Download - Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

Transcript
Page 1: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

1

Talon FAST™

Firewall & Antivirus

Requirements Guide

Revision 401029

Page 2: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

2

TABLEOFCONTENTS

1. FirewallandAntivirusBestPractices............................................3

2. McAfeeVirusScan.........................................................................5

3. SymantecEndpointProtection12.x...........................................17

4. SophosEndpointSecurityandControlv10.x.............................25

5. TrendMicroOfficeScan..............................................................31

DISCLAMER:THISDOCUMENTATIONISPROVIDEDBYTALONONAN"ASIS"BASIS.TALONMAKESNOREPRESENTATIONSORWARRANTIESOFANYKIND,EXPRESSORIMPLIED,ASTOTHEOPERATIONOFTHEWEBSITEORTHEINFORMATION,CONTENT,MATERIALS,ORPRODUCTSINCLUDEDINTHISDOCUMENT.TOTHEFULLEXTENTPERMISSIBLEBYAPPLICABLELAW,TALONDISCLAIMSALLWARRANTIES,EXPRESSORIMPLIED,INCLUDING,BUTNOTLIMITEDTO,IMPLIEDWARRANTIESOFMERCHANTABILITYANDFITNESSFORAPARTICULARPURPOSEANDNON-INFRINGEMENT.

AlthoughTalonhasattemptedtoprovideaccurateinformationinthisdocumentation,Talonassumesnoresponsibilityfortheaccuracyorcompletenessoftheinformation.Talonmaychangetheprogramsorproductsmentionedinthisdocumentatanytimewithoutnotice,butTalonmakesnocommitmenttoupdatetheprogramsorproductsmentionedonthiswebsiteinanyrespect.Mentionofnon-Talonproductsorservicesisforinformationalpurposesonlyandconstitutesneitheranendorsementnorarecommendation.

Page 3: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

3

1. FIREWALLANDANTIVIRUSBESTPRACTICESNote:WhileTalonmakesareasonableefforttovalidatethatthefollowingantivirusapplicationsuitesarecompatiblewiththeTalonFAST™solution,wecannotguaranteeandarenotresponsibleforanyincompatibilitiesorperformanceissuescausedbytheseprograms,ortheirassociatedupdates,servicepacks,ormodifications.TalondoesnotrecommendtheinstallationnorapplicationofmonitoringorantivirussolutionsonanyFAST™enabledappliances(CoreorEdge).Shouldasolutionbeinstalled,bychoiceorbypolicy,thefollowingBestPracticesandrecommendationsmustbeapplied.

MicrosoftFirewall

• RetainFirewallSettingsasDefault

Recommendation:LeaveMicrosoftFirewallsettingsandservicesatthedefaultsettingofOFFandnotstartedforstandardTalonFAST™CoreorEdgeinstallations.

Recommendation:LeaveMicrosoftFirewallsettingsandservicesatthedefaultsettingofONandstartedforCoreorEdgeappliancesalsobeingusedasdomaincontrollers.

CorporateFirewall

• RetainFirewallSettingsasDefault•Firewall:ports6618-6621(TalonFAST™usesTCPports6618-6621)• WANOptimizationsolutions/devicesmustbeconfiguredto“Pass-thru”Talon-specificports

Client-SideSoftware

TalonhastestedcommonantivirussoftwarepackagesincludingMcAfee,Symantec,SophosandTrendMicroforusealongsideourFAST™solutiononbothCoreandEdgesystemsconfiguredtorunoursoftware.

Note:AddingantivirustoanEdgeappliancemayintroducea20-30%impactonuserperformance.

Pre-Installationnotes

• TheantivirussoftwarepackageshouldbecertifiedbyTalon.• Theantivirussoftwarepackage(likeanyothercertifiedsoftware)shouldonlybeinstalledondriveC:\

Page 4: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

4

RestrictFileScanning

Applicationsthatscanfilesand/orfoldersinordertogatherstatisticsorotherdatasometimesonlyreadmetadataofthefilewithoutreadingactualdatacontainedwithinthefile.Otherapplicationsmayopeneachfileindividuallyinordertodeterminethetypeofdatapresentinthefile.Inthecaseofpictures,music,orvideofiles,certainapplicationsmayalsocreatethumbnailsorprovideadditionalinformationaboutthecontentsofthefile.

