
119
ePolicy Orchestrator
®
3.6 Walkthrough Guide
Advanced Feature Evaluations
Rogue System Detection
9
In this section, you will:
1
Configure Rogue System Detection sensor policy
.
2
Deploy the Rogue System Detection sensor
3
Configure an automatic response
.
4
Rogue detection and remediation
.
S
T
E
P
4
Configure Rogue System Detection sensor policy
Before deploying the Rogue System Detection sensor, you should first configure the
sensor policy.
Once the sensor is deployed to a system in your environment, it requires one
agent-to-server communication and one policy enforcement interval before it is
functioning in the environment. The agent-to-server communication installs the sensor
on the system in a disabled state. Then the policy enforcement retrieves policy,
including security certificates. These certificates are needed by the sensor to
communicate to the server directly.
The following configuration changes to the sensor policy speed up this process for this
purpose of this guide.
1
In the console tree, select
Directory
.
2
In the details pane, select the
Policy
tab, then select
Rogue System Sensor 1.0.0
.
3
Click
Edit
at the right end of the
Configuration
row.
4
Select
New Policy
from the
Policy Name
drop-down list. The
Create new policy
dialog box
appears.
5
Provide a
New policy name
for the policy (for example,
Sensor1
), then click
OK
. The
Policy Settings
dialog box appears.
6
On the
General
tab, deselect
Inherit
, then under
Communication Intervals
make the
following changes:
a
Set
Minimum reporting interval for each detected host
to
120
seconds.
b
Set
Minimum sensor-to-server communication interval for primary sensors
to
5
seconds.
7
Click
Apply All
, then click
Close
. The new policy is created.
8
Click
Apply
at the end of the
Configuration
row on the
Assign Policies
page to assign the
new policy to the site selected in the console tree.
Note
These specific configurations to the sensor policy are only for the purpose of the
evaluation. These are not recommended configurations for a production environment
deployment of the sensor.
Содержание ePolicy Orchestrator
Страница 2: ......