new policy

90 Installing UNIX agentsUninstalling agents manually5 Type and run the following commands to remove the agent user and group:userdel sisipsrmgroup si

Strona 114 - Validating your rules

91Installing UNIX agentsDisabling and enabling UNIX agentsEdit and remove the line from /etc/symantec/sis/sis.conf:SisInstalledClsId=<cluster_membe

Strona 115

92 Installing UNIX agentsDisabling and enabling UNIX agentsAfter you disable the driver, apply the Null prevention policy or a prevention policy in wh

Strona 116 - Compiling a policy

93Installing UNIX agentsDisabling and enabling UNIX agentsEnabling a disabled Solaris agentYou can enable a Solaris agent that was previously disabled

Strona 117 - ■ Test the workspace policy

94 Installing UNIX agentsDisabling and enabling UNIX agentsWarning: You should perform these procedures only in emergency situations.To permanently di

Strona 118

95Installing UNIX agentsDisabling and enabling UNIX agents/sbin/init.d/sisidsagent stopPermanently disabling HP-UX agentsIf you have performance issue

Strona 119

96 Installing UNIX agentsDisabling and enabling UNIX agentsTemporarily disabling AIX agentsWarning: You should perform these procedures only in emerge

Strona 120 - 120 Index

97Installing UNIX agentsDisabling and enabling UNIX agentsrcsisidsagent:23456789:wait:/etc/rc.sisidsagent start >/dev/console 2>&13 Type and

Strona 121 - 121Index

98 Installing UNIX agentsMonitoring and restarting UNIX agentsmv sisipsagent sisipsagentOFFmv sisidsagent sisidsagentOFFIf the machine not is a member

Strona 122 - 122 Index

99Installing UNIX agentsTroubleshooting agent issues0 * * * * /etc/init.d/sisidsagent health_check0 * * * * /etc/init.d/sisipsutil health_check (Sola

Komentarze do niniejszej Instrukcji

Brak uwag