Symantec Critical System User Manual

Browse online or download User Manual for Hardware Symantec Critical System. Symantec Critical System User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 122
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1 - Protection Installation Guide

Symantec™ Critical System Protection Installation Guide

Page 2 - Installation Guide

10 ContentsCopying files required for the policy conversion utility ...110Migrating legacy detection policy files ...

Page 3 - Technical Support

100 Installing UNIX agentsTroubleshooting agent issues

Page 4

Chapter5Migrating to the latest versionThis chapter includes the following topics: Migrating legacy installations of Symantec Critical System Protect

Page 5

102 Migrating to the latest versionMigrating legacy installations of Symantec Critical System ProtectionWhen migrating legacy installations for Symant

Page 6

103Migrating to the latest versionMigrating legacy installations of Symantec Critical System ProtectionIf you changed the name of the database owner a

Page 7 - Contents

104 Migrating to the latest versionMigrating legacy installations of Symantec Critical System ProtectionTable 5-1 lists the management server-related

Page 8 - 8 Contents

105Migrating to the latest versionMigrating other legacy agent installationsTo specify the management server list for an agent1 At a command prompt, l

Page 9 - 9Contents

106 Migrating to the latest versionChecklist for migrating from Symantec Intruder AlertPolicy migration involves using a policy conversion utility tha

Page 10 - 10 Contents

107Migrating to the latest versionChecklist for migrating from Symantec Intruder AlertSystem Protection authoring environment (and eventually conditio

Page 11 - Critical System Protection

108 Migrating to the latest versionChecklist for migrating from Symantec Host IDSChecklist for migrating from Symantec Host IDSSymantec Critical Syste

Page 12 - Protection

109Migrating to the latest versionMigrating legacy agent software(and each ungrouped agent), noting the stock policies and the custom policies that ar

Page 13 - About the policy library

Chapter1Introducing Symantec™ Critical System ProtectionThis chapter includes the following topics: About Symantec Critical System Protection Compon

Page 14 - Where to get more information

110 Migrating to the latest versionPreparing for detection policy migrationInstalling the authoring environment and policy conversion utilityThe Syman

Page 15 - Planning the installation

111Migrating to the latest versionMigrating legacy detection policy filesMigrating legacy detection policy filesYour legacy detection policy files may

Page 16 - System requirements

112 Migrating to the latest versionMigrating legacy detection policy filesTable 5-2 lists the policy conversion utility command line switches.Note: To

Page 17 - Operating system requirements

113Migrating to the latest versionMigrating legacy detection policy files4 Type ITAHIDSpolicyMigration.exe, type the names of your source and destinat

Page 18 - Solaris packages

114 Migrating to the latest versionMigrating legacy detection policy files3 In the right pane, on the General tab, in the Name box, type a name for yo

Page 19 - Linux kernel driver support

115Migrating to the latest versionMigrating legacy detection policy filesYou should also check other migrated rule elements such as patterns and actio

Page 20 - Hardware requirements

116 Migrating to the latest versionMigrating legacy detection policy files6 For rules that need to be changed, on the Rules tab, right-click the rule

Page 21

117Migrating to the latest versionMigrating legacy detection policy filesApplying policies created and compiled in the authoring environmentYou use th

Page 22

118 Migrating to the latest versionMigrating legacy detection policy files

Page 23 - About name resolution

IndexAagentalternate management servers 27, 103fail back interval 26failover 25, 74groupscommon configuration 53, 63, 76, 81detection configuration 54

Page 24 - About intrusion prevention

12 Introducing Symantec™ Critical System ProtectionComponents of Symantec Critical System ProtectionSymantec Critical System Protection agents detect

Page 25 - About simple failover

120 IndexIP routing 24LLinux agentsdisabling and enabling 93kernel driver support 19monitoring and restarting 98uninstalling manually 87log filesagent

Page 26 - About the fail back interval

121IndexSQL serverevaluation installation 44installation requirements 34installing to existing 34MDAC requirements 35production database installation

Page 28 - About log files

13Introducing Symantec™ Critical System ProtectionHow Symantec Critical System Protection worksHow Symantec Critical System Protection worksSymantec C

Page 29 - What to do after installation

14 Introducing Symantec™ Critical System ProtectionWhere to get more informationWhere to get more informationProduct manuals for Symantec Critical Sys

Page 30 - 30 Planning the installation

Chapter2Planning the installationThis chapter includes the following topics: About planning the installation About network architecture and policy d

Page 31 - Installing Symantec

16 Planning the installationSystem requirementsalong with a few agents, and become familiar with Symantec Critical System Protection operations. When

