McAfee SIEM Port Usage by Appliance

Size: px
Start display at page:

Download "McAfee SIEM Port Usage by Appliance"

Transcription

1 McAfee SIEM Port Usage by Appliance Application Direction Port(s) Protocol Destination / Description ETM Enterprise Security Manager Active Directory out 389, 3268 tcp Active Directory. Port 3268 is used for LDAP. Backup In/out 445,111,2049 tcp/udp EDB Backup and Restore CIFS use 445; NFS uses 111 and 2049 out tcp Port used to communicate to ensure compliance HTTP out 80 tcp/udp Rules Server - HTTPS in/out tcp/udp Client login & OpenVPN client IP varies. Currently 9.1.x uses In udp For Remote management iscsi out 860, 3260 tcp To communicate with iscsi storage. RADIUS in/out 1812 tcp/udp Radius SMTP out 25 tcp/udp Alerts and Reports in/out tcp/udp Traps received from McAfee appliances or sent to Trap collector in/out tcp/udp All McAfee appliances and to access command line. WHOIS out 43 tcp/udp Whois lookups. ERC - Event Receiver out tcp Port used to communicate to ensure compliance HTTPS out tcp/udp Callhome OpenVPN client IP varies. Currently 9.1.x uses In udp For Remote management in/out tcp/udp Traps received from McAfee appliances or sent to Trap collector in/out tcp/udp To/From ESM, ELM and to access command line. ELM Enterprise Log Manager Data Archival in/out 445,111,2049 tcp/udp Data storage destination CIFS use 445; NFS uses 111 and 2049; out tcp Port used to communicate to ensure compliance HTTPS out tcp/udp Callhome OpenVPN client IP varies. Currently 9.1.x uses In udp For Remote management iscsi out 860, 3260 tcp To communicate with iscsi storage. in/out tcp/udp Traps received from McAfee appliances or sent to Trap collector in/out tcp/udp To/From ESM, Receiver and to access command line. sftp in/out 23 tcp/udp Allow sftp client to access raw log files. ADM Application Data Monitor out tcp Port used to communicate to ensure compliance HTTPS out tcp/udp Callhome OpenVPN client IP varies. Currently 9.1.x uses In udp For Remote management in/out tcp/udp Traps received from McAfee appliances or sent to Trap collector in/out tcp/udp To/From ESM and to access command line.

2 ACE Advance Correlation Engine out tcp Port used to communicate to ensure compliance HTTPS out tcp/udp Callhome OpenVPN client IP varies. Currently 9.1.x uses In udp For Remote management in/out tcp/udp Traps received from McAfee appliances or sent to Trap collector in/out tcp/udp To/From ESM and to access command line. DEM Database Event Monitor for SIEM out tcp Port used to communicate to ensure compliance HTTPS out tcp/udp Callhome OpenVPN client IP varies. Currently 9.1.x uses In udp For Remote management in/out tcp/udp Traps received from McAfee appliances or sent to Trap collector in/out tcp/udp To/From Nitro ESM, Administrative

3 Below are the ports that data sources defined to a Event Receiver would typically use. This may be an incomplete list depending on new data sources that were added after the publication of this document. Data Sources Description Port Protocol Cisco Mars 993 tcp Cisco ASA NSEL User configurable. tcp Cisco RDEP. User configurable. Tcp estreamer 8302 tcp Flat File 21,,80,445,111,2049 CIFS uses 445; NFS uses 111 and 2049; SCP & SFTP use ; HTTP uses 80; FTP uses 21 tcp IBMTivoli ID Mgr (sql pull). User configurable. tcp IPFIX 4739 udp/tcp itron 21 tcp McAfee Event Agent User configurable. tcp/udp McAfee NSM User configurable. tcp mssql pull User configurable. Various data source use this. tcp/udp mysql User configurable. tcp/udp netflow 2055, User configurable. udp McAfee NSM 3306 (sql pull). User configurable. tcp McAfee 8. User configurable. tcp OPSEC User configurable. tcp Oracle 1521 tcp Postgres DB 5432 tcp SDEE tcp/udp SilverSpring 21 tcp Sophos 1127 tcp syslog 514 tcp/udp Vmware vcenter tcp WMI 135,139, Windows 2000 will use 139 & W2K3 and above will us 139. W2K3 and below will use dynamic port range W2K8 and above will use dynamic port range tcp/udp

4 Vulnerability Assessment udp SQL 205,1433 tcp/udp HTTPS tcp/udp SCP tcp/udp FTP 20,21 tcp/udp NFS 2049, 3780 tcp/udp For outbound Actions (NOTE: The ports listed here are the defaults and can be changes in the ESM GUI) epo 8 tcp NVM 3800 tcp NSM tcp