ScansthatcausethesetypesoffileopenoperationsshouldbeavoidedontheEdgeapplianceandontheclientworkstation.AnyopenofafileinthismannerwillcausetheEdgeappliancetoretrievethefilefromthebackenddatacenterfileserverandcacheitlocallyinthebranchoffice.ScanningtogatherstatisticsorprovidethumbnailstopicturefilescouldalsocausetheEdgeappliancetoretrieveandcachemoredatathanthecachewasoriginallysizedtoaccommodate.Client-sidesoftwarethatsearches,indexesand/orscansnetworkfilesandfolderscancauseunnecessarymetadataandfiletransfersovertheWAN,resultinginanadditionalloadontheapplianceandshouldbeavoided.

AntivirusCoverageRecommendation

AntivirussoftwareinstalledonthebackenddatacenterfileserverandonclientPCsisgenerallyadequateprotectionagainstnetworkviruses.TalondoesallowdataonitsEdgeandCoreappliancestobescanned,ensuringcompletepoint-to-pointprotection.However,onbothCoresandEdges,theD:\(cachedrive)andT:\(virtualfileshare)volumesshouldbothbeexcludedfromvirusscanningaswellasanyTalonFAST™processes.Users’mappednetworkdrivesshouldneverbescanned.

ConfigureExclusions

AntivirussoftwareorotherthirdpartyindexingorscanningutilitiesshouldneverscandriveD:\ordriveT:\ontheEdgeappliance.ThesescansofEdgeserverdrivesD:\andT:\willresultinnumerousfileopenrequestsfortheentirecachenamespace.ThiswillresultinfilefetchesovertheWANtoallfileserversbeingoptimizedatthedatacenter.WANconnectionfloodingandunnecessaryloadontheEdgeappliancewilloccurresultinginperformancedegradation.

ThefollowingTalonFAST™processesshouldbeexcludedfromanyandallantivirusscans:

• C:\ProgramFiles\TalonFAST\Bin\LMClientService.exe• C:\ProgramFiles\TalonFAST\Bin\Optimus.exe• C:\ProgramFiles\TalonFAST\Bin\tafsexport.exe• C:\ProgramFiles\TalonFAST\Bin\tafsutils.exe• C:\ProgramFiles\TalonFAST\Bin\tapp.exe• C:\ProgramFiles\TalonFAST\Bin\TService.exe• C:\ProgramFiles\TalonFAST\Bin\tum.exe• C:\Windows\System32\drivers\tfast.sys

Page 5: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

5

2. MCAFEEVIRUSSCAN

ThissectionoutlinesbestpracticesforMcAfeeVirusScanEnterpriseversiontargetedforTalonFAST™appliancesbasedonWindowsServer2012R2.

BaselineProtection

AftercompletingaStandardinstallationoftheMcAfeeVirusScanEnterpriseandchoosingtonotperformtheinitialOn-demandscan,followtheconfigurationspecificsasoutlinedbelow,includingOn-AccessScanning,FullandTargetedScan.

Page 6: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

6

ExcludingServicesandProcessesinMcAfeeVirusScanConsole

ThissectiondetailshowtoexcludeTalonFAST™processesonCore/EdgeServersandotherremoteappliancesbasedonMcAfeeVirusScanscanning.

✍Note:EnsurethatTalonFAST™processes,services,anddrivesareexcludedonantivirusserversandclientsandasagrouppolicyforTalonFAST™users,ifapplicable.

• Doubleclickthe“On-AccessScanner”taskinthemainVirusScanConsolewindow.

Page 7: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

7

• Click“DefaultProcesses”intheleftpaneandthenselecttheradiobuttonlabeled“Configuredifferentscanningpoliciesforhigh-risk,low-risk,anddefaultprocesses.”

• Clickthe“Exclusions”tabandthenclickthe“Exclusions…”buttontoconfigurethem.

Page 8: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

8

• AddtheT:\andD:\drivestotheExclusionslist.Ensurethatsubfoldersarealsoexcludedfromscans.ClickOKwhenfinished

• ClicktheScanItemstabandde-select“Whenwritingtodisk”

Page 9: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

9

• Click“Low-RiskProcesses”intheleftpane.• Clickthe“Add…”buttononthe“Processes”tab.

