McAfee MER for EPO 3.1 Walkthrough Guide. About this guide This guide provides information on how to use McAfee MER for EPO 3.1.

Similar documents
Installing Client Proxy software

Deploying the hybrid solution

McAfee Application Control Windows Installation Guide. (McAfee epolicy Orchestrator)

Product overview. McAfee Web Protection Hybrid Integration Guide. Overview

McAfee File and Removable Media Protection Installation Guide

POC Installation Guide for McAfee EEFF v4.2.x using McAfee epo 4.6 and epo New Deployments Only Windows Deployment

McAfee Security for Microsoft SharePoint Hotfix

XIA Configuration Server

McAfee Security for Microsoft Exchange Hotfix Release Notes

Release Notes for McAfee(R) Security for Microsoft Exchange(TM) Version 8.0 Copyright (C) 2013 McAfee, Inc. All Rights Reserved

McAfee Client Proxy Installation Guide

McAfee SiteAdvisor Enterprise 3.5.0

Endpoint Intelligence Agent 2.2.0

Managing Client Proxy

McAfee Agent Interface Reference Guide. (McAfee epolicy Orchestrator Cloud)

McAfee Rogue Database Detection For use with epolicy Orchestrator Software

Quick Reference Guide Updating Anti-Virus to Microsoft Security Essentials. Check for McAfee EPO Agent

McAfee Endpoint Security Threat Prevention Installation Guide - macos

Resolution: The DataChannel servlet no longer stops working, regardless of the state of the DataChannel extension.

ForeScout Extended Module for IBM BigFix

McAfee File and Removable Media Protection 6.0.0

McAfee Agent 4.5 Product Guide

Installation Guide. McAfee Endpoint Security for Servers 5.0.0

Release Notes for McAfee(R) Security for Lotus Domino(TM) Version 7.5 with Patch 2 Hotfix Copyright (C) 2013 McAfee, Inc. All Rights Reserved

Revision A. McAfee Data Loss Prevention Endpoint 11.1.x Installation Guide

McAfee Red and Greyscale

McAfee Management of Native Encryption 3.0.0

McAfee Client Proxy Product Guide

========================================================== Release date: December 03, This release was developed and tested with:

McAfee epolicy Orchestrator Release Notes

McAfee Content Security Reporter Installation Guide. (McAfee epolicy Orchestrator)

McAfee Change Control and McAfee Application Control 8.0.0

McAfee Change Control and McAfee Application Control 6.1.4

Tzunami Deployer Hummingbird DM Exporter Guide

McAfee. Deployment and User Guide. epo 4 / Endpoint Encryption

Best Practices Guide. Amazon OpsWorks and Data Center Connector for AWS

McAfee MOVE AntiVirus Installation Guide. (McAfee epolicy Orchestrator)

McAfee Threat Intelligence Exchange Installation Guide. (McAfee epolicy Orchestrator)

McAfee Data Protection for Cloud 1.0.1

Installing Data Exchange Layer

McAfee Endpoint Security Threat Prevention Installation Guide - Linux

McAfee Gateway Appliance Patch 7.5.3

McAfee Endpoint Security Installation Guide. (McAfee epolicy Orchestrator)

McAfee Management for Optimized Virtual Environments AntiVirus 4.5.0

Boot Attestation Service 3.0.0

ForeScout Extended Module for IBM BigFix

Data Loss Prevention Discover 11.0

McAfee Endpoint Security

McAfee MVISION Endpoint 1811 Installation Guide

Installation Guide. . All right reserved. For more information about Specops Command and other Specops products, visit

Product Guide. McAfee Endpoint Upgrade Assistant 1.4.0

McAfee MVISION Endpoint 1808 Installation Guide

Important notice regarding accounts used for installation and configuration

McAfee epolicy Orchestrator Installation Guide

============================================================

Sophos Anti-Virus standalone startup guide. For Windows and Mac OS X

Installation Guide Revision B. McAfee Cloud Workload Security 5.0.0

Installation Guide. McAfee epolicy Orchestrator software D R A F T

MOVE AntiVirus page-level reference

Installation Guide. McAfee Web Gateway. for Riverbed Services Platform

Cisco Unified Customer Voice Portal

McAfee Data Loss Prevention Endpoint 10.0

Installation Guide. McAfee epolicy Orchestrator Software. Draft for Beta

McAfee epolicy Orchestrator 5.9.1

Using the SQL CI TeamCity plugin in SQL Automation Pack

Release Notes McAfee Change Control 8.0.0

MSI Admin Tool User Guide

MYOB Advanced Business

Release Notes McAfee Application Control 6.1.0

McAfee Security Connected Integrating epo and MFECC

File Uploader Application

McAfee Application Control Windows Installation Guide

McAfee Boot Attestation Service 3.5.0

============================================================ About this release:

Install and upgrade Qlik Sense. Qlik Sense 3.0 Copyright QlikTech International AB. All rights reserved.