Page 32 - Protection on Windows

17Planning the installationSystem requirementsOperating system requirementsTable 2-1 lists Symantec Critical System Protection component operating sys

Page 33 - Bypassing prerequisite checks

18 Planning the installationSystem requirementsSolaris packagesThe agent installation checks for the presence of Solaris system packages.The following

Page 34

19Planning the installationSystem requirements SUNWkvm Core Architecture, (Kvm) SUNWcsr Core Solaris, (Root) SUNWcsu Core Solaris, (Usr) SUNWcsd C

Page 35

Symantec™ Critical System ProtectionInstallation GuideThe software described in this book is furnished under a license agreement and may be used only

Page 36

20 Planning the installationSystem requirementsIf a system is configured with a different kernel, the agent will attempt to load the latest version av

Page 37 - ■ Tomcat component only

21Planning the installationDisabling Windows XP firewallsDisabling Windows XP firewallsWindows XP and Windows 2003 Server contain firewalls that are e

Page 38

22 Planning the installationAbout using firewalls with Symantec Critical System Protection4 On the Advanced tab, under Internet Connection Firewall, u

Page 39 - ■ SQL Prod: NA

23Planning the installationAbout name resolutionto the instance using that port. Thus, your firewall must allow traffic from the management server to

Page 40

24 Planning the installationAbout IP routingAbout IP routingAs bastion hosts, firewalls traditionally incorporate some form of network address transla

Page 41

25Planning the installationAbout simple failoverBy default, the enable intrusion prevention option is selected during Symantec Critical System Protect

Page 42 - ■ SQL Prod: variable

26 Planning the installationAbout simple failover Once the IPS Service fails away from the first server in the ordered list, it periodically checks i

Page 43

27Planning the installationAbout the Windows NT agent installationSpecifying the management server list for an agentTo use simple failover for an agen

Page 44

28 Planning the installationAbout log filesdrivers. To temporarily disable agents that run on Windows NT Server, you create an alternate hardware prof

Page 45

29Planning the installationWhat to do after installationTable 2-5 lists the management server log files.What to do after installationYou can begin enf

Page 46

Technical SupportSymantec Technical Support maintains support centers globally. Technical Support’s primary role is to respond to specific queries abo

Page 47 - ■ server-cert.ssl

30 Planning the installationWhat to do after installation

Page 48

Chapter3Installing Symantec Critical System Protection on WindowsThis chapter includes the following topics: About installing Symantec Critical Syste

Page 49

32 Installing Symantec Critical System Protection on WindowsAbout installing Symantec Critical System Protection on WindowsAbout installing Symantec C

Page 50

33Installing Symantec Critical System Protection on WindowsAbout installing Symantec Critical System Protection on WindowsBypassing prerequisite check

Page 51 - Installing a Windows agent

34 Installing Symantec Critical System Protection on WindowsAbout installing a database to a SQL Server instanceAbout installing a database to a SQL S

Page 52 - Setting Default Description

35Installing Symantec Critical System Protection on WindowsAbout installing a database to a SQL Server instanceAfter you install the instance of SQL S

Page 53

36 Installing Symantec Critical System Protection on WindowsConfiguring the temp environment variableConfiguring the temp environment variableThe inst

Page 54

37Installing Symantec Critical System Protection on WindowsInstalling the management server Evaluation installation using existing MS SQL instanceYou

Page 55

38 Installing Symantec Critical System Protection on WindowsInstalling the management serverUsing the SQL Server Enterprise Manager, do the following:

Page 56

39Installing Symantec Critical System Protection on WindowsInstalling the management serverDestination Folder C:\Program Files\Symantec\Critical Syste

Page 57

Operating system Version and patch level Network topology Router, gateway, and IP address information Problem description: Error messages and l

Page 58

40 Installing Symantec Critical System Protection on WindowsInstalling the management serverMSDE Data Path C:\Program Files\Symantec\Critical System P

Page 59 - Unattended agent installation

41Installing Symantec Critical System Protection on WindowsInstalling the management serversa password noneYou have the following options: MSDE Eval:

Page 60

42 Installing Symantec Critical System Protection on WindowsInstalling the management serverInstalling evaluation installation that runs MSDE on the l

Page 61 - Installation properties

43Installing Symantec Critical System Protection on WindowsInstalling the management server4 In the Installation Type panel, click Evaluation Installa

Page 62

44 Installing Symantec Critical System Protection on WindowsInstalling the management server7 In the Database Selection panel, change the default serv

Page 63

45Installing Symantec Critical System Protection on WindowsInstalling the management server3 In the License Agreement panel, select I accept the terms

Page 64

46 Installing Symantec Critical System Protection on WindowsInstalling the management server All other accounts (owner, guest, and internal accounts)

