McAfee EPOCDE-AA-BA Product Guide - Page 16

Components and what they

Page 16 highlights

1 Introducing McAfee ePolicy Orchestrator Software version 4.6.0 Components and what they do Components and what they do The ePolicy Orchestrator software is comprised of these components. • McAfee ePO server - The center of your managed environment. The server delivers security policies and tasks, controls updates, and processes events for all managed systems. The ePolicy Orchestrator server includes these subcomponents: • Apache server - Along with the event parser, this component is responsible for communicating with the McAfee Agent. Together, these two components receive updated events and properties from agents, and send updated policies and tasks. • Application server - This component hosts the user interface and server task scheduler. • Event parser - This component works in conjunction with the apache server to communicate events and properties from the agent to the server, and send policies and tasks from the server to the agent. • Database - The central storage component for all data created and used by ePolicy Orchestrator. You can choose whether to house the database on your McAfee ePO server or on a separate system, depending on the specific needs of your organization. • McAfee Agent - A vehicle of information and enforcement between the ePolicy Orchestrator server and each managed system. The agent retrieves updates, ensures task implementation, enforces policies, and forwards events for each managed system. It uses a separate secure data channel to transfer data to the server. A McAfee Agent can also be configured as a SuperAgent. • Master repository - The central location for all McAfee updates and signatures, residing on the ePolicy Orchestrator server. Master repository retrieves user-specified updates and signatures from McAfee or from user-defined source sites. • Distributed repositories - Local access points strategically placed throughout your environment for agents to receive signatures, product updates, and product installations with minimal bandwidth impact. Depending on how your network is configured, you can set up SuperAgent, HTTP, FTP, or UNC share distributed repositories. • Remote Agent Handlers - A server that you can install in various network locations to help manage agent communication, load balancing, and product updates. Remote Agent Handlers are comprised of an apache server and an event parser. They can help you manage the needs of large or complex network infrastructures by allowing you more control over agent-server communication. • Registered servers - Used to register other servers with your ePolicy Orchestrator server. Registered server types include: • LDAP server - Used for Policy Assignment Rules and to enable automatic user account creation. • SNMP server - Used to receive an SNMP trap. You must add the SNMP server's information so that ePolicy Orchestrator knows where to send the trap. • Database server - Used to extend the advanced reporting tools provided with ePolicy Orchestrator software. • Ticketing server - Before tickets can be associated with issues, you must have a registered ticketing server configured. The system running the ticketing extension must be able to resolve the address of the Service Desk system. Depending on the needs of your organization and the complexity of your network, you might only need to use some of these components. 16 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Components and what they do
The ePolicy Orchestrator software is comprised of these components.
McAfee ePO server — The center of your managed environment. The server delivers security
policies and tasks, controls updates, and processes events for all managed systems. The ePolicy
Orchestrator server includes these subcomponents:
Apache server — Along with the event parser, this component is responsible for communicating
with the McAfee Agent. Together, these two components receive updated events and properties
from agents, and send updated policies and tasks.
Application server — This component hosts the user interface and server task scheduler.
Event parser — This component works in conjunction with the apache server to communicate
events and properties from the agent to the server, and send policies and tasks from the server
to the agent.
Database — The central storage component for all data created and used by ePolicy Orchestrator.
You can choose whether to house the database on your McAfee ePO server or on a separate
system, depending on the specific needs of your organization.
McAfee Agent — A vehicle of information and enforcement between the ePolicy Orchestrator server
and each managed system. The agent retrieves updates, ensures task implementation, enforces
policies, and forwards events for each managed system. It uses a separate secure data channel to
transfer data to the server. A McAfee Agent can also be configured as a SuperAgent.
Master repository — The central location for all McAfee updates and signatures, residing on the
ePolicy Orchestrator server. Master repository retrieves user-specified updates and signatures from
McAfee or from user-defined source sites.
Distributed repositories — Local access points strategically placed throughout your environment for
agents to receive signatures, product updates, and product installations with minimal bandwidth
impact. Depending on how your network is configured, you can set up SuperAgent, HTTP, FTP, or
UNC share distributed repositories.
Remote Agent Handlers — A server that you can install in various network locations to help
manage agent communication, load balancing, and product updates. Remote Agent Handlers are
comprised of an apache server and an event parser. They can help you manage the needs of large
or complex network infrastructures by allowing you more control over agent-server communication.
Registered servers — Used to register other servers with your ePolicy Orchestrator server.
Registered server types include:
LDAP server — Used for Policy Assignment Rules and to enable automatic user account creation.
SNMP server — Used to receive an SNMP trap. You must add the SNMP server’s information so
that ePolicy Orchestrator knows where to send the trap.
Database server — Used to extend the advanced reporting tools provided with ePolicy
Orchestrator software.
Ticketing server — Before tickets can be associated with issues, you must have a registered
ticketing server configured. The system running the ticketing extension must be able to resolve
the address of the Service Desk system.
Depending on the needs of your organization and the complexity of your
network, you might only need to use some of these components.
1
Introducing McAfee ePolicy Orchestrator Software version 4.6.0
Components and what they do
16
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide