TDR and Kaspersky. Integration Guide

Similar documents
TDR and Sophos Software. Integration Guide

TDR and Symantec. Integration Guide

TDR and McAfee. Integration Guide

TDR and Panda Fusion. Integration Guide

TDR and Avast Business Antivirus. Integration Guide

TDR and Malwarebytes. Integration Guide

TDR and ESET Endpoint. Integration Guide

TDR & Bitdefender. Integration Guide

TDR and Trend Micro. Integration Guide

TDR and Microsoft Security Essentials. Integration Guide

TDR and Symantec. Integration Guide

TDR and Windows Defender. Integration Guide

Universal CMDB. Software Version: Backup and Recovery Guide

HP Universal CMDB. Software Version: Backup and Recovery Guide

TPP: Date: October, 2012 Product: ShoreTel PathSolutions System version: ShoreTel 13.x

Avigilon Control Center Server User Guide. Version 6.8

VMware AirWatch Certificate Authentication for Cisco IPSec VPN

Xerox Security Bulletin XRX12-007

HP Server Virtualization Solution Planning & Design

Technical Paper. Installing and Configuring SAS Environment Manager in a SAS Grid Environment with a Shared Configuration Directory

Avigilon Control Center Server User Guide. Version 6.4

Introduction to Mindjet on-premise

EView/400i Management Pack for Systems Center Operations Manager (SCOM)

Quest InTrust Connector for Microsoft System Center Operations Manager User

Admin Report Kit for Exchange Server

Advanced and Customized Net Conference Powered by Cisco WebEx Technology

AvePoint Accessibility Accelerator 2.0

IMC QoS Manager 7.3 (E0502) Copyright 2015, 2016 Hewlett Packard Enterprise Development LP

Kaltura Video Extension for SharePoint 2013 Deployment Guide for Microsoft Office 365. Version: 1.0

NiceLabel LMS. Installation Guide for Single Server Deployment. Rev-1702 NiceLabel

Enterprise Chat and Developer s Guide to Web Service APIs for Chat, Release 11.6(1)

Hitachi Server Adapter for the SAP HANA Cockpit

SMART Room System for Microsoft Lync. Software configuration guide

Troubleshooting Citrix- Published Resources Configuration in VMware Identity Manager

WinEst 15.2 Installation Guide

HPE AppPulse Mobile. Software Version: 2.1. IT Operations Management Integration Guide

Avigilon Control Center Virtual Matrix User Guide. Version 6.8

Technical Paper. Installing and Configuring SAS Environment Manager in a SAS Grid Environment

SMART Product Drivers 11.3 for Windows and Mac computers

Cisco Tetration Analytics, Release , Release Notes

Date: October User guide. Integration through ONVIF driver. Partner Self-test. Prepared By: Devices & Integrations Team, Milestone Systems

Cisco EPN Manager Network Administration

Dell EqualLogic PS Series Arrays: Expanding Windows Basic Disk Partitions

CA CMDB Connector for z/os

This document lists hardware and software requirements for Connected Backup

Investor Services Online Quick Reference Guide FTP Delivery

TIBCO Statistica Options Configuration

Your New Service Request Process: Technical Support Reference Guide for Cisco Customer Journey Platform

Frequently Asked Questions

Licensing the Core Client Access License (CAL) Suite and Enterprise CAL Suite

Virtual Office

Cisco EPN Manager Network Administration - Optical

Aras Innovator 11. Client Settings for Chrome on Windows

CodeSlice. o Software Requirements. o Features. View CodeSlice Live Documentation

How to Guide. DocAve Extender for MOSS 2007 and SPS Installing DocAve Extender and Configuring a Basic SharePoint to Cloud Extension

UPGRADING TO DISCOVERY 2005

PRIVACY AND E-COMMERCE POLICY STATEMENT

September 24, Release Notes

USO RESTRITO. SNMP Agent. Functional Description and Specifications Version: 1.1 March 20, 2015

How to set up Dell SonicWALL Aventail SRA Appliance with OPSWAT GEARS Client

Level 2 Development Training

ESET REMOTE ADMINISTRATOR PLUG-IN FOR KASEYA Technical Setup and User Guide. Click here to download the latest version of this document

HP ExpertOne. HP2-T21: Administering HP Server Solutions. Table of Contents

RTX includes new functionality, see the product Release Notes for a full list of new features.