Page 10: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

10

• Oncethelistofavailableprocessesfinishespopulating,youmayneedtoclickthe“Browse…”buttonandmanuallyaddthefollowingprocesses.

• C:\ProgramFiles\TalonFAST\Bin\LMClientService.exe• C:\ProgramFiles\TalonFAST\Bin\Optimus.exe• C:\ProgramFiles\TalonFAST\Bin\tafsexport.exe• C:\ProgramFiles\TalonFAST\Bin\tafsutils.exe• C:\ProgramFiles\TalonFAST\Bin\tapp.exe• C:\ProgramFiles\TalonFAST\Bin\TService.exe• C:\ProgramFiles\TalonFAST\Bin\tum.exe

• ClickOKtoapplythechanges.

Page 11: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

11

• Clickthe“ScanItems”tabandde-select“Whenwritingtodisk”and“Whenreadingfromdisk”.

Page 12: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

12

• Clickthe“Exclusions”tabatthetop.• Clickthe“Exclusions…”button

Page 13: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

13

• AddtheT:\andD:\drivestotheExclusionslist.Ensurethatsubfoldersarealsoexcludedfromscans.• AddC:\Windows\System32\drivers\tfast.sys.Note:Youmayhavetomanuallytypeinthispathtoadd

tfast.sys• ClickOKwhenfinished.

Page 14: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

14

FullorTargetedScans

IfrunningafullortargetedscanonaTalonFAST™server,pleasefollowthestepsbelow

• DoubleclickeitherFullScanorTargetedScanfromtheVirusScanConsole

• Clickthe“Exclusions”tabfromtheOn-DemandScanPropertieswindow.Clickthe“Exclusions…”button.

Page 15: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

15

• AddtheT:\andD:\drivestotheExclusionslist.Ensurethatsubfoldersarealsoexcludedfromscans.

ClickOKwhenfinished.

Page 16: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

16

PreventConnectionBlockinginSharedFolders

WiththeexclusionsoftheD:\andT:\drives,itisrecommendedthatconnectionsnotbeblockedfromsharedfolders.ThiswillprovideconsistentfileaccessfromtheTalonVirtualFileShare,T:\.

Todisabletheconnectionblocking,unchecktheboxasshownbelow:

Page 17: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

17

3. SYMANTECENDPOINTPROTECTION12.X

ThissectionoutlinesbestpracticesforSymantecEndpointProtectionversion12.xtargetedforTalonFAST™appliancesbasedonWindowsServer2012R2.

DoubleclicktheSymantecicononthetaskbar

VirusandSpywareProtection->ClickOptions->ChangeSettings

ClickViewList

Page 18: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

18

ClickAdd->SecurityRickException->Folder

Scrolldown,clickonD,andclickOK

Page 19: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

19

ClickAdd->SecurityRiskException->Folder

Scrolldown,clickonT,andclickOK

Page 20: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

20

ClickAdd->SecurityRiskException->Folder

Addthefollowing:

• C:\ProgramFiles\TalonFAST\Bin\LMClientService.exe• C:\ProgramFiles\TalonFAST\Bin\Optimus.exe• C:\ProgramFiles\TalonFAST\Bin\tafsexport.exe• C:\ProgramFiles\TalonFAST\Bin\tafsutils.exe• C:\ProgramFiles\TalonFAST\Bin\tapp.exe• C:\ProgramFiles\TalonFAST\Bin\TService.exe• C:\ProgramFiles\TalonFAST\Bin\tum.exe• C:\Windows\System32\drivers\tfast.sys

Page 21: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

21

ClickAdd->ApplicationException

Page 22: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

22

BrowsetoC:\ProgramFiles\TalonFAST\Bin\andaddtum

ClickOK

ClickontheAuto-Protecttab.UnderFileTypes,clickSelected.UncheckDeterminefiletypesbyexaminingfilecontents.ClickAdvanced.

Page 23: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

23

Adjustsettingsasshownbelow

ClickNetwork

UncheckNetworkcache

ClickOK

Page 24: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

24

NetworkThreatProtection->ClickOptionsandselectViewNetworkActivity

Rightclicktum.exeandselectAllow

Configurationiscomplete.

Page 25: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

25

4. SOPHOSENDPOINTSECURITYANDCONTROLV10.X

ThissectionoutlinesbestpracticesforSophosEndpointSecurityandControltargetedforTalonFAST™appliancesbasedonWindowsServer2012R2.

BaselineProtection(EnterpriseConsoleconfiguration)

AftercompletingatypicalinstallationoftheSophosEnterpriseConsole,followtheconfigurationspecificsasdocumentedbelow.ThisprocessoutlinestheproceduretoconfigureSophosEndpointSecurityandControlfromacentralconfigurationperspective.

Page 26: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

26

ExcludingServicesandProcessesusingSophosEnterpriseControl

ThissectiondetailshowtoexcludeTalonFAST™processesonserverandremoteappliancesfromSophosantivirusscanning.

✍Note:EnsurethatTalonFAST™processes,services,anddrivesareexcludedfromantivirusscanning

ThesechangesshouldbemadetoServerandClientpoliciesaswellasgrouppolicyforTalonFAST™usersifapplicable:

• ExpandtheAnti-VirusandHIPStreeinthePoliciessectionoftheEnterpriseConsole.Double-clickthepolicyyouwishtoadjust.

• Clickthe“Configure…”buttonnexttoEnableon-accessscanning.

Page 27: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

27

• Clickthe“WindowsExclusions”tab

Page 28: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

28

• AddthefollowingitemstotheExcludedItemslistandclickOKwhenfinished:ü C:\ProgramFiles\TalonFAST\Bin\LMClientService.exeü C:\ProgramFiles\TalonFAST\Bin\Optimus.exeü C:\ProgramFiles\TalonFAST\Bin\tafsexport.exeü C:\ProgramFiles\TalonFAST\Bin\tafsutils.exeü C:\ProgramFiles\TalonFAST\Bin\tapp.exeü C:\ProgramFiles\TalonFAST\Bin\TService.exeü C:\ProgramFiles\TalonFAST\Bin\tum.exeü C:\Windows\System32\drivers\tfast.sysü D:ü T:

Page 29: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

29

Toverifythecentralconfigurationresultsonaconnectedclientmachine,wecanusetheSophosEndpointSecurityandControlpanel.

• Click“Configureanti-virusandHIPS”

• Click“On-accessscanning”

Page 30: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

30

• Clickthe“Exclusions”tabtoverifythatthecorrectpolicyandexclusionshavebeenappliedtotheappliance.

SophosbuiltinFirewall

MicrosoftWindowsServer2012R2bydefaultincludesaMicrosoftWindowsFirewall.TalonFAST™softwareautomaticallyprovidesascripttoperformMicrosoftWindowsfirewallmaintenance,allowingportsassociatedwiththeTalonFAST™product.TalonrecommendstheuseoftheMicrosoftWindowsfirewall.

Page 31: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

31

5. TRENDMICROOFFICESCAN

1. OpentheManagementGUIandnavigatetoNetworkedComputers->ClientManagement.

2. Navigateto“ScanSettings”->”Real-TimeScanSettings”.

Page 32: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

32

3. Onthe“Target”tab,enable“FiletypesscannedbyIntelliScan”.

4. Directoryscanning.Scrolldownandaddthefollowingexclusionsto“ScanExclusionList(Directories)”topreventTrendMicrofromscanningTalonrelateddirectories:•C:\ProgramFiles\TalonFAST\bin\*•C:\ProgramFiles\TalonFAST\bin•D:\*•D:•T:\*•T:

Page 33: Talon FAST 4.x - Firewall and Antivirus Requirements FAST... · Firewall & Antivirus Requirements Guide ... 1. FIREWALL AND ANTIVIRUS BEST PRACTICES ... , and drives are excluded

33

5. TrendMicrowillscanactiveprocessesbeforeperformingafolder/filescan.Scrolldownandaddthefollowingexclusionsto“ScanExclusionList(Files)”:•C:\ProgramFiles\TalonFAST\Bin\*.exe•C:\Windows\System32\drivers\tfast.sys•TFAST.sys•TService.exe•Tapp.exe•tum.exe