Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise...

77
Sophos Enterprise Solutions
  • date post

    21-Dec-2015
  • Category

    Documents

  • view

    229
  • download

    8

Transcript of Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise...

Page 1: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Sophos Enterprise Solutions

Page 2: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

This Seminar…

• Overview– Components — EM Library, Enterprise Console,

Clients– OS requirements and product functionality

• EM Library– In depth

• Enterprise Console– In depth

• Clients– In brief

Page 3: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Overview

Page 4: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Components

• EM Library (essential)– Manages downloading of software from

Sophos

• Enterprise Console (optional — sort of)– Manages clients

• Sophos Anti-Virus Clients (essential)– Client software for virus detection and

disinfection

Page 5: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Requirements — EM Library

• Windows– Windows NT SP6a– Windows 2000 Professional or Server (SP3+)– Windows XP Professional (SP1+)– Windows 2003 Server

• Requires MMC 1.2

• IE 5.5 SP2 or above

Page 6: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Requirements — Enterprise Console

• Windows 2000 (SP3+) or 2003 Server– If managing more than 10 PCs

• Windows 2000 (SP3+) or XP (SP1+) Professional – If managing up to 10 PCs– May be used to define and export policies,

regardless of PCs managed

Page 7: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Function — EM Library

• Downloads package updates from Sophos to a library according to a schedule– Default is c:\program files\sophos enterprise

manager\library shared as SophosEM– Library can be remote or local

• Optionally publishes packages to make them available to child libraries

Page 8: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Function — EM Library

• Pushes updates to Central Installation Directories (CIDs)– CIDs can be on remote servers (e.g. unix)– CIDs can be published via a web server

• Clients check CIDs for updates and download as required

Page 9: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Function — Enterprise Console

• Deploy software to clients

• Monitor status of client installations

• Organise clients into groups

• Define and apply updating and anti-virus polices to groups of PCs

• Report on alerts etc.

Page 10: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Library maintained by

EM Library

Sophos Databank at sophos.com

1. EM Library pulls updates from Sophos according to schedule

2000/XP/2003 CID on Windows

share

95/98/Me CID on Windows share

Mac OS X 10.2+ CID on AppleShare compatible share

2000/XP/2003 CID on IIS

2000/XP/2003 CID on samba

share

2000/XP/2003 CID on Apache

2. EM Library pushes updates to central

installation directories (CIDs)

OS XOS X

OS X

XP

20002003

9598

ME

XP 2000

2003

3. Clients check CIDS according to their

schedule and pull updates from CIDs

XP 2000

2003

XP

20002003

Clients

Page 11: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

How does Enterprise Console fit in?

• Not required to provide updates to clients

• May be used to manage clients

Page 12: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Documentation

• Sophos enterprise solutions installation advisor• Sophos Anti-Virus Startup Guide• Knowledgebase

– Ignore docs with references to Remote Updates, SAVAdmin

– Look for EM Library v1.2, Enterprise Console 1.0, Clients 4.5 or 5.0

• http://www.oucs.ox.ac.uk/viruses/sophos/antivirus as a starting point

Page 13: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Questions?

Page 14: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

EM Library

Page 15: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Installation• Download required network installer from

micros.oucs• Before installation on Domain Controller

– Optionally create domain a/c with admin privileges• http://www.sophos.com/support/knowledgebase/article/

2522.html• Global credentials used to access and update CIDs (Can be

altered for individual CIDS)

• Run installer– Server: es10sfx.exe (unpacks to \sec10)– Workstation: run es10wssfx.exe – if you run setup.exe

from unpacked files it will fail (tells you only server supported!)

Page 16: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Installation

• To install EM Library only– \sec10\Serverinstaller\EMConsole\setup.exe

• Post Installation– Patch MSDE 2000 engine (use MBSA to determine

appropriate patches)– Not required if only installing EM Library (MSDE

installed by Enterprise Console only)– Note EM Library creates share for EM Library

installation files• Default is C:\Program Files\Sophos Enterprise Manager\

console\bin\inst shared as EMLibInstaller

Page 17: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Configuring EM Library

Page 18: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Create Library

• Location for downloaded files from Sophos• Local or remote• Prompts for installation path and library share

name– Defaults are C:\Program Files\Sophos Enterprise

Manager and SophosEM

• Prompts for path and share name for Central Installation Directories– Default C:\Program Files\Sophos Sweep for NT

shared as Interchk

Page 19: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Create Library

Page 20: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Create network account

• Used to update library files• May need to use pre-created domain account on

a domain controller• Unclear whether you need to pre-create account

if installing on member server in a domain– http://www.sophos.com/support/knowledgebase/

article/2522.html

• On standalone server you can choose option to create account

Page 21: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Create Network Account

Page 22: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Select Parent

Page 23: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Select Parent

• Source of files to download to library• Can be Sophos databank or another library

– Will generally be the Sophos databank

• Credentials available from ITSS restricted facilities web page– https://register.oucs.ox.ac.uk:6123/cgi-bin/dia

gonalley/index– Under Sophos EM Library Update Service– Do not divulge these to anyone except ITSS!

