installation hands on n.
Skip this Video
Loading SlideShow in 5 Seconds..
INSTALLATION HANDS-ON PowerPoint Presentation
Download Presentation


133 Views Download Presentation
Download Presentation


- - - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript


  2. About the Hands-On • This hands-on section is structured in a way that allows you to work independently, but still giving you the possibility to consult step-by-step instructions. • Each given task will be divided into two sections • Actual Task • Conditions, goals and short instructions • Allowing you to work independently • Detailed instructions (step-by-step work through) • In case you can not come up with own solutions

  3. Task Overview • Policy Manager deployment (incl. PMS, PMC and AUSYS) • Console initialization and initial configuration • AVCS 6.x rollout

  4. Root Update Server XP Pro SP2 2003 Server Infrastructure • Your environment consists of two computers • Windows 2003 Standard Server (SP3) • Windows XP Professional (SP2) • Network • 100 Mbit Ethernet, supporting TCP/IP • C-class network (

  5. Install Policy Manager with all necessary components on a single computer Is such an installation possible in this environment? Once you have a clear plan how to proceed, install the products and configure it as follows Limit access to the PMS admin module to local host (use the default ports during installation) If needed the next pages will provide you with a step-by-step walk through => After installation is completed, continue on page 19 Root Update Server XP Pro SP2 2003 Server Task 1

  6. Policy Manager Installation Walk-Through • Insert the F-Secure Product CD (old screenshot!) • Select ”F-Secure Policy Manager”

  7. Policy Manager Installation Walk-Through • Choose the installation language • Click “Next”

  8. Policy Manager Installation Walk-Through • Read the F-Secure License Terms and accept the agreement • Click ”Next”

  9. Policy Manager Installation Walk-Through • Accept Custom installation • Click “Next”

  10. Policy Manager Installation Walk-Through • Also here accept default selections • Click “Next”

  11. Policy Manager Installation Walk-Through • Default installation path C:\Program Files\F-Secure is fine • Click “Next”

  12. Policy Manager Installation Walk-Through • There is no old Policy Manager installed, so accept the default • Click ”Next”

  13. Policy Manager Installation Walk-Through • Accept the default Port Numbers • Click ”Next”

  14. Policy Manager Installation Walk-Through • Select F-Secure Anti-Virus Client Security 6.x • Click ”Next”

  15. Policy Manager Installation Walk-Through • Necessary setup information has been collected. System is ready for installation • Click “Start”

  16. Policy Manager Installation Walk-Through • Installation in process. Do not restart the system until 100 % completed • Might take some minutes

  17. Policy Manager Installation Walk-Through • Components have been installed • Click “Next”

  18. Policy Manager Installation Walk-Through • Installation finished successfully • Click “Finish”

  19. Task 1 Completed • F-Secure Policy Manager is now installed • Check the Server Status • Start/Status Monitor • Both Apache modules should have Status: OK • Web Reporting Module will still show an error, because we didn’t initialize the console yet • Initializing and configuring the console will be your next task

  20. Task 2 • Initialize and configure Policy Manager Console • Start the Console and go through the initialization process • After that, configure the console as follows • Rename the Root domain to F-Secure • Restrict all user settings (try to find the easiest way) • Define the Policy Manager host communication address • Note: The address defined during the console initialization is the administration module address • Change the server polling interval to 10 seconds (incoming and outgoing requests) • Distribute policies! • Task continues on next page…

  21. Task 2 • Perform a general system check • Are all modules working properly? • What does the status monitor say? • Try out the web reporting, does it work? • Try to complete this task independently • If needed, next pages will provide you with a step-by-step walk through • => If you managed to complete this task, continue on page 36

  22. Console Initialization Walk-Through • Start Policy Manager from Start menu for initialization • Click “Next”

  23. Console Initialization Walk-Through • Select Administrator mode • Click “Next”

  24. Console Initialization Walk-Through • Accept default • Click “Next”

  25. Console Initialization Walk-Through • Select the location of the key-pair. Defaults are ok. • Click ”Next”

  26. Console Initialization Walk-Through • Create administrator’s cryptographic keys • Move the cursor until the next dialogue box appears

  27. Console Initialization Walk-Through • Enter the administrative password. Use “password” in this hands-on • Click “Next”

  28. Console Initialization Walk-Through • Click ”Finish”

  29. Console Initialization Walk-Through • First Policy Manager Console launch • By default, Policy Manager Console is run in the Anti-Virus Administration mode (AV mode) • Policy Manager is now initialized and ready to use • Next step is the console configuration and first policy distribution

  30. Initial Console Configuration Walk-Through • Rename the root domain • Right-click the root domain • Select Domain/Host Properties • Rename “Root” to “F-Secure” • After that start fine tuning the communication settings • Click Centralized Management tab

  31. Initial Console Configuration Walk-Through • Prevent user from changing most important settings • Click “Do not allow users to change settings…”

  32. Initial Console Configuration Walk-Through • Define communication settings • Set Policy Manager Server address (IP address of your PMS computer) • Set both polling intervals to 10 seconds

  33. Initial Console Configuration Walk-Through • Distribute the Policy, select File/Distribute (or press CTRL + D)

  34. System Status CheckOverall • Check the status of the Policy Manager Server • From the start menu: Start/Programs/F-Secure Policy Manager Server/Status Monitor • The Web Reporting error should now be fixed

  35. System Status CheckWeb Reporting • Open Report web interface • From the start menu: Start/Programs/F-Secure Policy Manager Server/F-Secure Policy Manager Web Reporting

  36. Root Update Server F-SecurePMS / PMC XP Pro SP2 Task 2 completed • Policy Manager initialization and configuration has been finalized • The next Task will be F-Secure Anti-Virus Client Security 6 rollout

  37. Task 3 • Install AVCS 6.x on your client computer running Windows XP SP2 • Is the installation possible without any changes to the host? • Any conflicting software installed on the target system? • Which rollout method suits best for this environment? • Which methods are possible? • Is there a firewall installed on the host preventing certain rollout methods? • Task continues on next page…

  38. Task 3 • Once you have a clear plan how to rollout AVCS 6.x, and you have checked all issues mentioned on the previous page, go ahead with the rollout • Install AVCS at this point without “Web Traffic Scanning” • We will update this component in the administration hands-on • Try to complete this task independently • If needed, next pages will provide you with a step-by-step walk through • => If you managed to complete this task and your client has rebooted, continue on page 61

  39. Pre-Rollout Checks • Check your target host for installed conflicting software • You will find McAfee Virus Scan 4.5.1 • This product is automatically detected and removed by F-Secure Sidegrade Function • Important: Always check all your hosts for conflicting software before your start any rollout. • Check the AVCS administrator manual for more information on which applications are detected and removed.

  40. Pre-Rollout Checks • The XP Firewall on your host is enabled! • F-Secure Intelligent Installations requires certain inbound traffic allowed on target host (TCP 135 and 445) • Try to connect to the ports from your PMS • Open the command prompt and telnet the ports • There will be no response, so you need to allow the above mentioned protocols on your target host • Try to come up with a solution, without disabling the firewall!

  41. XP Firewall Configuration • Configure XP SP2 firewall exceptions • Allow “File and Printer Sharing” • Press “Edit” • Enable SMB only (TCP 445) • Disable all other ports • Create new service and allowing RPC • Press “Add Port” • Name: RPC, Port number: 135 • Confirm by pressing OK

  42. Remote Installation Walk-Through • Select ”Installation” leaf on the editor pane • Click “Autodiscover Windows hosts…”

  43. Remote Installation Walk-Through • Select your target host from the list • Click “Install”

  44. Remote Installation Walk-Through • Select F-Secure Anti-Virus Client Security 6.x • Click “Next”

  45. Remote Installation Walk-Through • Check that F-Secure Anti-Virus for Client Security 6.x is the only selection • Click “Next”

  46. Remote Installation Walk-Through • Include the policy from your root domain “F-Secure” • Click “Next”

  47. Remote Installation Walk-Through • Accept the default domain account • Domain administrator account will be used to access the target host • Click “Next”

  48. Remote Installation Walk-Through • Check the installation details, correct if necessary (“Back” button) • Click “Start”

  49. Remote Installation Walk-Through • Click “Next”

  50. Remote Installation Walk-Through • Instructor will provide you with the correct keycode • After typing the keycode, click “Next”