5 ETM to External Sources Active Directory Backup Rules & GTI RADIUS SMTP WHOIS ACE Correlation Appliance Rules and Risk Engines Original Events flow from ESM CE Events flow to ESM ACE 389, ,111, Rules & GTI connect to Call home connects to ACE to External Sources GUI via HTTPS 80 & ETM ETM Stores parsed event s in EDB Hosts GUI Central point for all administration - - DEM Passively Monitors DB Traffic DEM DEM to External Sources SPAN Access to see DB Events Span Port Event Receiver Parses Events Normalizes Events Aggregates Events Parsed to ETM Raw to ELM - - Event Receiver - ADM Passively Monitors Application Traffic Inspects Layer 3 & layer 7 ADM ERC to External Sources ELM Stores Raw Events Full Text Indexing User definable storage User definable Compression ELM ERC to VA Sources FTP NFS SQL SCP Updated and as of v9.4 ADM to External Sources 20, , , 1433 SPAN Access to see Events ERC to Data Sources See Page 3 of this document for a complete list. ELM to External Sources Data Archival iscsi sftp 445,111, , Span Port

McAfee Enterprise Security Manager 10.3.x Release Notes

McAfee Enterprise Security Manager 10.3.x Release Notes McAfee Enterprise Security Manager 10.3.x Release Notes Contents Installation information What's new in update 10.3.3 Resolved issues in update 10.3.3 Migrating from Flash to HTML Installation information

More information

HP ArcSight Port and Protocol Information

HP ArcSight Port and Protocol Information Important Notice HP ArcSight Port and Protocol Information The information (data) contained on all sheets of this document constitutes confidential information of Hewlett- Packard Company or its affiliates

More information

MA0-104.Passguide PASSGUIDE MA0-104 Intel Security Certified Product Specialist Version 1.0

MA0-104.Passguide  PASSGUIDE MA0-104 Intel Security Certified Product Specialist Version 1.0 MA0-104.Passguide Number: MA0-104 Passing Score: 800 Time Limit: 120 min File Version: 1.0 PASSGUIDE MA0-104 Intel Security Certified Product Specialist Version 1.0 Exam A QUESTION 1 A SIEM can be effectively

More information

McAfee Enterprise Security Manager 10.3.x Release Notes

McAfee Enterprise Security Manager 10.3.x Release Notes McAfee Enterprise Security Manager 10.3.x Release Notes Contents Installation information What's new in update 10.3.4 Resolved issues in update 10.3.4 Migrating from Flash to HTML Installation information

More information

McAfee Enterprise Security Manager

McAfee Enterprise Security Manager Release Notes McAfee Enterprise Security Manager 10.1.2 Contents About this release Resolved Issues 10.1.2 Resolved Issues 10.1.1 Resolved Issues 10.1.0 Resolved issues in 10.0.1 and 10.0.2 Known issues

More information

McAfee Enterprise Security Manager

McAfee Enterprise Security Manager Release Notes McAfee Enterprise Security Manager 10.0.2 Contents About this release New features Resolved issues Instructions for upgrading Find product documentation About this release This document contains

More information

Log Sources Users Guide

Log Sources Users Guide Security Threat Response Manager Release 2010.0 Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA 408-745-2000 www.juniper.net Published: 2011-10-10 Copyright Notice Copyright 2011

More information

VMware vsphere 4. Architecture VMware Inc. All rights reserved

VMware vsphere 4. Architecture VMware Inc. All rights reserved VMware vsphere 4 Architecture 2010 VMware Inc. All rights reserved VMware vsphere Architecture vsphere Client vcenter Converter plug-in Update Manager plug-in vcenter Database vcenter Server vcenter Linked

More information

McAfee Enterprise Security Manager 9.5.2

McAfee Enterprise Security Manager 9.5.2 Release Notes McAfee Enterprise Security Manager 9.5.2 Contents About this release New features for 9.5.2 Known and resolved issues Upgrade instructions Find product documentation About this release This

More information

Security, Internet Access, and Communication Ports

Security, Internet Access, and Communication Ports Security, Internet Access, and Communication Ports The following topics provide information on system security, internet access, and communication ports: Overview: Security, Internet Access, and Communication

More information

Cisco ISE Ports Reference

Cisco ISE Ports Reference Cisco ISE Infrastructure Cisco ISE Infrastructure, on page 1 Cisco ISE Administration Node Ports, on page 2 Cisco ISE Monitoring Node Ports, on page 4 Cisco ISE Policy Service Node Ports, on page 6 Cisco