Page 65

47Installing Symantec Critical System Protection on WindowsInstalling the management server9 In the Database Configuration panel, specify the database

Page 66

48 Installing Symantec Critical System Protection on WindowsInstalling and configuring the management consoleNote: If the management server database i

Page 67

49Installing Symantec Critical System Protection on WindowsInstalling and configuring the management consoleC:/Program Files/Symantec/Critical System

Page 68

Maintenance agreement resourcesIf you want to contact Symantec regarding an existing maintenance agreement, please contact the maintenance agreement a

Page 69 - ■ Symantec IPS driver

50 Installing Symantec Critical System Protection on WindowsInstalling and configuring the management consoleTo configure the management console1 Clic

Page 70

51Installing Symantec Critical System Protection on WindowsInstalling a Windows agentInstalling a Windows agentThe Symantec Critical System Protection

Page 71 - Reinstalling Windows agents

52 Installing Symantec Critical System Protection on WindowsInstalling a Windows agentLogs File DirectoryC:\Program Files\Symantec\Critical System Pro

Page 72

53Installing Symantec Critical System Protection on WindowsInstalling a Windows agentPrimary Management Serverlocalhost The IP address or fully qualif

Page 73 - Installing UNIX agents

54 Installing Symantec Critical System Protection on WindowsInstalling a Windows agentPrevention Policy Groupnone The name of an existing prevention p

Page 74

55Installing Symantec Critical System Protection on WindowsInstalling a Windows agentInstalling the Windows agent softwareThe installation CD contains

Page 75

56 Installing Symantec Critical System Protection on WindowsInstalling a Windows agent4 In the Destination Folder panel, change the folders if necessa

Page 76

57Installing Symantec Critical System Protection on WindowsInstalling a Windows agentIf you changed the Agent Port setting during management server in

Page 77

58 Installing Symantec Critical System Protection on WindowsInstalling a Windows agentYou may add multiple detection policy group names separated with

Page 78 - 78 Installing UNIX agents

59Installing Symantec Critical System Protection on WindowsUnattended agent installationUnattended agent installationYou must log on to an Administrat

Page 80

60 Installing Symantec Critical System Protection on WindowsUnattended agent installation3 Type and run one of the following commands:agent.exe ?orage

Page 81

61Installing Symantec Critical System Protection on WindowsUnattended agent installationInstallation propertiesTable 3-6 describes the Windows agent i

Page 82

62 Installing Symantec Critical System Protection on WindowsUnattended agent installationLOG_DIR=<val> C:\Program Files\Symantec\Critical System

Page 83

63Installing Symantec Critical System Protection on WindowsUnattended agent installationCOMMON_CONFIG_GROUP=<val>Common Configuration The name o

Page 84

64 Installing Symantec Critical System Protection on WindowsInstalling the Windows NT policyInstalling the Windows NT policyThe Windows NT prevention

Page 85 - Uninstalling agents manually

65Installing Symantec Critical System Protection on WindowsUninstalling Symantec Critical System Protection You must install the Symantec Critical Sy

Page 86

66 Installing Symantec Critical System Protection on WindowsUninstalling Symantec Critical System ProtectionUninstalling an agent using Add or Remove

Page 87

67Installing Symantec Critical System Protection on WindowsUninstalling Symantec Critical System ProtectionSee “Unattended agent installation” on page

Page 88

68 Installing Symantec Critical System Protection on WindowsTemporarily disabling Windows agents3 Click Symantec Critical System Protection Management

Page 89

69Installing Symantec Critical System Protection on WindowsTemporarily disabling Windows agentsC:\Program Files\Symantec\Critical System Protection\Ag

Page 90

ContentsTechnical SupportChapter 1 Introducing Symantec™ Critical System ProtectionAbout Symantec Critical System Protection ...

Page 91

70 Installing Symantec Critical System Protection on WindowsTemporarily disabling Windows agentsUse one of the following methods to disable intrusion

Page 92

71Installing Symantec Critical System Protection on WindowsReinstalling Windows agentsReinstalling Windows agentsYou can perform an unattended reinsta

Page 93

72 Installing Symantec Critical System Protection on WindowsReinstalling Windows agents

Page 94

Chapter4Installing UNIX agentsThis chapter includes the following topics: About installing UNIX agents Installing an agent in verbose mode Installi

Page 95

74 Installing UNIX agentsAbout installing UNIX agents If you are installing a Solaris, Linux, HP-UX, AIX, or Tru64 agent on a system that supports no

Page 96 - Enabling a disabled AIX agent

75Installing UNIX agentsAbout installing UNIX agentsAgent Port 443 The Agent Port number that was used during management server installation.See Table