McAfee Application Control/ McAfee Change Control Administration

Appendix A: Courseware setup

XLmanage Version 2.4. Installation Guide. ClearCube Technology, Inc.

2013 McAfee, Inc. All Rights Reserved. 1. epolicy Orchestrator 5.1 Essentials

Forescout. eyeextend for IBM BigFix. Configuration Guide. Version 1.2

Firewall Enterprise epolicy Orchestrator

SUREedge DR Installation Guide for Windows Hyper-V

McAfee Firewall Enterprise epolicy Orchestrator Extension

Deploying Code42 CrashPlan with Jamf Pro. Technical Paper Jamf Pro 9.0 or Later 21 January 2019

McAfee VirusScan and McAfee epolicy Orchestrator Administration Course

McAfee Firewall Enterprise and 8.3.x

McAfee MVISION Mobile MobileIron Integration Guide

Colligo Administrator 1.2. User Guide

Client Proxy interface reference

Client Proxy interface reference

McAfee Threat Intelligence Exchange Installation Guide

0. Introduction On-demand. Manual Backups Full Backup Custom Backup Store Your Data Only Exclude Folders.

McAfee Host Intrusion Prevention 8.0

SC-T35/SC-T45/SC-T46/SC-T47 ViewSonic Device Manager User Guide

Migrating vrealize Automation 6.2 to 7.1

McAfee Security Connected Integrating epo and MVM

McAfee Embedded Control McAfee epolicy Orchestrator Configuration Guide

ForeScout Extended Module for ServiceNow

Password Reset Utility. Configuration

ForeScout Extended Module for ServiceNow

Transcription:

McAfee MER for EPO 3.1 Walkthrough Guide About this guide This guide provides information on how to use McAfee MER for EPO 3.1.

2 1. Scope: The MER for epo tool runs MER (Minimum Escalations Requirements) through epo (epolicy Orchestrator). This product targets corporate users, where the administrator administers and manages a number of computers through epo. The purpose of this product is to enable the epo administrator to run MER on client computers to collect results and logs due to the intricacy associated with McAfee products installed on the client computers. Users can download MER for epo (epo-mer) from the Tools section on the ServicePortal at https://support.mcafee.com/epomer. A login to the ServicePortal is required. Alternatively, it can be downloaded through Software Manager within epo. This guide will cover using both methods. 2. Supported Operating Systems: NOTE: The epo administrator will be unable to push the MER package to operating systems which are not supported by MER for epo 3.1. The supported operating systems for the epo server include: Windows 2012 R2 Server Windows 2012 Server Windows 2008 R2 Server Windows 2008 Server The supported operating systems for the clients include: Windows 2012 R2 Server Windows 2012 Server Windows 2008 R2 Server Windows 2008 Server Windows 10 Windows 8.1 Windows 8 Windows 7 Windows Vista 3. Supported McAfee Products: The current list of supported McAfee products can be found at https://kc.mcafee.com/corporate/index?page=content&id=kb69396. 4. Installing MER for epo from ServicePortal 4.1 Download and extraction Download the latest MER for epo 3.1 Deployment and Update packages from the ServicePortal. Extract the Deployment package to a location. It will contain deployment and extension zip packages

3 4.2 Check in the MER for epo Deployment package 1. To check in the MER for epo package, log on to epo as an administrator and click Menu -> Software -> Master Repository 2. Click Check In Package. 3. Select Product or Update (.ZIP). 4. Browse for the package MER-FOR-EPO-3.1.0-DEPLOYMENTPKG.ZIP and then click Next.

4 5. Click Save. 4.3 Check in the MER for epo Update package 1. To check in the MER for epo package, log on to epo as an administrator and click Menu -> Software -> Master Repository 2. Click Check In Package.

5 3. Select Product or Update (.ZIP). 4. Browse for the package MER_FOR_EPO_Update.ZIP and then click Next. 5. Click Save. 4.4 Check in the MER for epo Extension 1. Log on to epo as an administrator and click Menu -> Software -> Extensions. 2. Select Install Extension

6 4. Browse for the package MER-FOR-EPO-3.1.0-POLICYMANAGEMENT.ZIP. 5. Click OK to install the extension. 5. Installing MER for epo through Software Manager 1. To go to Software Manager, log on epo as an administrator and click Menu -> Software -> Software Manager

7 2. Click Utilities and Connectors 3. Select the MER for epo (epo-mer) product from the list to view the details 4. To check in the deployment, update, and extension packages simultaneously, click Check in All. 5. Select I accept the terms in the license agreement.

