McAfee EPOCDE-AA-BA Product Guide - Page 271

Rogue System Detection permission sets, Interface settings

Page 271 highlights

Detecting Rogue Systems What are rogue systems 21 • Sensor-to-server communication port. • Server IP address or DNS name. • Whether the Rogue System Sensor is enabled. The server IP address default value is the address of the McAfee ePO server that you are using to install sensors. Rogue System Detection reports system detections to the specified server. When this server detects a system that has an agent deployed by an McAfee ePO server with a different IP address, that system is detected as a rogue because the agent is considered an alien agent. The sensor-to-server communication port server setting can be changed only during installation. Whichever port you have specified during installation must also be specified in the General tab of Rogue System Detection policies. Interface settings Interface settings determine whether sensors: • Do not listen on interfaces whose IP addresses are included in specific networks. • Only listen on an interface if its IP address is included on a network found during installation. • Only listen on interfaces whose IP addresses are included in specific networks. Specifying these settings allows you to choose the networks that the sensor reports on. Rogue System Detection permission sets Permission sets for Rogue System Detection determine what information a user group can view, modify, or create for Rogue System Detection. One or more permission sets can be assigned. By default, permission sets for global administrators are automatically assigned to include full access to all products and features. The permission sets and their available privileges for Rogue System Detection are listed in the following table. Permission set Rights Rogue System Detection • Create and edit Rogue System information; manage sensors. • Create and edit Rogue System information; manage sensors; deploy McAfee Agents and add to System Tree. • No permissions. • View Rogue System information. Rogue System Sensor • No permissions. • View and change settings. • View settings. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 271

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Sensor-to-server communication port.
Server IP address or DNS name.
Whether the Rogue System Sensor is enabled.
The server IP address default value is the address of the McAfee ePO server that you are using to
install sensors. Rogue System Detection reports system detections to the specified server. When this
server detects a system that has an agent deployed by an McAfee ePO server with a different IP
address, that system is detected as a rogue because the agent is considered an alien agent.
The sensor-to-server communication port server setting can be changed
only during installation. Whichever port you have specified during
installation must also be specified in the General tab of Rogue System
Detection policies.
Interface settings
Interface settings determine whether sensors:
Do not listen on interfaces whose IP addresses are included in specific networks.
Only listen on an interface if its IP address is included on a network found during installation.
Only listen on interfaces whose IP addresses are included in specific networks.
Specifying these settings allows you to choose the networks that the sensor reports on.
Rogue System Detection permission sets
Permission sets for Rogue System Detection determine what information a user group can view,
modify, or create for Rogue System Detection. One or more permission sets can be assigned. By
default, permission sets for global administrators are automatically assigned to include full access to
all products and features.
The permission sets and their available privileges for Rogue System Detection are listed in the
following table.
Permission set
Rights
Rogue System Detection
Create and edit Rogue System information; manage sensors.
Create and edit Rogue System information; manage sensors; deploy McAfee
Agents and add to System Tree.
No permissions.
View Rogue System information.
Rogue System Sensor
No permissions.
View and change settings.
View settings.
Detecting Rogue Systems
What are rogue systems
21
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
271