Application Notes for Stratus ftserver 6310 with VMWare and Avaya Aura Contact Center Release 6.2 Issue 1.0

Manually Upgrading PostgreSQL 9.1 to PostgreSQL

HP Oracle LMS. Software Version: User Guide

Virtual Server Protection (VSP)

McAfee Endpoint Upgrade Assistant 2.2

Planning, installing, and configuring IBM CMIS for Content Manager OnDemand

Repstor custodian. On Premise Pre-Requisites. Document Version 1.1 January 2017

BMC Remedyforce Integration with Remote Support

Aras Innovator 11. Client Settings for Chrome on Windows

Troubleshooting Citrix- Published Resources Configuration in VMware Identity Manager

AvePoint Pipeline Pro 2.0 for Microsoft Dynamics CRM

App Orchestration 2.6

NSE 8 Certification. Exam Description for FortiGate 5.2 and higher

Release Date: 29-April-2011 Purpose: The Configuration & Orchestration Manager Release Notes provide the following information:

Kaltura Video Extension for IBM Connections User Guide. Version: 1.0

Shavlik Protect. Migration Tool User s Guide

Integration Framework for SAP Business One

AvePoint Timeline Enterprise for Microsoft Dynamics CRM

ALCATEL-LUCENT RAINBOW TM

CMC Blade BIOS Profile Cloning

Password Reset for Remote Users

Dell Chassis Management Controller (CMC) Version 1.35 for Dell PowerEdge VRTX. Release Notes

Remoting SDK Release Notes

Sircon User Guide A Guide to Using the Vertafore Sircon Self-Service Portal

Proficy* SmartSignal 6.1 Installation Guide

Hitachi Dynamic Link Manager (for AIX) Release Notes

SAP Business One Hardware Requirements Guide

Dolby Conference Phone Support Frequently Asked Questions

Getting Started with the SDAccel Environment on Nimbix Cloud

Stellar Phoenix Excel Repair. Version 5.0. Installation Guide

Demand Forecasting. For. Microsoft Dynamics 365 for Operations. Technical Guide. Release 7.1. December 2017

Juniper Networks Certification Program

Virtual Server Protection (VSP)

LiveEngage and Microsoft Dynamics Integration Guide Document Version: 1.0 September 2017

Element Creator for Enterprise Architect

Xerox WorkCentre 7120/7125 Series User Instructions

Transcription:

TDR and Kaspersky Integratin Guide

i WatchGuard Technlgies, Inc.

TDR and Kaspersky Deplyment Overview Threat Detectin and Respnse (TDR) is a cllectin f advanced malware defense tls that crrelate threat indicatrs frm Firebxes and Hst Sensrs t enable real-time, autmated respnse t stp knwn, unknwn, and evasive threats. As part f the TDR slutin, yu install TDR Hst Sensrs t prvide endpint prtectin. In sme cases, the TDR Hst Sensr might have cnflicts with the antivirus sftware installed n yur endpints. T reslve this issue, yu can cnfigure exclusins in the antivirus sftware and in TDR. This dcument describes the steps t deply a TDR Hst Sensr n a hst that runs Kaspersky sftware. This dcument des nt describe all steps necessary t set up yur Threat Detectin and Respnse accunt. Befre yu begin, make sure t set up yur TDR accunt and enable TDR n the Firebx. Fr infrmatin abut hw t set up yur TDR accunt, TDR deplyment best practices, and hw t enable TDR n a Firebx, see Quick Start Set Up Threat Detectin and Respnse. TDR and Kaspersky Integratin Guide 1

Cnfiguratin Summary T avid cnflicts between the TDR Hst Sensr and Kaspersky, add these exclusins: Exclusins in TDR fr Kaspersky Fr Windws: C:\PrgramData\KasperskyLab\ C:\PrgramData\Kaspersky Lab Setup Files\ C:\PrgramData\Kaspersky Lab\ C:\Prgram Files(x86)\Kaspersky Lab\ C:\Prgram Files\Kaspersky\ C:\Windws\Temp\klsc-*\ Exclusins in Kaspersky fr the TDR Hst Sensr Fr Windws: 64-bit Windws C:\Prgram Files(x86)\WatchGuard\Threat and Respnse\ 32-bit Windws C:\Prgram Files\WatchGuard\Threat and Respnse\ Exclusins in TDR fr Kaspersky Fr Mac: /Applicatin/Kaspersky Endpint Security/ /Applicatin/Kaspersky Internet Security/ /Library/Applicatin Supprt/Kaspersky Lab/ Exclusins in Kaspersky fr TDR Fr Mac: /usr/lcal/watchguard/ If the Hst Sensr and Kaspersky detect and respnd t a threat at the same time, this can cause high utilizatin f system resurces such as CPU, Memry and Disk I/O. 2 WatchGuard Technlgies, Inc.

Cnfiguratin Details T cmplete this deplyment, yu must have: An active Threat Detectin and Respnse subscriptin with Hst Sensr licenses Firebx with Fireware v12.0 r higher Kaspersky Endpint Security Kaspersky Endpint Security 10.3.0.6.6294 Kaspersky Endpint Security Clud build 3.0.1.741 Kaspersky Small Office Security 5 17.0.0.611 Windws. Kaspersky Internet Security Mac The Windws test envirnment fr this deplyment included: Windws 7,8,10 Enterprise Operating System Memry (RAM) 4 GB Prcessr 2 CPU Cres The Mac test envirnment fr this deplyment included: Sierra versin 10.13.2 Memry (RAM) 8 GB Prcessr 2.6GHz Intel Cre i5 TDR and Kaspersky Integratin Guide 3

Cnfigure Exclusins in TDR In yur TDR accunt, add the exclusins t manually identify paths fr files and prcesses that yu d nt want Hst Sensrs t mnitr. Befre yu deply a Hst Sensr n cmputers that have Kaspersky installed, Add exclusins fr the Kaspersky file paths as TDR Exclusins in yur TDR accunt. T exclude Kaspersky directries, add exclusins with these paths in yur TDR accunt. Flders specified in an exclusin must end with a backslash. Exclusins fr Windws: C:\PrgramData\KasperskyLab\ C:\PrgramData\Kaspersky Lab Setup Files\ C:\PrgramData\Kaspersky Lab\ C:\Prgram Files(x86)\Kaspersky Lab\ C:\Prgram Files\Kaspersky\ C:\Windws\Temp\klsc-*\ Exclusins fr Mac: /Applicatin/Kaspersky Endpint Security/ /Applicatin/Kaspersky Internet Security/ /Library/Applicatin Supprt/Kaspersky Lab/ T add an exclusin in TDR: 1. Lg in t yur TDR accunt r managed accunt as a user with Operatr privileges. 2. Select Cnfiguratin > Exclusin. 3. Click Add Exclusin. The Add Exclusin dialg bx appears. 4. In the Path text bx, type the path t exclude. 5. Click Save. Repeat these steps t add each exclusin. 4 WatchGuard Technlgies, Inc.

Cnfigure Exclusin in Kaspersky T exclude TDR Hst Sensr files n Windws add an exclusin: C:\Prgram Files(x86)\WatchGuard\Threat and Respnse C:\Prgram Files\WatchGuard\Threat and Respnse T add an exclusin in Kaspersky Small Office Security: 1. Click Setting. The Setting page appears. 2. Select Additinal n the left panel. A list f ptins appears n the right panel. 3. Select Threats and Exclusins n the right panel. The Threat and exclusin setting page appears. 4. Click Exclusin > Manage exclusin. 5. Click Add. 6. In the File r flder text bx, type the path t exclude. 7. Click Add. T exclude TDR Hst Sensr files n Mac add an exclusin: /usr/lcal/watchguard/ T add an exclusin in Kaspersky: 1. Lg in yu Kaspersky clud accunt. 2. Click Security prfiles in yur clud hme page. 3. Click Default. Select Mac in Operating system. 4. Select Advanced. Click Settings after the Threats and exclusins. 5. Click Settings after the Scan exclusins. 6. Click Add and type in the Cmment, TDR path and Object name. 7. Click Save buttn. Fr infrmatin abut the integratin testing methds, see TDR Testing Methdlgy. TDR and Kaspersky Integratin Guide 5

Abut This Guide Guide Type Dcumented Integratin WatchGuard r a Technlgy Partner has prvided dcumentatin demnstrating integratin. Guide Details WatchGuard prvides integratin instructins t help ur custmers cnfigure WatchGuard prducts t wrk with prducts created by ther rganizatins. If yu need mre infrmatin r technical supprt abut hw t cnfigure a third-party prduct, see the dcumentatin and supprt resurces fr that prduct. Infrmatin in this guide is subject t change withut ntice. Cmpanies, names, and data used in examples herein are fictitius unless therwise nted. N part f this guide may be reprduced r transmitted in any frm r by any means, electrnic r mechanical, fr any purpse, withut the express written permissin f WatchGuard Technlgies, Inc. Guide revised: 2/6/2018 Cpyright, Trademark, and Patent Infrmatin Cpyright 1998 2018 WatchGuard Technlgies, Inc. All rights reserved. All trademarks r trade names mentined herein, if any, are the prperty f their respective wners. Cmplete cpyright, trademark, patent, and licensing infrmatin can be fund in the Cpyright and Licensing Guide, available nline at http://www.watchguard.cm/wgrd-help/dcumentatin/verview. Abut WatchGuard WatchGuard Technlgies, Inc. is a glbal leader in netwrk security, prviding best-in-class Unified Threat Management, Next Generatin Firewall, secure Wi-Fi, and netwrk intelligence prducts and services t mre than 75,000 custmers wrldwide. The cmpany s missin is t make enterprisegrade security accessible t cmpanies f all types and sizes thrugh simplicity, making WatchGuard an ideal slutin fr Distributed Enterprises and SMBs. WatchGuard is headquartered in Seattle, Washingtn, with ffices thrughut Nrth America, Eurpe, Asia Pacific, and Latin America. T learn mre, visit WatchGuard.cm. Fr additinal infrmatin, prmtins and updates, fllw WatchGuard n Twitter, @WatchGuard n Facebk, r n the LinkedIn Cmpany page. Als, visit ur InfSec blg, Secplicity, fr real-time infrmatin abut the latest threats and hw t cpe with them at www.secplicity.rg. Address 505 Fifth Avenue Suth Suite 500 Seattle, WA 98104 Supprt www.watchguard.cm/supprt U.S. and Canada +877.232.3531 All Other Cuntries +1.206.521.3575 Sales U.S. and Canada +1.800.734.9905 All Other Cuntries +1.206.613.0895 TDR and Kaspersky Integratin Guide 6