background image

Administration

 

Installation Guide

6

EMON

EMON (Email MONitor), a complementary resident module, scans emails 

incoming via MAPI interface. The MAPI interface hooks into the different 

interfaces of Microsoft Outlook. MAPI interface is used also when receiving 

emails from the Microsoft Exchange Mail Server via the Exchange protocol.
Even if the MAPI Interface is 

not

 used on the computer, EMON will still 

be installed. E-mails incoming via the POP3 protocol 

will be checked 

by IMON.

As with IMON, you may want to alter similar scanning features within this 

module.

XMON

XMON stands for MS Exchange MONitor which serves for scanning 

incoming 

and

 outgoing email, utilizing the MS VSAPI interface on MS 

Exchange servers. The minimum requirements are MS Exchange 5.5 

SP3, MS Exchange Server 2000 SP1, MS Exchange 2003 or higher. The 

newer the version of MS Exchange server you have, the more features are 

available in XMON.
The removal of entire infected email is supported from MS Exchange server 

2003. Otherwise, this option is unavailable and the appropriate check-box 

is grayed out.

Using XMON requires a 2nd license file. In the 

License Keys

 section 

(top of the Configuration Editor list: General / Settings), you can locate and 

add the license key for XMON (nod32.lic) that you have purchased.

Summary of Contents for LAN Update Server 2.7

Page 1: ...udes Windows Vista and 64 bit protection RemoteAdminstrator1 0 14 andLANUpdateServer2 7 Installation Guide Proactive protection againstViruses Spyware Worms Trojans Rootkits Adware and Phishing Best Detection Fastest Performance Minimal Resource Utilization ...

Page 2: ...ks of Microsoft Corporation Eset LLC 610 West Ash Street Suite 1900 San Diego California 92101 U S A http www eset com For Sales and Technical Support US and Canada Tel 619 876 5400 Fax 1 619 876 5845 Online purchase http www eset com purchase index php Sales email sales eset com Technical Support Worldwide http www eset com support Then by clicking on your country s name you can locate the suppor...

Page 3: ...pdateNowTask Section8 MoreDetailedInformation RemoteInstallindetail Thefilenod32installer exe Clientswindow Contextmenuoptions Contextmenuexamples Alertlogwindow Eventlogwindow Scanlogwindow Taskswindow Reportswindow Licensekey nod32 lic RACconnectiontoRAS settings RACserveroptionssetup UseRACmoreefficiently Section9 PossibleProblems ErrorCodes Errormessages Section10 Installationinamulti sitenetw...

Page 4: ... best protection and administration possible NOD32 is more than just a virus scanner being able to scan for known viruses is the bare minimum that should be expected from an anti virus product so it should be reassuring to know that NOD32 not only does this faster and more reliably than other products but that it also has an excellent track record in discovering new threats In addition version 2 7...

Page 5: ...nable both On Access scanners at once If another anti virus program has previously been installed on your computer its scanner may interfere with NOD32 Usually resident scanners will display an icon in the system tray the area of the taskbar near the clock We recommend removing any other antivirus software including older versions of NOD32 before installing NOD32 Version 2 7 to avoid the possibili...

Page 6: ...Administration Installation Guide Overview ...

Page 7: ... NT based operating system NT4 2000 XP 2003 but doesn t have to be a server operating system The updates will be stored there and then picked up by the workstations in your network So the server acts as a mirror to your clients and is referred to as such in the setup Using NOD32 Remote Administrator Console RAC the administrator can get a global overview of the NOD32 antivirus system activity on n...

Page 8: ... large corporate networks It consists of two modules NOD32 RA Server RAS and NOD32 RA Console RAC FEATURES Quick overview of your network security situation Comprehensive statistics in an intuitive graphical form Enables virus scan on remote disks Remote NOD32 client configuration file editing on chosen workstations Remote installation uninstall of NOD32 antivirus system Localization of unprotecte...

Page 9: ...Administration Installation Guide Installation foranoffice network ...

