Endpoint Intelligence Agent 2.2.0

Similar documents
McAfee Firewall Enterprise and 8.3.x

McAfee Endpoint Security

Product Guide Revision A. Endpoint Intelligence Agent 2.2.0

Network Security Platform 8.1

Release Notes McAfee Change Control 8.0.0

McAfee Firewall Enterprise

Network Security Platform 8.1

Network Security Platform 8.1

McAfee Network Security Platform 9.1

Network Security Platform 8.1

McAfee Endpoint Security

McAfee Network Security Platform 8.1

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3

Network Security Platform 8.1

Installing Client Proxy software

McAfee Network Security Platform

McAfee Network Security Platform 9.1

McAfee Security for Microsoft SharePoint Hotfix

Network Security Platform 8.1

McAfee Endpoint Upgrade Assistant Product Guide. (McAfee epolicy Orchestrator 5.9.0)

Release Notes McAfee Change Control 7.0.0

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1

Release Notes McAfee Application Control 6.1.2

McAfee Endpoint Upgrade Assistant Product Guide. (McAfee epolicy Orchestrator)

Deploying the hybrid solution

McAfee Network Security Platform 8.3

McAfee Network Security Platform 9.1

McAfee epolicy Orchestrator Release Notes

McAfee Data Loss Prevention Endpoint 10.0

McAfee Network Security Platform 8.3

McAfee Data Loss Prevention 9.3.2

McAfee Security for Microsoft Exchange Hotfix Release Notes

McAfee Network Security Platform 8.3

McAfee epolicy Orchestrator 5.x

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.1

McAfee Data Loss Prevention Endpoint

Product Guide. McAfee Endpoint Upgrade Assistant 1.5.0

McAfee Firewall Enterprise 8.3.2P05

Stonesoft Management Center. Release Notes Revision C

McAfee Network Security Platform 9.2

McAfee Data Loss Prevention Endpoint

McAfee Network Security Platform 9.1

McAfee Network Security Platform 8.3

Product overview. McAfee Web Protection Hybrid Integration Guide. Overview

McAfee MVISION Endpoint 1808 Installation Guide

McAfee Network Security Platform 8.3

McAfee Endpoint Upgrade Assistant 2.3.x Product Guide

Product Guide. McAfee Endpoint Upgrade Assistant 1.4.0

============================================================

McAfee MVISION Endpoint 1811 Installation Guide

McAfee Network Security Platform 9.1

McAfee File and Removable Media Protection Installation Guide

McAfee Network Security Platform

McAfee Virtual Network Security Platform 8.4 Revision A

Network Security Platform 8.1

Data Loss Prevention Endpoint

McAfee Content Security Reporter Installation Guide. (McAfee epolicy Orchestrator)

McAfee Advanced Threat Defense Release Notes

McAfee Network Security Platform 9.2

McAfee Content Security Reporter Release Notes. (McAfee epolicy Orchestrator)

McAfee Endpoint Security Migration Guide. (McAfee epolicy Orchestrator)

McAfee Network Security Platform

Product Guide. McAfee GetClean. version 2.0

McAfee Network Security Platform 9.2

Release Notes McAfee Application Control 6.1.0

McAfee Web Gateway

McAfee epolicy Orchestrator Release Notes

This document contains important information about the current release. We strongly recommend that you read the entire document.

McAfee Data Loss Prevention Endpoint 9.4.0

Network Security Platform 8.1

McAfee Endpoint Security Installation Guide. (McAfee epolicy Orchestrator)

Network Security Platform 8.1

McAfee Host Intrusion Prevention Administration Course

McAfee Content Security Reporter 2.6.x Installation Guide

McAfee Next Generation Firewall 5.9.1

McAfee Active Response 2.1.0

Forcepoint Sidewinder

McAfee Network Security Platform 9.1

McAfee Endpoint Upgrade Assistant 1.5.0

Network Security Platform 8.1

Stonesoft Management Center. Release Notes Revision B

McAfee SiteAdvisor Enterprise 3.5.0

About this release This document contains important information about the current release. We strongly recommend that you read the entire document.

NGFW Security Management Center

NGFW Security Management Center

Network Security Platform 8.1

Network Security Platform 8.1

McAfee Application Control Windows Installation Guide. (McAfee epolicy Orchestrator)

NGFW Security Management Center

NGFW Security Management Center

McAfee File and Removable Media Protection 6.0.0

NGFW Security Management Center

Stonesoft Management Center. Release Notes Revision A

McAfee Data Loss Prevention 9.3.3

McAfee Client Proxy Installation Guide

McAfee Policy Auditor 6.2.2

Stonesoft Management Center. Release Notes Revision A

Transcription:

Release Notes Endpoint Intelligence Agent 2.2.0 Revision A Contents About this release New features Resolved issues Installation instructions Known issues Find product documentation About this release This document contains important information about the current release. We strongly recommend that you read the entire document. The following are the product requirements for McAfee Endpoint Intelligence Agent (Endpoint Intelligence Agent or McAfee EIA) 2.2.0. McAfee epolicy Orchestrator (McAfee epo ) server Version 4.6.5, 5.x, and later McAfee Agent Version 4.8.0 Patch 2 McAfee Endpoint Intelligence Manager Version 2.2.0 The following are the integrated product requirements for Endpoint Intelligence Agent 2.2.0. McAfee Firewall Enterprise Control Center McAfee Firewall Enterprise Version 5.3.1 and later Version 8.3.1 with the latest P-patch, version 8.3.2, and later Version 8.3.1 with the latest P-patch McAfee EIA works only with the Network Integrity Agent 1.0.0 features. Version 8.3.1 without the latest P-patch McAfee EIA does not communicate with the Firewall Enterprise. McAfee Network Threat Behavior Analysis Version 8.1.3.x and later 1

McAfee Network Security Manager McAfee Improvement Program (PIP) Version 8.1.3.x and later Version 1.2 and later Firewall Enterprise epo extension 5.3.0 or earlier version can't co-exist with Endpoint Intelligence Management epo extension. New features This release of Endpoint Intelligence Agent includes the following new features and enhancements: Platform support McAfee EIA is now supported on Microsoft Windows 8.1 and Windows Server 2012 (2012 and 2012 R2 64-bit Enterprise edition) operating systems. The abort command used by McAfee EIA installer is not supported on these platforms. If McAfee EIA installer has to abort, the installation or uninstallation of McAfee EIA fails. Trust information and trust value expiry time McAfee EIA receives notification whenever an executable initiates traffic. Endpoint Intelligence Agent uses the public key of the executable signer and SHA1 of the public key to look up the cache to compute trust information. If available, the trust details are sent as part of the metadata to the supported network devices. If the trust information is not available, McAfee EIA consolidates the missing SHA1s for executables and DLLs and requests supported network device for trust details so that it can send trust information for follow-on traffic from the same executable. The trust values are good or unknown for an executable. When trust value of a particular SHA1 expires, a request is sent to NTBA to revalidate the trust value. Integration with McAfee Improvement Program (PIP) McAfee Improvement Program (formerly Telemetry) collects the data from the client systems where epo-managed McAfeeproducts are installed. The data collected by Improvement Program is used by McAfee to improve the overall user experience, provide better-performing product features, and perform proactive data collection for faster troubleshooting of customer issues. You can install McAfee Improvement Program when installing the McAfee epo 5.0 and later and McAfee Agent 4.8 and later. The collected data is aggregated on the McAfee epo server and sent to the McAfee Improvement Program server once a day (default collection period) and stored at \TelemetryData. The collected data is filtered to remove any personally identifiable information. Open SSL upgrade McAfee EIA now supports OpenSSL version 1.0.1f. Improved Log Collector 2

A time stamp is appended to each CAB file so that you can track all the collected logs in the format EiaDiagnosisLogs_<month_date_hour_minutes>.CAB, for example, EiaDiagnosisLogs_Mar_18_11_08.CAB. At any time. when you execute the Log Collector, the generated CAB file is placed at C:\Program Files\McAfee\Endpoint Intelligence Agent\x86\. Resolved issues These issues are resolved in this release of the product. For a list of issues fixed in earlier releases, see the Release Notes for the specific release. The following table lists the medium-severity Endpoint Intelligence Agent issues. ID # Issue Description 936537 Signer name is listed as a detached signature for system files instead of being listed as Microsoft Corporation. 943182 Some of the mandatory fields, such as version information or path, are missing in the reputation cache. 924022 When upgrading from McAfee EIA 2.0 to 2.1, McTray crashes when the McAfee EIA user interface is open. 927851 LogCollector tool is unable to generate a CAB file in the installation folder if McTray logs are present. 925264 After uninstalling McAfee EIA from an endpoint, the installation folder has leftover files and doesn't get deleted. 936557 For Java 6.0.260.3, McAfee EIA fails to send reputation to NTBA in metadata. Installation instructions Review the following before you install the Endpoint Intelligence Agent: Make sure your Firewall Enterprise, Control Center, NTBA, epolicy Orchestrator, and managed systems meet the necessary requirements. Endpoint Intelligence Agent can be installed on these Microsoft operating systems: Only enterprise editions of Server operating systems are supported. Windows XP Service Pack 2 and later Windows Server 2008 R2 (64-bit) Windows 7 Windows Server 2008 Windows 8.1 Windows Server 2012 (64-bit) Windows Server 2003 Service Pack 2 and later Windows Server 2012 R2 (64-bit) Windows Server 2003 R2 Service Pack 2 and later McAfee recommends running Endpoint Intelligence Agent on systems with at least 2 GB of RAM. If you uninstall McAfee EIA and install any version, you must restart your system for the installed McAfee EIA version to function properly. 3

Upgrade Endpoint Intelligence Agent You can upgrade from Endpoint Intelligence Agent 2.0.0 or 2.1.0 to 2.2.0. Upgrading from an earlier version of the Endpoint Intelligence Agent (previously known as Network Integrity Agent) is not supported. 1 Download the latest Endpoint Intelligence Agent package.zip file. 2 Upload the package into the epolicy Orchestrator master repository. 3 Deploy the agent on epo-managed endpoints. Endpoint Intelligence Agent and firecore files upgrade to the latest version. All upgrade attempts generate logs in the installation directory. If the upgrade fails, Endpoint Intelligence Agent restores to the previous version. To complete the upgrade process, you do not need to restart the system. Upgrade Endpoint Intelligence Manager You can upgrade from Endpoint Intelligence Manager 2.1.0 to 2.2.0. Upgrading from McAfee Firewall Enterprise epo extension to Endpoint Intelligence Manager 2.2.0 is not supported. 1 Download the latest Endpoint Intelligence Manager.zip file. 2 Install the extension on the epolicy Orchestrator server. The Endpoint Intelligence Manager 2.0.0 is not supported on epolicy Orchestrator server 5.1. To upgrade from epolicy Orchestrator server 5.0 to 5.1, first upgrade the Endpoint Intelligence Manager to 2.1.0. For complete set of instructions to set up Endpoint Intelligence Agent, see the McAfee Endpoint Intelligence Agent Guide. Known issues For a list of known issues in this product release, see this McAfee KnowledgeBase article: McAfee EIA issues: KB81466 Find product documentation Every McAfee product has a comprehensive set of documentation. 1 Go to the McAfee Technical Support ServicePortal at http://mysupport.mcafee.com. 2 Under Self Service, access the type of information you need: 4

To access... User documentation Do this... 1 Click Documentation. 2 Select a product, then select a version. 3 Select a product document. KnowledgeBase Click Search the KnowledgeBase for answers to your product questions. Click Browse the KnowledgeBase for articles listed by product and version. The related documents available with Endpoint Intelligence Agent are: McAfee Endpoint Intelligence Agent Guide McAfee Network Threat Behavior Analysis Appliance (NTBA Appliance) Administration Guide McAfee Firewall Enterprise Guide McAfee Firewall Enterprise Control Center Guide McAfee Improvement Program Quick Start Guide Copyright 2014 McAfee, Inc. Do not copy without permission. McAfee and the McAfee logo are trademarks or registered trademarks of McAfee, Inc. or its subsidiaries in the United States and other countries. Other names and brands may be claimed as the property of others. 0A-00