More information

Security, Internet Access, and Communication Ports

Security, Internet Access, and Communication Ports Security, Internet Access, and Communication Ports The following topics provide information on system security, internet access, and communication ports: Security Requirements Security Requirements, on

More information

Security, Internet Access, and Communication Ports

Security, Internet Access, and Communication Ports Security, Internet Access, and Communication Ports The following topics provide information on system security, internet access, and communication ports: About Security, Internet Access, and Communication

More information

Recording user activity on a SIMATIC Controller using a SIEM System. SIMATIC Controller S H, S7-410E SIMATIC PCS 7

Recording user activity on a SIMATIC Controller using a SIEM System. SIMATIC Controller S H, S7-410E SIMATIC PCS 7 Recording user activity on a SIMATIC Controller using a SIEM System SIMATIC Controller S7-410-5H, S7-410E SIMATIC PCS 7 https://support.industry.siemens.com/cs/ww/en/view/109748211 Siemens Industry Online

More information

Cisco Security Monitoring, Analysis and Response System 4.2

Cisco Security Monitoring, Analysis and Response System 4.2 Q&A Cisco Security Monitoring, Analysis and Response System 4.2 GENERAL Q. What is the Cisco Security Monitoring, Analysis and Response System? A. The Cisco Security Monitoring, Analysis and Response System

More information

McAfee Enterprise Security Manager 9.5.0

McAfee Enterprise Security Manager 9.5.0 Release Notes McAfee Enterprise Security Manager 9.5.0 Contents About this release New features for 9.5.0 Resolved issues Known issues Upgrade instructions Find product documentation About this release

More information

Security in the Privileged Remote Access Appliance

Security in the Privileged Remote Access Appliance Security in the Privileged Remote Access Appliance 2003-2018 BeyondTrust, Inc. All Rights Reserved. BEYONDTRUST, its logo, and JUMP are trademarks of BeyondTrust, Inc. Other trademarks are the property

More information

Cisco ISE Ports Reference

Cisco ISE Ports Reference Cisco ISE Infrastructure, page 1 Cisco ISE Administration Node Ports, page 2 Cisco ISE Monitoring Node Ports, page 4 Cisco ISE Policy Service Node Ports, page 5 Cisco ISE pxgrid Service Ports, page 10

More information

Ports and Protocols. Clearswift SECURE ICAP Gateway v4.3. Version 01 14/03/2016. Clearswift Public

Ports and Protocols. Clearswift SECURE ICAP Gateway v4.3. Version 01 14/03/2016. Clearswift Public Clearswift SECURE ICAP Gateway v4.3 Version 01 14/03/2016 Clearswift Public Copyright Version 1.0, March, 2016 Published by Clearswift Ltd. 1995 2016 Clearswift Ltd. All rights reserved. The materials

More information

Ports and Protocols. Clearswift SECURE ICAP Gateway v4.8. Version 2.0. July Clearswift Public

Ports and Protocols. Clearswift SECURE ICAP Gateway v4.8. Version 2.0. July Clearswift Public Clearswift SECURE ICAP Gateway v4.8 Version 2.0 July 2018 Clearswift Public Copyright Version 2.0, July, 2018 Published by Clearswift Ltd. 1995 2018 Clearswift Ltd. All rights reserved. The materials contained

More information

Dell Compellent FS8600

Dell Compellent FS8600 Dell Compellent FS8600 Network-Attached Storage (NAS) Networking Best Practices Guide Dell Compellent Technical Solutions Group July 2013 THIS BEST PRACTICES GUIDE IS FOR INFORMATIONAL PURPOSES ONLY, AND

More information

Ports and Protocols. Clearswift SECURE ICAP Gateway v4.9. Version 2.3. November Clearswift Public

Ports and Protocols. Clearswift SECURE ICAP Gateway v4.9. Version 2.3. November Clearswift Public Clearswift SECURE ICAP Gateway v4.9 Version 2.3 November 2018 Clearswift Public Copyright Version 2.3, November 2018 Published by Clearswift Ltd. 1995 2018 Clearswift Ltd. All rights reserved. The materials

More information

Compare Security Analytics Solutions

Compare Security Analytics Solutions Compare Security Analytics Solutions Learn how Cisco Stealthwatch compares with other security analytics products. This solution scales easily, giving you visibility across the entire network. Stealthwatch

More information

IBM Security QRadar Version Architecture and Deployment Guide IBM

IBM Security QRadar Version Architecture and Deployment Guide IBM IBM Security QRadar Version 7.3.1 Architecture and Deployment Guide IBM Note Before you use this information and the product that it supports, read the information in Notices on page 41. Product information

More information

Cisco ISE Ports Reference

Cisco ISE Ports Reference Cisco ISE Infrastructure Cisco ISE Infrastructure, on page 1 Cisco ISE Administration Node Ports, on page 2 Cisco ISE Monitoring Node Ports, on page 4 Cisco ISE Policy Service Node Ports, on page 5 Inline

More information

McAfee Enterprise Security Manager 11.1.x Release Notes

McAfee Enterprise Security Manager 11.1.x Release Notes McAfee Enterprise Security Manager 11.1.x Release Notes Contents Installation information What's new in the 11.1.3 update Resolved issues in update 11.1.3 Flash to HTML migration Installation information

More information

McAfee ESM Release 9.1.3

McAfee ESM Release 9.1.3 McAfee Release Notes McAfee ESM Release 9.1.3 October 15, 2012 Copyright 2012 McAfee, Inc. All rights reserved worldwide. CONTENTS ================================================================ CONTENTS...

More information

Security, Internet Access, and Communication Ports

Security, Internet Access, and Communication Ports Security, Internet Access, and Communication Ports The following topics provide information on system security, internet access, and communication ports: Security Requirements Security Requirements, on

More information

Avaya Port Matrix. Avaya Orchestrator 1.4. Issue 1.0 November 2, November 2018 Avaya Port Matrix: Avaya Orchestration 1.4 1

Avaya Port Matrix. Avaya Orchestrator 1.4. Issue 1.0 November 2, November 2018 Avaya Port Matrix: Avaya Orchestration 1.4 1 Avaya Port Matrix Avaya Orchestrator 1.4 Issue 1.0 November 2, 2018 November 2018 Avaya Port Matrix: Avaya Orchestration 1.4 1 ALL INFORMATION IS BELIEVED TO BE CORRECT AT THE TIME OF PUBLICATION AND IS

More information

McAfee Data Loss Prevention 9.3.3

McAfee Data Loss Prevention 9.3.3 Release Notes Revision A McAfee Data Loss Prevention 9.3.3 Contents About this release Enhancements Resolved issues Installation instructions Known issues Find product documentation About this release

More information

Port Utilization in Finesse

Port Utilization in Finesse Utilization in Finesse Utilization Table Columns, page 1 Finesse Utilization, page 2 Utilization Table Columns The columns in the port utilization tables in this document describe the following: A value

More information

OpenManage Integration for VMware vcenter Version 4.1. Compatibility Matrix

OpenManage Integration for VMware vcenter Version 4.1. Compatibility Matrix OpenManage Integration for VMware vcenter Version 4.1 Compatibility Matrix tes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION:

More information

Cisco ISE Ports Reference

Cisco ISE Ports Reference Cisco ISE Infrastructure, page 1 Cisco ISE Administration Node Ports, page 2 Cisco ISE Monitoring Node Ports, page 3 Cisco ISE Policy Service Node Ports, page 4 Cisco ISE pxgrid Service Ports, page 8 OCSP

More information

Dell EMC OpenManage Version Port Information Guide. Version 9.1

Dell EMC OpenManage Version Port Information Guide. Version 9.1 Dell EMC OpenManage Version Information Guide Version 9.1 tes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates

More information

Requirements and Dependencies

Requirements and Dependencies CHAPTER 2 You can install and use Security Manager as a standalone product or in combination with several other Cisco Security Management Suite applications, including optional applications that you can

More information

McAfee Data Loss Prevention 9.3.2

McAfee Data Loss Prevention 9.3.2 Release Notes Revision A McAfee Data Loss Prevention 9.3.2 Contents About this release Enhancements Resolved issues Installation instructions Known issues Find product documentation About this release

More information

Application Discovery Manager User s Guide vcenter Application Discovery Manager 6.2.2

Application Discovery Manager User s Guide vcenter Application Discovery Manager 6.2.2 Application Discovery Manager User s Guide vcenter Application Discovery Manager 6.2.2 This document supports the version of each product listed and supports all subsequent versions until the document

More information

Dell OpenManage Port Information Guide Version 7.2

Dell OpenManage Port Information Guide Version 7.2 Dell OpenManage Port Information Guide Version 7.2 tes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your computer. CAUTION: A CAUTION indicates

More information

All Events. One Platform.