Page 10: ...eset com download balance php dir download ra rasrvnten exe The product must be installed on an MS Windows NT based operating system NT4 2000 XP 2003 RAS is installed by running the file rasrvnten exe During installation the program will ask for the location of the license key ie the file called nod32 lic which contains information about its owner its expiry date as well as about the number of use...

Page 11: ... dir download ra raconsnten exe Install NOD32 LAN Update Server Using your Username and Password download and install NOD32 LAN Update Server Mirror version onto your server http www eset com download balance php dir download win v2ad ndntenad exe Its virus signature database will form the basis of a so called Mirror for the client workstations For detailed instructions on downloading and installi...

Page 12: ...h require a restart of the operating system and bring a lot of new features and improvements to NOD32 it is an upgrade to a completely new version eg from 2 5 to 2 7 Choose this to ensure that the program component upgrade will not be applied to a local update server immediately it is available on the servers of the Eset company NOD32 on the workstations will remain in the current version and the ...

Page 13: ...g a possible Program Component Upgrade at some point after the initial installation on the client workstations Using your Username and Password download only NOD32 for Windows NT 2000 2003 XP Vista 32 bit 64 bit onto your server http www eset com download balance php dir download win v2st ndntenst exe assuming you have machines running these operating systems in your network Using your Username an...

Page 14: ...Administration Installation Guide 14 Running RAC ...

Page 15: ...via their Control Center s Go to Tools Console options Connection Add Remove and enter the DNS name of your server You can use the IP address instead but if that ever changed in the future it might cause a problem click OK From the Select Connection box choose the server name you ve just added Press Connect In the Current state of connection window you should see the name of the server If true pre...

Page 16: ... If there is another server showing other than the one which the administrator is currently connected to then it is a result of replication You may add a connection via SMTP server also if you have a mail server address and you wish to be contacted via email from your clients about alerts etc or you wish to install on some clients via email Tools Server Options Other Settings tab ...

Page 17: ...Administration Installation Guide 17 Configuration Editor ...

Page 18: ...ated with the installation package s you will soon create The Configuration will be saved as an xml file You can set this up before or during the creation of your installation package Here are 3 ways to do this Start Program Files Eset Configuration Editor Now make the necessary changes to your configuration as described on the next page and save with a title and directory of your choice on the se...

Page 19: ...itor You will now see a window like this Rather than look at every single option in the editor we ll take a look at the crucial areas that should be considered when setting up a configuration but obviously you can change as many options as you wish Further in depth information can be found on page 49 When an item is changed the radio button beside it turns blue This helps you to identify quickly t...

Page 20: ...machines you will need to enter the SMTP server address or IP address that you use plus the sender address should be entered exactly as ComputerName yourcompany com which will enable you to identify the relevant machine in your network Pay close attention to the way ComputerName is entered as this is case sensitive Also enter the email address you d like the warnings sent to Also you can choose to...

Page 21: ...se MS Exchange Server you will need a 2nd license key for XMON which can also be added to this folder Now move further down the list to Update Profile My Profile Settings Update server address In the Update section again the majority of the default settings should prove satisfactory however there are a couple of absolutely vital settings that you must enter in this section Internet connection type...

Page 22: ... side of the Editor s window and in the new window click Add Select the type of task you wish to add Hint if you wish to run a scan with specific command line parameters choose Execution of an external application The next few windows will be quite self explanatory ie giving the task a name when you want it to run etc After you click the Finish button you will need to enter the name of the task ag...

Page 23: ...reatening actions on protected computers such as opening executing creating or renaming files It is recommended to leave the default settings for this module However there may be an instance when a particular file or program used in your network needs to be excluded from scanning Also you may have reason to not want your workstations to scan network files DMON Microsoft Office documents Word Excel...

Page 24: ... of items you may want to look at You may not want IMON to append a message at the bottom of every email that your clients receive so this can be changed to only infected emails or no notification at all Also you may have reason to want certain applications excluded from IMON s scanning so the program s can be added to an exclusion list here IMON s Scanner is generally setup to optimum performance...

