Hw t set up Dell SnicWALL Aventail SRA Appliance with OPSWAT GEARS Client Abut This Guide:... 2 End Pint Cntrl... 3 Device Prfile Definitin... 3 1
Abut This Guide: GEARS is a platfrm fr netwrk security management fr IT and security prfessinals that prvides visibility ver all types f endpint applicatins frm antivirus t hard disk encryptin and public file sharing, as well as the ability t enfrce cmpliance and detect advanced threats. Mre infrmatin n GEARS may be fund at http://www.pswatgears.cm/. GEARS can be leveraged by the Dell SnicWALL Aventail Secure Remte Access (SRA) Appliance End Pint Cntrl t prvide enhanced cmpliance checking capabilities. Once yu have deplyed the GEARS Client t yur devices and cnfigured yur cmpliance plicy thrugh the GEARS Plicy cnfiguratin page, the GEARS Client will stre the device s cmpliance status within the Windws Registry r Mac OS p-list. The Dell SnicWALL Aventail appliance can access and use this infrmatin thrugh a simple End Pint Cntrl functin, and can be used t determine if a device shuld be granted netwrk access, r n a cntinuus basis t ensure that a device shuld retain netwrk access based n the predefined security and cmpliance plicies established by the rganizatin. The steps fund within this dcument assume that this cnfiguratin is ccurring with the Aventail Management Cnsle. Mre infrmatin n the benefits f integrating GEARS with Dell SnicWALL Aventail Secure Remte Access (SRA) Appliance can be fund at http://www.pswatgears.cm/integratin/secure-access. 2014 OPSWAT, Inc. All rights reserved. OPSWAT, GEARS and the OPSWAT lg are trademarks f OPSWAT, Inc. All ther trademarks, trade names, service marks, service names and images mentined and/r used herein belng t their respective wners. 2
End Pint Cntrl A Dell SnicWALL Aventail Secure Remte Access (SRA) appliance can be cnfigured t utilize OPSWAT GEARS fr advanced threat detectin and cmpliance enfrcement fr remte users. These checks will ensure that endpint devices cnnecting t the netwrk are meeting all cmpliance requirements established by the rganizatin. The plicies can be easily cnfigured via the GEARS Dashbard, and will enable an administratr t ensure that the security and cmpliance requirements f an rganizatin are met n a cntinuus basis. Device Prfile Definitin In rder t cnfigure the End Pint Cntrl functin, yu first need t establish the Device Prfiles. Navigate t End Pint Cntrl under User Access, and then select the Device Prfiles tab. Step 1: Click n New and select Micrsft Windws frm the drp-dwn list. This will pen the Device Prfile Definitin windw, where yu can create yur device prfiles. We will be creating 3 device prfiles: Windws 32-bit, Windws 64-bit, and Mac OSX. Within the Device Prfile Definitin page specify the fllwing attributes: Name: GEARS-RegistryCheck-32bit Descriptin: Cmpliance check f 32bit Windws endpints fr GEARS registry Add Attribute(s) If yu are using the persistent, installed GEARS client: The first f 2 attributes: Type: Applicatin Applicatin: GearsAgentService.exe Click Add t Current Attributes. Type: Windws registry entry Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\OPSWAT\GEARS Client\Cnfig Value name: Plicy Registry entry: = Data: 1 3
If yu are using the n demand, prtable GEARS client: The first f 2 attributes: Type: Applicatin Applicatin: pswat-gears-d.exe Click Add t Current Attributes. Type: Windws registry entry Key Name: HKEY_CURRENT_USER\SOFTWARE\OPSWAT\GEARS OnDemand\Cnfig Value name: Plicy Registry entry: = Data: 1 Click Add t Current Attributes and then click Save and Add Anther. 4
Step 2: Fr the secnd Device Prfile Definitin page specify the fllwing attributes: Name: GEARS-RegistryCheck-64bit Descriptin: Cmpliance check f 64bit Windws endpints fr GEARS registry If yu are using the persistent, installed GEARS client: Add Attribute(s) The first f 2 attributes: Type: Applicatin Applicatin: GearsAgentService.exe Click Add t Current Attributes. Type: Windws registry entry Key Name: HKEY Lcal Machine\SOFTWARE\Ww6432Nde\OPSWAT\GEARS Client\Status Value name: Plicy Registry entry: = Data: 1 If yu are using the n demand, prtable GEARS client: The first f 2 attributes: Type: Applicatin Applicatin: pswat-gears-d.exe Click Add t Current Attributes. Type: Windws registry entry Key Name: HKEY_CURRENT_USER\SOFTWARE\OPSWAT\GEARS OnDemand\Cnfig Value name: Plicy Registry entry: = Data: 1 Click Add t Current Attributes and then click Save and Add Anther. 5
Step 3: Fr the final Device Prfile Definitin page specify the fllwing attributes: Name: GEARS-Check-Mac Descriptin: Cmpliance check f Mac endpints fr GEARS If yu are using the persistent, installed GEARS client: Add Attribute(s) Type: File name Value: File name: Applicatins/OPSWAT GEARS Client/Plicies/GEARS_<gears license key>_1.txt 6
If yu are using the n demand, prtable GEARS client: Add Attribute(s) Type: File name Value: File name: /Users/Dcuments/OPSWAT/GEARS OnDemand/ GEARS_<license_key>_<0 r 1> Click Add t Current Attributes, and then click Save. The file referenced, Applicatins/OPSWAT GEARS Client/Plicies/GEARS_<gears license key>_1.txt, r /Users/Dcuments/OPSWAT/GEARS OnDemand/ GEARS_<license_key>_<0 r 1>, includes the variable gears license key. This value will be yur Accunt Registratin Key, and the 1 represents the Plicy Value f a device that passes the plicy defined in the GEARS dashbard. This file includes a cmbinatin f 2 values, Plicy and LicenseKey, t ensure that the client installed is assigned t the Accunt that manages the defined Plices. Yur Device Prfiles shuld nw include yur 3 new prfiles. Yu can nw navigate t End Pint Cntrl Znes, t establish hw yu wish t manage the devices with these plicies. Depending n yur preference yu can create a Standard Zne, Deny Zne, r Quarantine Zne. Within these znes yu 7
are able t define the actin the netwrk shuld take when the devices pass the established plicies r fail the established plices. The checks can be a ne-time check when the endpint lgs in, r it can be a cntinuus check that validates the cmpliance state f the endpint thrughut the time within the netwrk. Fr mre infrmatin, r if yu have any questins abut the steps abve, please lg int the OPSWAT Prtal at https://myprtal.pswat.cm and submit a ticket t request assistance frm ur supprt team. 8