Connecting McAfee DLP Manager and the ePolicy Orchestrator
server
McAfee DLP Manager and the ePolicy Orchestrator server must be authenticated to each other to
initiate the unified policy installation.
Each product requires information from the other before they can be connected. The database name is
needed from ePolicy Orchestrator, and an epouser account is needed from the McAfee DLP Manager.
Gather ePolicy Orchestrator registration information
You must log on to the ePolicy Orchestrator server
(https://servername:port/core/config)
and
SQL Server Configuration Manager
to get the information needed to register McAfee DLP Manager on McAfee
ePO.
Table 6-1 Sources for ePolicy Orchestrator data
Field or menu item
Where to find data
ePO database IP address or
hostname
Menu
|
Configuration
|
Registered Servers
(local McAfee ePO server)
ePO database password
The SQL password created in
Microsoft SQL Server Management Studio
ePO database port
SQL Server Configuration Manager
|
TCP/IP Properties
|
IP Addresses
|
TCP Ports
ePO database user
The logon name created in
Microsoft SQL Server Management Studio
Unified policy / Incident copy
If incident copy only is selected, no policy updates will be routed to
endpoints through ePolicy Orchestrator
ePO database
Menu
|
Configuration
|
Registered Servers
|
Actions
|
Edit
|
Next
|
Database
instance
ePO database instance
Menu
|
Configuration
|
Registered Servers
|
Actions
|
Edit
|
Next
|
SQL Server
instance
|
instance name
ePO GUI IP address
Address bar of McAfee ePO server
ePO GUI user
User account name used to log on to McAfee ePO server
ePO GUI password
User account password used to log on to McAfee ePO server
ePO GUI port
Address bar of McAfee ePO server
Add an ePolicy Orchestrator database user
You must create an ePolicy Orchestrator database user to set up access to the McAfee DLP Manager
MySQL database.
Before you begin
Register ePolicy Orchestrator on McAfee DLP Manager.
Database access is needed for ePolicy Orchestrator to transfer events and policy updates to and from
McAfee DLP Manager. The epouser is needed because ePolicy Orchestrator servers are Windows
‑
based,
but McAfee DLP Manager is a Linux server that does not support Windows
‑
based authentication of
users. The ePolicy Orchestrator user account is needed to get around that limitation.
This step must be completed before the network extension is installed on ePolicy Orchestrator.
Task
1
Open the
DB User
page in one of two ways:
• In ePolicy Orchestrator, select
Menu
|
Data Loss Prevention
|
DLP Sys Config
|
User Administration
|
DB User
.
6
Integrating McAfee DLP Endpoint into a unified policy system
Connecting McAfee DLP Manager and the ePolicy Orchestrator server
70
McAfee Data Loss Prevention 9.2.1
Installation Guide
Summary of Contents for Data Loss Prevention 9.2.1
Page 78: ...TP000030C00...