Page 25: ...alicious code What s more if the application repeatedly attempts to download an infected file it may use the already downloaded data and request only the rest of the file In this case IMON may not find anything suspicious in the remaining portion In Active mode default IMON first downloads and scans the whole file and then passes it on to the target application This procedure is safer because in t...

Page 26: ...es within this module XMON XMON stands for MS Exchange MONitor which serves for scanning incoming and outgoing email utilizing the MS VSAPI interface on MS Exchange servers The minimum requirements are MS Exchange 5 5 SP3 MS Exchange Server 2000 SP1 MS Exchange 2003 or higher The newer the version of MS Exchange server you have the more features are available in XMON The removal of entire infected...

Page 27: ...y diskettes My Profile create and save a profile with your own settings The above headings are to give the user a selection of names for specific scans You can create and name as many new profiles as you wish You might like to create names that are more specific for your clients or easier to understand perhaps To create click Profile in the toolbar and choose New profile or right click on a Profil...

Page 28: ...ultant scan log could be enormous and therefore difficult to plough through when checking for threats Run time packers Archives and Self extracting archives are not set to be scanned by default because of the slow down in scan time plus there is a much higher chance that scanning in archives could lead to a greater number of incidents like Why can t I delete that nasty infiltration or What exactly...

Page 29: ...tomatic update occurs an hour after the last update so even if all clients were installed exactly at let s say 8 00 then the first automatic update will be scheduled for all of them at 9 00 But in the meantime one client could hit the Update Now button or has restarted and thus update occurred during logon let s say at 8 30 Even if there was actually no fresh update available at that time the next...

Page 30: ...rol Center and go to the Update Setup section and click on the Profiles button Press Add and copy from the default My Profile and call the new profile a name of your choice like Office Profile maybe This should be set to update from your local DNS server ie Add a new server and enter http myservername 8081 Now Add another new profile Copy it from the default My Profile and call it Out of Office Pr...

Page 31: ...ect Configuration from the context menu In the next window select Save as and give the configuration a name of your choice The setup will then open in the Configuration Editor with the settings you ve just arranged in NOD32 on your workstation You can now alter any other settings as previously described from pages 19 to 28 A couple of items that you ll need to alter at this point Under General Set...

Page 32: ...ecting File Save from the toolbar and not by just closing the configuration window which will cause the Settings ID to NOT be written correctly which may cause problems with clients not picking up the configuration properly If you created a configuration using method 3 as decribed on page 18 ie whilst setting up a package then it will be saved in C Program Files ESET RA Server Packages Default nod...

Page 33: ...Administration Installation Guide 33 Createa package ...

Page 34: ... OK and you will move back to the Packages Editor window Option 3 Press Select and you can choose a pre designed package that you may have already created or select either or both of the built in installers eg C Program Files ESET RA Server packages Default nod32_nt nip and or nod32_98 nip Whichever method you chose you will now be back in the Packages Editor window again In the Edit Select config...

Page 35: ...Administration Installation Guide 35 Remote Installation ...

Page 36: ... to regain resources as a protective measure Given that a server is not used as a workstation for accessing email or surfing the internet IMON is therefore not necessary anyway Make sure as you are the administrator of your network that you have set your admin s logon name and password to access all your clients If the password is left blank connection to your clients will not work If installing o...

Page 37: ...allation only for workstations with WinNT 2000 XP 2003 Vista operating systems The installation is pushed to remote workstations directly on the administrator s command While on the Remote Install tab in RAC click on the Install button In the new window Package text box select your new package In the left hand panel select maybe one client to start with drag him over to the right hand panel and cl...

Page 38: ...lient will show up in the RA Console under the Clients tab This is because 5 minutes is the default time period that the clients will contact the server You can of course alter this time period in the installation package see Configuration Editor chapter page 17 If successful choose some more or all of the other clients and push the installation to them also Go to the Clients tab in RAC and you ll...

Page 39: ... You may choose any name for this folder It doesn t even have to be a shared folder since a logon script uses proper share C in the screenshot example Whatever folder you choose the Share field will be filled automatically In the Script location section choose the current logon script directory and select the logon scripts that will be customized for the NOD32 logon script installation Select the ...

Page 40: ...ter Of course the best and logical choice is the Domain Administrator account since you ensure that you have administrative access to all computers in the domain When administrating multiple domains workgroups we recommend to create an RA server for each domain workgroup so that the server will keep the Default Logon with administrative rights to all clients of that particular server All correspon...

Page 41: ...indows will start While on the Remote Install tab in RAC click on the Email button In the new window choose the required Package and select addresses where the nod32installer exe file will be sent It is also advised to define the Subject and Body of the e mail being sent out to your clients For the RA server to work properly it is required to set the SMTP server address and sender e mail address I...

Page 42: ...th your administration license and install onto your chosen workstation following the Typical installation route and reboot the machine Open the NOD32 Control Center and go to the Update Setup section In the Location panel press the Servers button and then Add In the new window enter your server s details like this http myservername 8081 or http myserver sIPaddress 8081 and click OK The Username a...

Page 43: ...Administration Installation Guide 43 Use of Tasks ...

Page 44: ...rd press the key combination CTRL and N or from the toolbar File New Task Configuration task changes in configuration To apply a configuration task to client workstations first you must create clicking on the Create button or choose an already existing the Select button XML configuration file Configuration setup takes place in the NOD32 Configuration Editor it is described in more detail in the ch...

Page 45: ...hted in the left hand Clients window Alternatively you can select some or all clients that are listed and click the button to add them to the list under Selected items in the right hand panel In the final step you can name the task or add its description This data serves only to help the administrator and for easier orientation At the same time you can delay the task Apply task after or provide it...

Page 46: ...anged the Edit button Use the Create from Template button to open an existing scan configuration and use it as a background for a new configuration The original template will stay unchanged even if you make some changes In this mode viewing editing creating only the scanner settings are available to view In the upper section choose a profile name from the Profile name pull down menu If this profil...

Page 47: ...uration put them in the Selected items section Click on the Add from Clients Pane to add currently displayed clients to the pane under Selected items Check the Selected option to move only those clients which were highlighted in the left hand Clients window Alternatively you can select some or all clients that are listed and click the button to add them to the list under Selected items in the righ...

Page 48: ... under Selected items Check the Selected option to move only those clients which were highlighted in the left hand Clients window Alternatively you can select some or all clients that are listed and click the button to add them to the list under Selected items in the right hand panel And finally name the task or add a description to it These features serve only for easier orientation for the admin...

Page 49: ...Administration Installation Guide 49 More detailed information ...

Page 50: ...ckage starts together with predefined attributes configurations command line parameters etc In the case of the variant Export to logon script or Send via E mail the process starts with the running of the file nod32installer exe either manual by user or automatic eg from logon script Then these operations take place The file nod32installer exe is started as a service and executed After that nod32in...

Page 51: ...tor Server product In case this address was not specified the file is given a default name ie the name of the machine where RAS is being installed The file nod32installer exe can be installed with the following parameters without slash MODE defines whether it is installation of NOD32 for Windows value 1 or uninstall value 0 SERVER name or IP address of RAS from which the NOD32 installation package...

Page 52: ...irus signature database on the client workstation If there is an older version on the workstation the data field is shown in red default but it does not inevitably mean there is a problem eg in case the workstation has been shut down for a week it can be indicated in Last Connected Last Connected Shows the time since the last connection of NOD32 on the workstation to the RAS server According to th...

Page 53: ...ddress of the client workstation Mobile User If the Mobile User option is turned on then the workstation will be updated as soon as the machine connects to the RAS see interval defined by the NOD32 Control Center settings This attribute can be enabled by the Set Mobile User flag option using the right mouse button context menu It s recommended to use the Mobile User setting if you connect to the n...

Page 54: ...example different configuration settings can be pushed to specific groups Request Configuration If the client is not currently connected to RAS ie the machine is switched off selecting this option will show the configuration is requested in the Clients window in RAC so that when the client workstation is running again the message will change to Ready and you can right click on the client and choos...