Page 24: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Select Parent

Page 25: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Schedule Downloads

Page 26: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Schedule Downloads

• Sets up schedule for downloading from Sophos or parent library

• Generally set up new schedule and accept defaults

• Downloads updates once every hour (random offset)

• Downloads can also be triggered manually via EM Library

Page 27: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Schedule Downloads

Page 28: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Schedule Downloads

Page 29: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Select Packages

Page 30: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Select Packages

• Default view shows only the current versions of the new Sophos clients

Page 31: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Select Packages

• Uncheck options to see more packages

Page 32: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Download Packages

Page 33: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Download packages

• Triggers initial download of packages to populate both library and central installation folders (CIDs)– Default CID already set up for each package

• If you want to move CIDs (e.g. to linux box) you can do this before downloading– …or later

Page 34: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Download Packages

• Can also be used at any time to trigger manual update of packages

Page 35: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Configuring Packages

Page 36: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Configuring Packages

• Subscribed– Will be downloaded according to schedule

• Unsubscribed– Will not be downloaded– Right-click to subscribe

• Published– Available to child libraries– Right-click to publish

Page 37: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Configuring Central Installations

Page 38: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Configuring Existing CIDs

• Can alter location of CID (e.g. to a different server)

• Can alter credentials to access CID• Can change updating schedule (default is

to update immediately after library is updated)

• Can locate CIDs on other servers, so long as the location is accessible from Windows box (e.g. via Samba)

Page 39: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Configuring Central Installations• Right-click to configure existing CIDs

Page 40: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Add additional CIDs

• Packages/subscribed and right-click on chosen package

• Configure options as per configuring existing CIDs

Page 41: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

CIDs — Additional Information

• Note special requirements for CIDs for the following clients (see manuals)– Mac OS X– Netware– Unix

• We will cover some of these points in more detail in future seminars

• Manually update a CID via right-click/Update CID

Page 42: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

CID AnatomyTop Level Purpose

cid\

setup.exe Main setup file

cidsync.upd Used to check synchronisation status

sau\ AutoUpdate files

cidsync.upd Used to check synchronisation status

sauconf.xml Optional file to configure updating policy

rms\ Remote Management System files

cidsync.upd Used to check synchronisation status

savxp\ Sophos Anti-virus files

cidsync.upd Used to check synchronisation status

savconf.xml Optional file to configure A-V policy

Page 43: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

CID Anatomy

• cidsync.upd– Clients use this to check synchronisation status– Includes details of all files (including ides)– Binary file, generally updated by EM Library

• rms folder is optional– Remote management components used by Enterprise

Console– Need to tell installer not to use it (default is to install

rms)– More on this in the next seminar…

Page 44: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

EM Library — Tools/Options

• Console Options– Display, refresh etc.

• Security– Who can run EM Library– Effectively adds and removes users or groups from

the EMLibrary Users group

• Notifications– Method (Email, Event Log, Network Messaging)– What is notified

Page 45: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

EM Library — Scripts

• \\server\SophosEM\bin\EMLexp.exe (C:\Program Files\Sophos Enterprise Manager\Library\bin\EMLexp.exe)– Export library settings to XML file– Import library settings from XML file– Trigger manual update of a library– NB File may require editing before import to

different server (see http://www.sophos.com/sophos/docs/eng/manuals/eml_men.pdf)

Page 46: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

EM Library — Scripts

• Manual update of child library via batch file– http://www.sophos.com/sophos/docs/eng/man

uals/eml_men.pdf)

– Page 48

Page 47: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Questions?

Page 48: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Sophos Enterprise Console

Page 49: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Enterprise Console

• Install using network installers as per EM Library• Manage clients in a controlled environment, e.g.

college or department– Remote installation and updating of Sophos– Status of Sophos on machines– Reporting

• Apply Policies for updating and A-V engine– Apply via Enterprise Console– Or export to files for inclusion in CIDs

Page 50: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Console View

Page 51: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Viewing Computers

• Actions/Find Computers– Relies on Microsoft networking (browse masters etc.)– Windows XP firewall likely to cause problems

• File/Import computers from file– File format (text file)

[]||name1||name2

– Netbios or DNS names– See help for full information (testing shows that you may need to

include OS)

Page 52: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Organising Computers — Groups

• Need at least one group in order to define policies

• Move PCs from Unassigned into groups

Page 53: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Configuring Policies