Page 97

76 Installing UNIX agentsAbout installing UNIX agentsCommon Config Groupnone The name of an existing common configuration group for this agent to join

Page 98

77Installing UNIX agentsAbout installing UNIX agentsBypassing prerequisite checksThe UNIX installation kit lets you bypass some of the prerequisite ch

Page 99

78 Installing UNIX agentsInstalling an agent in verbose modeYou can use the bypass prerequisite checks feature to bypass the following prerequisite ch

Page 100 - Troubleshooting agent issues

79Installing UNIX agentsInstalling an agent in silent mode On the computer on which the agent will be installed, create a directory and then copy the

Page 101 - Migrating to the latest

8 ContentsBypassing prerequisite checks ... 33About installing a database to a SQL Ser

Page 102

80 Installing UNIX agentsInstalling an agent in silent modeTable 4-2 describes the settings that are used with the installation commands.Table 4-2 UNI

Page 103

81Installing UNIX agentsInstalling an agent in silent mode-cert=<file> /tmp/agent-cert.ssl The directory location of the SSL certificate file, a

Page 104 - Command Syntax Description

82 Installing UNIX agentsInstalling an agent in silent mode-idsPolGrp=<group> OS-specific groupThe OS-specific group is one of the following: A

Page 105 - ■ UNIX: sisipsconfig.sh -t

83Installing UNIX agentsInstalling an agent in silent modeUse the -silent option and other options to perform a silent installation.The following comm

Page 106

84 Installing UNIX agentsUninstalling agents using package commandsTo install an agent in silent mode1 Follow the procedures and steps that are used t

Page 107

85Installing UNIX agentsUninstalling agents manually6 On HP-UX, type and run the following command:swremove SYMCcsp7 On Tru64, type and run the follow

Page 108 - ■ Template_FileWatch policy

86 Installing UNIX agentsUninstalling agents manuallypgrep -U sisips -P1 -f sisipsdaemonpgrep -U sisips -P1 -f sisipsutildaemonpgrep -U root -P1 -f si

Page 109

87Installing UNIX agentsUninstalling agents manuallyUninstalling Linux agents manuallyYou can manually uninstall Linux agents.To uninstall Linux agent

Page 110 - ◆ Do one of the following:

88 Installing UNIX agentsUninstalling agents manually7 Remove the following lines from the initialization scripts:Remove the lines (including comments

Page 111

89Installing UNIX agentsUninstalling agents manuallyrm -rf /var/log/scsplog (default directory)rm -f /var/run/sisipsdaemon.pidrm -f /var/run/sisidsdae

Page 112

9ContentsInstalling an agent in silent mode ... 79Uninstalling agents using package

Page 113 - Creating a new policy

90 Installing UNIX agentsUninstalling agents manually5 Type and run the following commands to remove the agent user and group:userdel sisipsrmgroup si

Page 114 - Validating your rules

91Installing UNIX agentsDisabling and enabling UNIX agentsEdit and remove the line from /etc/symantec/sis/sis.conf:SisInstalledClsId=<cluster_membe

Page 115

92 Installing UNIX agentsDisabling and enabling UNIX agentsAfter you disable the driver, apply the Null prevention policy or a prevention policy in wh

Page 116 - Compiling a policy

93Installing UNIX agentsDisabling and enabling UNIX agentsEnabling a disabled Solaris agentYou can enable a Solaris agent that was previously disabled

Page 117 - ■ Test the workspace policy

94 Installing UNIX agentsDisabling and enabling UNIX agentsWarning: You should perform these procedures only in emergency situations.To permanently di

Page 118

95Installing UNIX agentsDisabling and enabling UNIX agents/sbin/init.d/sisidsagent stopPermanently disabling HP-UX agentsIf you have performance issue

Page 119

96 Installing UNIX agentsDisabling and enabling UNIX agentsTemporarily disabling AIX agentsWarning: You should perform these procedures only in emerge

Page 120 - 120 Index

97Installing UNIX agentsDisabling and enabling UNIX agentsrcsisidsagent:23456789:wait:/etc/rc.sisidsagent start >/dev/console 2>&13 Type and

Page 121 - 121Index

98 Installing UNIX agentsMonitoring and restarting UNIX agentsmv sisipsagent sisipsagentOFFmv sisidsagent sisidsagentOFFIf the machine not is a member

Page 122 - 122 Index

99Installing UNIX agentsTroubleshooting agent issues0 * * * * /etc/init.d/sisidsagent health_check0 * * * * /etc/init.d/sisipsutil health_check (Sola

Comments to this Manuals

No comments