All Events. One Platform. All Events. One Platform. Industry s first IT ops platform that truly correlates the metric, flow and log events and turns them into actionable insights. Correlate Integrate Analyze www.motadata.com Motadata

More information

IMC Network Traffic Analyzer 7.3 (E0504) Copyright 2015, 2017 Hewlett Packard Enterprise Development LP

IMC Network Traffic Analyzer 7.3 (E0504) Copyright 2015, 2017 Hewlett Packard Enterprise Development LP Network Traffic Analyzer 7.3 (E0504) Copyright 2015, 2017 Hewlett Packard Enterprise Development LP Table of Contents 1. What's New in this Release 2. Problems Fixed in this Release 3. Software Distribution

More information

akkadian Global Directory 3.0 System Administration Guide

akkadian Global Directory 3.0 System Administration Guide akkadian Global Directory 3.0 System Administration Guide Updated July 19 th, 2016 Copyright and Trademarks: I. Copyright: This website and its content is copyright 2014 Akkadian Labs. All rights reserved.

More information

Pass4sure q. Cisco Securing Cisco Networks with Sourcefire IPS

Pass4sure q. Cisco Securing Cisco Networks with Sourcefire IPS Pass4sure.500-285.42q Number: 500-285 Passing Score: 800 Time Limit: 120 min File Version: 6.1 Cisco 500-285 Securing Cisco Networks with Sourcefire IPS I'm quite happy to announce that I passed 500-285

More information

Understanding the ACS Server Deployment

Understanding the ACS Server Deployment CHAPTER 1 This chapter provides an overview of possible ACS server deployments and their components. This chapter contains: Deployment Scenarios, page 1-1 Understanding the ACS Server Setup, page 1-5 Deployment

More information

Cisco Stealthwatch Endpoint License with Cisco AnyConnect NVM

Cisco Stealthwatch Endpoint License with Cisco AnyConnect NVM Cisco Stealthwatch Endpoint License with Cisco AnyConnect NVM How to implement the Cisco Stealthwatch Endpoint License with the Cisco AnyConnect Network Visibility Module Table of Contents About This Document...

More information

SYSLOG and SUPERVISOR S WORKSHOP Knowledge Module for PATROL - Data Sheet Version Made by AXIVIA Conseil

SYSLOG and SUPERVISOR S WORKSHOP Knowledge Module for PATROL - Data Sheet Version Made by AXIVIA Conseil SYSLOG and SUPERVISOR S WORKSHOP Knowledge Module for PATROL - Data Sheet Version 1.6.01 Made by http://www.axivia.com/ SUMMARY SYSLOG and SUPERVISOR S WORKSHOP Knowledge Module for PATROL integrates a

More information

Technical Response Logging and Monitoring Requirements December 23, 2010

Technical Response Logging and Monitoring Requirements December 23, 2010 Technical Response Logging and Monitoring Requirements December 23, 2010 This technical response documents the capabilities of CorreLog, Inc., Logging and Monitoring Summary and Recommendations. A high-level

More information

Securing CS-MARS C H A P T E R

Securing CS-MARS C H A P T E R C H A P T E R 4 Securing CS-MARS A Security Information Management (SIM) system can contain a tremendous amount of sensitive information. This is because it receives event logs from security systems throughout

More information

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010. Upgrading to EventTracker v6.4 b50 8815 Centre Park Drive Publication Date: Feb 17, 2010 Columbia MD 21045 U.S. Toll Free: 877.333.1433 Abstract The purpose of this document is to help users upgrade from

More information

SIEM Product Comparison

SIEM Product Comparison SIEM Product Comparison SIEM Technology Space SIEM market analysis of the last 3 years suggest: Market consolidation of SIEM players (25 vendors in 2011 to 16 vendors in 2013) Only products with technology

More information

Security in Bomgar Remote Support

Security in Bomgar Remote Support Security in Bomgar Remote Support 2018 Bomgar Corporation. All rights reserved worldwide. BOMGAR and the BOMGAR logo are trademarks of Bomgar Corporation; other trademarks shown are the property of their

More information

Network Security Platform 8.1

Network Security Platform 8.1 8.1.7.91-8.1.3.124-2.11.9 Manager-XC-Cluster Release Notes Network Security Platform 8.1 Revision B Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Subscriber Data Correlation

Subscriber Data Correlation Subscriber Data Correlation Application of Cisco Stealthwatch to Service Provider mobility environment Introduction With the prevalence of smart mobile devices and the increase of application usage, Service

More information

ManageEngine EventLog Analyzer Quick Start Guide

ManageEngine EventLog Analyzer Quick Start Guide ManageEngine EventLog Analyzer Quick Start Guide Contents Installing and starting EventLog Analyzer Connecting to the EventLog Analyzer server Adding devices for monitoring Adding Windows devices Adding

More information

Proficy Application Suite Port (Firewall) Requirements Plant Applications, SOA/Workflow, Vision, Historian, Universal Client (UC), and Licensing

Proficy Application Suite Port (Firewall) Requirements Plant Applications, SOA/Workflow, Vision, Historian, Universal Client (UC), and Licensing Proficy Application Suite Port (Firewall) Requirements Plant Applications, SOA/Workflow, Vision, Historian, Universal Client (UC), and Licensing Document Version 2018.02.20 The following tables depict

More information

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1 9.1.7.11-9.1.7.4 Manager-Virtual IPS Release Notes McAfee Network Security Platform 9.1 Revision C Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Dell OpenManage Port Information Guide Version 7.4

Dell OpenManage Port Information Guide Version 7.4 Dell OpenManage Information Guide Version 7.4 tes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your computer. CAUTION: A CAUTION indicates either

More information

ASA/PIX Security Appliance

ASA/PIX Security Appliance I N D E X A AAA, implementing, 27 28 access to ASA/PIX Security Appliance monitoring, 150 151 securing, 147 150 to websites, blocking, 153 155 access control, 30 access policies, creating for web and mail

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.86-8.3.7.56 Manager-Virtual IPS Release Notes McAfee Network Security Platform 8.3 Revision C Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Open Mic #13: Log Source Protocols

Open Mic #13: Log Source Protocols IBM Security QRadar April 28, 2016 Open Mic #13: Log Source Protocols Panelists Colin Hay QRadar Ecosystem Team Lead Chris Collins Integration Team Lead L3/Maintenance Randika Upathilake Integration Team

More information

Optimizing Security for Situational Awareness

Optimizing Security for Situational Awareness Optimizing Security for Situational Awareness BRIAN KENYON McAfee Session ID: SPO1-106 Session Classification: Intermediate p gg able=network_objects, Operation=Update,Administrator=fwadmin, Machine=cp-mgmt-

More information

Clearswift SECURE Exchange Gateway V4.8

Clearswift SECURE Exchange Gateway V4.8 Clearswift SECURE Exchange Gateway V4.8 Ports and Protocols Issue 2.2 September 2018 Copyright Published by Clearswift Ltd. 1995 2018 Clearswift Ltd. All rights reserved. The materials contained herein

More information

JSA Common Ports Lists

JSA Common Ports Lists Juniper Secure Analytics Release 2014.6 Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA 408-745-2000 www.juniper.net Published: 2016-04-21 Copyright Notice Copyright 2016 Juniper

More information

Port Mirroring in CounterACT. CounterACT Technical Note

Port Mirroring in CounterACT. CounterACT Technical Note Table of Contents About Port Mirroring and the Packet Engine... 3 Information Based on Specific Protocols... 4 ARP... 4 DHCP... 5 HTTP... 6 NetBIOS... 7 TCP/UDP... 7 Endpoint Lifecycle... 8 Active Endpoint

More information

Dell OpenManage Version 8.5 Port Information Guide

Dell OpenManage Version 8.5 Port Information Guide Dell OpenManage Version 8.5 Information Guide tes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either

More information

McAfee Advanced Threat Defense 3.4.4

McAfee Advanced Threat Defense 3.4.4 Release Notes McAfee Advanced Threat Defense 3.4.4 Revision B Contents About this release New Features Enhancements Resolved issues Installation and upgrade notes Known issues Product documentation About

More information

Exam Name: Riverbed Certified Solutions Professional - Network Performance Management

Exam Name: Riverbed Certified Solutions Professional - Network Performance Management Vendor: Riverbed Exam Code: 299-01 Exam Name: Riverbed Certified Solutions Professional - Network Performance Management Version: Demo QUESTION 1 When creating an analytic service, the discovery process

More information

HPE Security ArcSight Connectors

HPE Security ArcSight Connectors HPE Security ArcSight Connectors SmartConnector Release Notes 7.6.0.8009.0 May 15, 2017 HPE Security ArcSight SmartConnector Release Notes 7.6.0.8009.0 May 15, 2017 Copyright 2010 2017 Hewlett Packard

More information

Manual Ftp Windows Server 2008 R2 Enterprise Virtual Edition

Manual Ftp Windows Server 2008 R2 Enterprise Virtual Edition Manual Ftp Windows Server 2008 R2 Enterprise Virtual Edition Including virtual paths in "Maximum Directory Size" calculations. 77 Case File: Custom FTP command response. 101 support through email, phone,

More information

OER uses the following default value if this command is not configured or if the no form of this command is entered: timer: 300

OER uses the following default value if this command is not configured or if the no form of this command is entered: timer: 300 holddown holddown To configure the Optimized Edge Routing (OER) prefix route dampening timer to set the minimum period of time that a new exit must be used before an alternate exit can be selected, use

More information

IMC Network Traffic Analyzer 7.2 (E0401P04) Copyright 2016 Hewlett Packard Enterprise Development LP

IMC Network Traffic Analyzer 7.2 (E0401P04) Copyright 2016 Hewlett Packard Enterprise Development LP Network Traffic Analyzer 7.2 (E0401P04) Copyright 2016 Hewlett Packard Enterprise Development LP Table of Contents 1. What's New in this Release 2. Problems Fixed in this Release 3. Software Distribution

More information

vcenter Server Installation and Setup Update 1 Modified on 30 OCT 2018 VMware vsphere 6.7 vcenter Server 6.7

vcenter Server Installation and Setup Update 1 Modified on 30 OCT 2018 VMware vsphere 6.7 vcenter Server 6.7 vcenter Server Installation and Setup Update 1 Modified on 30 OCT 2018 VMware vsphere 6.7 vcenter Server 6.7 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

Deploying VMware Identity Manager in the DMZ. JULY 2018 VMware Identity Manager 3.2

Deploying VMware Identity Manager in the DMZ. JULY 2018 VMware Identity Manager 3.2 Deploying VMware Identity Manager in the DMZ JULY 2018 VMware Identity Manager 3.2 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have

More information

Ports and Protocols. Clearswift SECURE Web Gateway v4.x. Issue /04/2017. Clearswift Public

Ports and Protocols. Clearswift SECURE Web Gateway v4.x. Issue /04/2017. Clearswift Public Clearswift SECURE Web Gateway v4.x Issue 1.7 18/04/2017 Clearswift Public Copyright Version 1.7, April, 2017 Published by Clearswift Ltd. 1995 2017 Clearswift Ltd. All rights reserved. The materials contained

More information

FireSIGHT Virtual Installation Guide

FireSIGHT Virtual Installation Guide Version 5.3.1 July 17, 2014 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL

More information

Cisco Exam Questions & Answers

Cisco Exam Questions & Answers Cisco 300-208 Exam Questions & Answers Number: 300-208 Passing Score: 800 Time Limit: 120 min File Version: 38.4 http://www.gratisexam.com/ Exam Code: 300-208 Exam Name: Implementing Cisco Secure Access

More information

McAfee Network Security Platform

McAfee Network Security Platform Revision E McAfee Network Security Platform (9.1.7.11-9.1.3.4 Manager-M-series, Mxx30-series, XC Cluster Release Notes) Contents About this release New features Enhancements Resolved issues Installation

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.28-8.3.7.6 Manager-Virtual IPS Release Notes McAfee Network Security Platform 8.3 Revision B Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

<Partner Name> <Partner Product> RSA SECURID ACCESS. VMware Horizon View 7.2 Clients. Standard Agent Client Implementation Guide

<Partner Name> <Partner Product> RSA SECURID ACCESS. VMware Horizon View 7.2 Clients. Standard Agent Client Implementation Guide RSA SECURID ACCESS Standard Agent Client Implementation Guide VMware Horizon View 7.2 Clients Daniel R. Pintal, RSA Partner Engineering Last Modified: September 14, 2017

More information

Seceon s Open Threat Management software

Seceon s Open Threat Management software Seceon s Open Threat Management software Seceon s Open Threat Management software (OTM), is a cyber-security advanced threat management platform that visualizes, detects, and eliminates threats in real

More information

Security Manager Policy Table Lookup from a MARS Event

Security Manager Policy Table Lookup from a MARS Event CHAPTER 17 Security Manager Policy Table Lookup from a MARS Event This chapter describes how to configure and use Security Manager and MARS so as to enable bi-directional lookup between events recieved

More information

IBM IBM Internet Security Systems Technical Test V1. Download Full Version :

IBM IBM Internet Security Systems Technical Test V1. Download Full Version : IBM 000-530 IBM Internet Security Systems Technical Test V1 Download Full Version : https://killexams.com/pass4sure/exam-detail/000-530 QUESTION: 109 During a Proventia Server IPS presentation, the client

More information

Manual Ftp Windows Server 2008 Firewall Port Forwarding

Manual Ftp Windows Server 2008 Firewall Port Forwarding Manual Ftp Windows Server 2008 Firewall Port Forwarding SMB/CIFS, FTP and WebDAV access is available allowing the use of existing client software to access the Alfresco data store. This allows you to browse

More information

SecureVue. SecureVue

SecureVue. SecureVue SecureVue SecureVue Detects Cyber-Attacks Before They Impact Your Business Provides Situational Awareness to Proactively Address Enterprise Threats Ensures Quick and Easy Compliance Reporting and Documentation

More information

Cisco Exam. Volume: 223 Questions. Question No: 1 Which three commands can be used to harden a switch? (Choose three.)

Cisco Exam. Volume: 223 Questions. Question No: 1 Which three commands can be used to harden a switch? (Choose three.) Volume: 223 Questions Question No: 1 Which three commands can be used to harden a switch? (Choose three.) A. switch(config-if)# spanning-tree bpdufilter enable B. switch(config)# ip dhcp snooping C. switch(config)#

More information

Stonesoft Management Center. Release Notes Revision A

Stonesoft Management Center. Release Notes Revision A Stonesoft Management Center Release Notes 6.1.3 Revision A Contents About this release on page 2 System requirements on page 2 Build version on page 3 Compatibility on page 4 New features on page 5 Enhancements

More information

McAfee Network Security Platform 9.2

McAfee Network Security Platform 9.2 McAfee Network Security Platform 9.2 (9.2.7.22-9.2.7.20 Manager-Virtual IPS Release Notes) Contents About this release New features Enhancements Resolved issues Installation instructions Known issues Product

More information

Configuration Export and Import

Configuration Export and Import This chapter includes the following sections:, page 1 From the Export & Import, you can schedule configuration backup for Cisco UCS Central and the registered Cisco UCS Domains. You can schedule export

More information

User and System Administration

User and System Administration CHAPTER 5 This chapter provides information about performing user and system administration tasks in Cisco Prime Network Analysis Module 5.1and generating diagnostic information for obtaining technical

More information

2 Hardening the appliance

2 Hardening the appliance 2 Hardening the appliance 2.1 Objective For security reasons McAfee always recommends putting the McAfee Web Gateway appliance behind a firewall. For added security McAfee also recommends that the appliance

More information

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1 9.1.7.15-9.1.5.9 Manager-NS-series Release Notes McAfee Network Security Platform 9.1 Revision A Contents About this release New features Enhancements Resolved issues Installation instructions Known issues

More information

Dell OpenManage Version 8.4 Port Information Guide

Dell OpenManage Version 8.4 Port Information Guide Dell OpenManage Version 8.4 Information Guide tes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either

More information

McAfee Data Loss Prevention 9.3.1

McAfee Data Loss Prevention 9.3.1 Release Notes Revision A McAfee Data Loss Prevention 9.3.1 Contents About this release Enhancements Resolved issues Installation instructions Known issues Find product documentation About this release

More information

Sophos Virtual Appliance. setup guide

Sophos Virtual  Appliance. setup guide Sophos Virtual Email Appliance setup guide Contents Installing a virtual appliance...1 Prerequisites...3 Enabling Port Access...4 Downloading Virtual Appliance Files... 7 Determining Disk Space and Memory

More information

Deploying VMware Identity Manager in the DMZ. SEPT 2018 VMware Identity Manager 3.3

Deploying VMware Identity Manager in the DMZ. SEPT 2018 VMware Identity Manager 3.3 Deploying VMware Identity Manager in the DMZ SEPT 2018 VMware Identity Manager 3.3 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have

More information

Top 10 use cases of HP ArcSight Logger

Top 10 use cases of HP ArcSight Logger Top 10 use cases of HP ArcSight Logger Sridhar Karnam @Sri747 Karnam@hp.com #HPSecure Big data is driving innovation The Big Data will continue to expand Collect Big Data for analytics Store Big Data for

More information

Clearswift SECURE Exchange Gateway V4.9

Clearswift SECURE Exchange Gateway V4.9 Clearswift SECURE Exchange Gateway V4.9 Ports and Protocols Issue 2.4 November 2018 Copyright Published by Clearswift Ltd. 1995 2018 Clearswift Ltd. All rights reserved. The materials contained herein

More information

Configuring Antivirus Devices

Configuring Antivirus Devices CHAPTER 9 Revised: November 11, 2007 Antivirus (AV) devices provide detection and prevention against known viruses and anomalies. This chapter describes how to configure and add the following devices and

More information

Selftestengine q

Selftestengine q Selftestengine 700-281 49q Number: 700-281 Passing Score: 800 Time Limit: 120 min File Version: 18.5 http://www.gratisexam.com/ 700-281 Web Security for Field Engineers Still Valid in Egypt, Passed today

More information

Best Practices: Server Security Hardening

Best Practices: Server Security Hardening The following sections explain how to enhance server security by eliminating or controlling individual points of security exposure. Disable Insecure Services, on page 1 Disable Root Access, on page 1 Use

More information

The Bomgar Appliance in the Network

The Bomgar Appliance in the Network The Bomgar Appliance in the Network The architecture of the Bomgar application environment relies on the Bomgar Appliance as a centralized routing point for all communications between application components.

More information