• Updating and Anti-virus policies

• Policies may be different for each group

• Updating policy has different sections for each OS– At least one section must be configured

• Updating policy must be set before protecting PCs via Enterprise Console

• Use Comply with… to enforce policies

Page 54: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Updating Policy

• Need to specify at least– Primary source (for updates)– Credentials (if required)

• Can specify other items– How often client checks for updates

Page 55: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Updating Policy

Page 56: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Anti-virus policy• E.g. scheduled and on-access scanning

Page 57: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Protect Computers — Prerequisites

• Need access to clients via file share– XP or other personal firewall– May prefer to install from client

• Need account with admin credentials on clients• Need same account credentials to exist on

server (does not need to be admin)– Don’t have to be logged in as this account– Suspect non-domain issue

• Must configure Updating Policy on group before protecting

Page 58: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Protect Computers — Wizard

Page 59: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Enterprise Console and Firewalls

• 3 services on client (see Appendix B)

• Using TCP 8192-8194

• Connections may be initiated by server or clients

• Be wary of firewalls at both ends

• Only applies for management of machines– Scheduled client updates are always initiated

from the client end

Page 60: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Policies

• Can be applied via Enterprise Console

• Can also be applied using files– Sauconf.xml (Updating policy) in sau folder– Savconf.xml (A-V policy) in savxp folder

• Useful for clients not managed by Enterprise Console– Web-based CIDs

Page 61: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Policies

• Export group policies from Enterprise Console using exportconfig.exe– \sec10\tools or \sec10ws\tools

• More detail in next seminar

Page 62: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Questions?

Page 63: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Sophos Clients

Page 64: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Client Installation

• Sophos AutoUpdate installed first– Configured with source of Sophos files– Credentials to access files

• Sophos AutoUpdate – Fetches and installs other components using source

and credentials

• Management Components– Optional (default install from CID includes these)– Enterprise Console will install them; can be turned off

using other installation methods

Page 65: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Client Components on Windows XP

Component Purpose Services

Sophos AutoUpdate

Updating Sophos

1. Sophos AutoUpdate Service

Sophos Anti-Virus

Virus Detection 1. Sophos Anti-Virus

2. Sophos Anti-Virus status reporter

Sophos Remote Management System

Enterprise Console Management

1. Sophos Agent

2. Sophos AutoUpdate Agent

3. Sophos Message Router

Page 66: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Client Configuration

• Groups created– SophosAdministrator– SophosPowerUser– SophosUser

• Automatically puts members of Administrators into SophosAdministrator, etc.

• Restricts access to configuration options

Page 67: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Group Restrictions

• Member of SophosAdministrator group

Page 68: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Group Restrictions

• Member of SophosUser group

Page 69: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Client Installation and Configuration

• To be continued…

Page 70: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Questions?

Page 71: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Appendix A — EM Library

• Default Shares– C:\Program Files\Sophos\Enterprise Manager\

console\bin\inst (EMLibInstaller)• Installation files for EM Library

– C:\Program Files\Sophos Enterprise Manager\Library (SophosEM)

• Library

– C:\Program Files\Sophos Sweep for NT (Interchk)

• Client software Central Installation Directories

Page 72: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Appendix A — EM Library

• Services created when Library is created– Sophos EMLibUpdate Agent – Sophos Enterprise Manager Scheduler

Page 73: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Appendix A — EM Library

• Users created (optional)– EMLibUser1 (can specify alternative account)– Member of Administrators

• Groups created– EMLibrary Users– Members of existing Administrators group are

made members automatically

Page 74: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Appendix B — Enterprise Console

• Shares created– None known

• Services created– Sophos Agent– Sophos AutoUpdate Agent– Sophos Certification Manager– Sophos Management Service– Sophos Message Router

Page 75: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

Appendix B — Enterprise Console

• Groups created– Sophos Console Administrators– Members of existing Administrators group are

made members automatically– Must be a member of this group in order to

run Enterprise Console

Page 76: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

References

• Sophos enterprise solutions installation advisor – http://www.sophos.com/misc/sophos_es_support_pac

k.chm

• Sophos Anti-Virus Startup Guide– http://www.sophos.com/sophos/docs/eng/instguid/esa

v_sen.pdf

• Sophos EM Library Manual– http://www.sophos.com/sophos/docs/eng/manuals/em

l_men.pdf

Page 77: Sophos Enterprise Solutions. This Seminar… Overview –Components — EM Library, Enterprise Console, Clients –OS requirements and product functionality EM.

References

• Sophos Enterprise Console Manual– http://www.sophos.com/sophos/docs/eng/man

uals/sec_men.pdf

• OUCS Guide to Installing and Configuring EM Library and Automatic Client Updating– http://www.oucs.ox.ac.uk/viruses/sophos/ente

rprise/– Refer to references section for more links