8 6. Click Ok to install 7. Alternatively, to check in each package one at a time, click on the Check In link in Action column. Each package is required to be installed for MER for epo. 8. Select I accept the terms in the license agreement. 9. Click Ok to install 10. To verify that MER for epo is installed, click Checked In Software - >Licensed 6. Enabling MER for epo events

9 By default, MER for epo 3.1 will automatically enable the MER specific epo events. 1. Go to Server Settings under Menu -> Configuration 2. Select Event Filtering in Setting Categories. 3. Click Edit. 4. Verify if the events from 18500 to 18505 are checked. If not, select all the events from 18500 to 18505 5. Click Save. 7. Configuring Policies

10 Before deploying the MER package on to the client computers, you should define policies for executing MER and saving the results. The administrator has the option to specify policy settings by group or for individual client computers. The options available in the policy are: Upload Settings, for uploading to a customer provided FTP or UNC server Storage Settings, for saving the results on the local machine Additional Log Settings 1. Go to Policy Catalog under Menu -> Policy 2. Select MER for epo 3.1 from the product drop-down list. 3. Click My Default and configure policy settings as desired. 4. To configure FTP and Anonymous FTP, enter the URL as either ftp://<ftpserver>/<subfolder> or <ftpserver>/<subfolder>, as ftp:// will be automatically added to the beginning of the server URL. Any subfolder must be included in the URL. Since the upload will be from the client machine, it must have connectivity to the server. To verify the FTP username and password configuration, use Verify Credentials. 5. To configure UNC, enter the server path as either \\<server>\<subfolder> or <server>\<subfolder>, as \\ will be automatically added to the beginning of the server URL. Any subfolder must be included in the URL. Since the upload will be from the client machine, it must have connectivity to the server. To verify the UNC username and password configuration, use Verify Credentials. A domain account is required for UNC and must be in the format of domain\user. 6. By default, the results are also saved on the client machine in %AllUsersProfile%\Application Data\McAfee\Supportability\MER for epo 7. Click Save to save policy settings.

11 8. Deploying the MER tool The MER tool needs to be deployed on the client computers before triggering the MER task. 1. Click Client Tasks Catalog under Menu -> Policy. 2. Select McAfee Agent under Client Task Types. 3. Click on New Task 4. In the popup box, select the Task Type as Product Deployment and click OK. 5. Enter a Task Name.

12 6. Leave Target platforms as Windows. MER for epo only supports Windows. 7. Select MER for epo 3.1 in Products and components and ensure Action is set to Install. 8. Click Save. 9. Assign the created task to the desired groups in the system tree and click OK 10. Ensure the task you just created is selected 11. Configure your desired scheduling options and click Save. 12. Select the Systems Tree tab. 13. Select the group or machines you assigned the scan task to.

13 14. Send an agent wake-up call to the selected machines. 15. The MER for epo files will be installed in the following directory of the computer: C:\Program files\mcafee\supportability\mer for epo on a 32-bit machine C:\Program Files (x86)\mcafee\supportability\mer for epo on a 64-bit machine 9. Run MER: MER is now ready to be executed on the client machines. 1. Click Client Tasks Catalog under Menu -> Policy. 2. Select MER for epo 3.1 under Client Tasks Type 3. Click on New Task 4. Click Ok to select the ScanTask type

14 5. Name the Task 6. Check Upload MER data to McAfee Support and enter your open SR number and email address the SR was opened with. 7. By default, MER will detect the installed products automatically. If desired, select which product or products to collect data for. 8. To sanitize the results, check Remove IP addresses, MAC addresses, Domain names and Computer names from WebMER result file. 9. Click Save. 10. Assign the created task to the desired groups in the system tree and click OK 11. Ensure the task you just created is selected 12. Configure your desired scheduling options and click Save. 13. Select the Systems Tree tab. 14. Select the group or machines you assigned the scan task to. 15. Send an agent wake-up call to the selected machines. 10. Configuring MER for epo content update The MER for epo content update ensures that the MER tool is always running the latest version of the product collection scripts. 1. Click Client Tasks Catalog under Menu -> Policy. 2. Select McAfee Agent under Product List, and click New Task. 3. Select Product Update under Task Type.

15 4. Click on Ok. 5. On the configuration page, give the task a name and check the Selected Packages option. 6. Select MER for epo 3.1 under patches and Service packs. 7. Click Save. 8. Assign the created task to the desired groups in the system tree and click OK 9. Ensure the task you just created is selected 10. Configure your desired scheduling options and click Save. 11. Select the Systems Tree tab. 12. Select the group or machines you assigned the scan task to. 13. Send an agent wake-up call to the selected machines.