Page 55: ...kstations John and Mary In the Alert Log tab click the right mouse button on any cell with the text John in the Client Name column In the context menu choose Select by John Now press and hold the CTRL key and in a similar way with the right mouse button and by selecting Select by Mary select Mary Click the right mouse button and choose Hide Unselected from the context menu Release the CTRL key At ...

Page 56: ...click on the client to gain more detailed information about the performed scan or request for the details if servers in your network are replicated Tasks Type type of task Name name of task Date To Deploy date and time of assigning to target client computers Description note added by administrator to describe the task Configuration information about accessibility to current configuration Double cl...

Page 57: ...eter Add also the current period is active the period chosen above will also include events from the last closed period until the moment of creating From To Use this setting to define a period for which the report will be generated Example We want to create a report including events from the last calendar week ie from Sunday to the following Saturday We want such a report to be generated on the fo...

Page 58: ...menu options you can perform other operations with reports Favorite templates can be placed in the left window Favorites and thus you can later immediately generate reports from favorite templates To move a template to Favorites choose Add to Favorites in the context menu in the list of the scheduled templates Following is a list of report types Top Viruses list of the most frequently detected vir...

Page 59: ... there are more clients than is defined in the license key purchased only a limited number of clients corresponding with the defined number will be displayed Note Should you have any problems with application of license keys please look in the file C ProgramFiles Eset RA Server nod32ra log where you can find the exact reason for the failure RAC Console connection to RAS Server setup More detailed ...

Page 60: ...r s local time Other settings tab Filter settings Auto Apply Changes allows all settings in the filter pane except the server client names to be applied automatically if changed Other settings Use automatic refresh automatic data refresh in a current folder and in chosen interval Empty console recycle bins at application exit click to remove items from internal recycle bin of the console after fin...

Page 61: ... clients not connected for the last X months this will completely delete clients who have not connected within the specified time interval Delete alert logs older than X months Delete event logs older than X months Delete scan logs older than X months Clean up scheduler Clean up every XX minutes sets the frequency of the above mentioned processes Clean Up Now button older records will be deleted a...

Page 62: ...hem from a child server Replication from settings Enable from replication Check this option to define RAS child servers their names in the Allowed servers dialog box from which RAS will receive requests for replication If you use more servers please separate their names by commas RAS can also be configured directly with the file nod32ra ini Replication takes place on TCP port 2846 Other settings S...

Page 63: ...be included in the output Only clients like Only those clients whose name contains a thread you typed in will be included in the output In the next section you can limit filtration by the Groups division Clients in Groups In this case only clients belonging to defined groups will be selected Clients in other Groups or N A Only clients belonging to other than chosen groups or not belonging to any g...

Page 64: ...og Event Log Scan Log and Tasks choose the Edit Delete special option Click the Specify Date button to define what data should be removed Maintenance and backing up of NOD32 Remote Administrator Server We recommend keeping the RAS database up to date and deleting old records in order not to overburden the system unnecessarily It applies mostly to data in the Alert Log tab To delete unnecessary dat...

Page 65: ...Administration Installation Guide 65 Possible problems error codes ...

Page 66: ...or means that a wrong or unknown password for the account under which remote installation was to take part was entered Problem Quite often you can come across this message caused by the nod32installer exe NOD32 Installer was told to quit by the server XYZ It means that installation on the chosen client workstation was already performed successful or not and RA refuses to repeat it Solution This me...

Page 67: ...2 remotely to this platform Problem Windows XP Service Pack 2 contains a built in firewall The firewall if turned on blocks the NOD32 installation package sent to a workstation Solution To solve the problem enable File and Printer Sharing in the Windows firewall Solution procedure Click on Start then click on the Control Panel icon Select Windows Firewall In the Exceptions tab check File and Print...

Page 68: ... service is started does not have the right to install To solve the problem start the NOD32 RAS service from the Administrator s user account Solution procedure click on Start Settings Control Panel Administrative Tools Services right click on the NOD32 Remote Administrator service and from the context menu choose Properties choose This Account from the Log On tab and insert Administrator click OK...

Page 69: ...115 the current version not compatible with the old version you need to uninstall the old version 116 error writing to the operating system registry 117 upgrade required 118 attempting to overinstall with a different language version uninstall the previous version first 119 corrupt uninstall file 120 registering service error 121 component installation error 122 cannot install a certain component ...

Page 70: ...Administration Installation Guide 70 Installation for a multi site network ...

Page 71: ... group of client workstations All transfers between servers are encrypted A company department network is an example of a sub network It is recommended to install RAS for each department controlling client computers only within its own network as seen in the illustration on the following page If from the point of view of replication RAS 1 will be set as the main root server then all the other serv...

Page 72: ...Administration Installation Guide 72 ...

Page 73: ...re administrators to control only partial groups of client workstations and which are connected to a certain RAS and to RA servers inferior to it What information will be retrieved from the client workstations connected to inferior RA servers is configured in the replication setup Replication is nothing other than a communication of RAS with superior RA servers Its specific features are described ...

Page 74: ...Administration Installation Guide 74 Installation for asmall office network ...

Page 75: ...e correct version should either be for Windows 95 98 ME or Windows NT 2000 2003 XP Check out this machine s operating system before you download For Windows NT 2000 2003 XP Vista 32 or 64 bit http www eset com download balance php dir download win v2ad ndntenad exe For Windows 95 98 ME http www eset com download balance php dir download win v2ad nd98enad exe Its virus signature database will form ...

Page 76: ...ck Require permission to perform program component upgrade Besides the virus signatures database update a license also includes program updates program component upgrades which require a restart of the operating system and bring a lot of new features and improvements to NOD32 it is an upgrade to a completely new version eg from 2 0 to 2 5 Choose this to ensure that the program component upgrade wi...

Page 77: ...k on the Setup button In the Mirror Setup dialog window click on Setup in Configuration files After clicking on the Setup button select Add then New and create a new configuration file Save the new configuration file anywhere on the local disk EXCEPT for the folder that holds the Mirror After this is done the application NOD32 Configuration Editor is launched see page 17 for more details After req...

Page 78: ...sing your Username and Password and save to your desktop the version s of NOD32 that you will be installing on your client s PCs Do not run the installer s Next right click on the installer and choose Extract to or Extract files will depend on the archiving program you use Choose to save the contents to a new folder on your desktop Name the folder NOD32 Install or any special name you wish but for...

Page 79: ...lder version of NOD32 over an existing version without providing a popup warning to the client must be used in conjunction with REBOOT CFG switch with a configuration name if this parameter is not present NOD32 XML is used by default SETTINGS name with obligatory SETUP XML file entered only if SETUP XML is not present in the installation folder or has a different name TEST installation creates NSE...

Page 80: ...version s of NOD32 that you will be installing on your client s PCs Do not run the installer s Next right click on the installer and choose Extract to or Extract files will depend on the archiving program you use Choose to save the contents to a new folder on your desktop Name the folder NOD32 Install or any special name you wish but for this explanation I ll use NOD32 Install In that folder add t...

Page 81: ...y or any removable media capable of storing this folder which will be around 10MB in size Insert the CD or flash key on the first target PC and double click the NOD32 Install exe This will only take a few seconds and there will be a prompt to reboot When the PC restarts it will start collecting updates from the Mirror on your machine automatically Run the NOD32 Install exe on each machine in your ...

Page 82: ...Administration Installation Guide 82 Additional information ...

Page 83: ...tern Enable disable testing using virus signatures heur Enable disable heuristic analysis scanfile Enable disable scanning of files scanboot Enable disable boot sector scanning scanmbr Enable disable master boot record MBR scanning scanmem Enable disable scanning memory arch Enable disable scanning archives ZIP ARJ and RAR sfx Enable disable scanning self extracting archives pack Enable disable sc...

Page 84: ...n Clean infected objects if applicable prompt Prompt for an action when a virus is detected rename Rename infected files delete Delete infected files quarantine Copy infected file to quarantine before taking further action clean delete Note If the switches prompt rename or delete are used concurrently with the clean switch the corresponding action will be carried out only if the virus cannot be cl...

Reviews: