McAfee HISCDE-AB-IA Product Guide - Page 145

Stopping Host IPS services, Command-line syntax

Page 145 highlights

Appendix B - Troubleshooting Clientcontrol.exe utility The utility records its activities to ClientControl.log at: C:\Documents and Settings\All Users\Application Data\McAfee\Host Intrusion Prevention; or C:\ProgramData\McAfee\Host Intrusion Prevention on Windows Vista, Windows 2008, and Windows 7. To enable logging, modify HKLM\Software\McAfee\HIP in the registry by adding the DWORD type FwLogLevel entry with a value of 0x7. Stopping Host IPS services The /stop parameter stops Host IPS services if the user has administrative authority to stop services. If the user has authority to stop services on the computer, the following occurs: • Host IPS services are turned off. The Host IPS checkbox on the IPS Policy tab is automatically deselected. • Host IPS services are not stopped. An entry is made in ClientControl.log. • The McAfee Agent enforces policies at next policy enforcement interval. • If the McAfee Agent enforces policies while you are engaged in an activity that requires that protection be disabled (e.g. patching Windows), your activity might be blocked by the enforced policies. Even if stopping Host IPS services is successful, policy settings might allow the McAfee Agent to restart them at the next Agent-Server Communication Interval (ASCI). To prevent this: 1 In ePolicy Orchestrator, open the Host Intrusion Prevention: General policy. 2 Select the Advanced tab. 3 Deselect Perform product integrity check. 4 Run an agent wake-up call. Command-line syntax Conventions: • [ ] means required. • [xxx, ...] means one or more. • < > means user-entered data. Major arguments: Only one of the following major arguments is allowed per invocation: • /help • /start • /stop • /log • /engine • /export However, you can specify more than one log option when changing log settings. Running the utility with the /help command provides the most up-to-date help information and notes. Usage: clientcontrol [arg] Argument definitions: • /help McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 145

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

The utility records its activities to
ClientControl.log
at: C:\Documents and Settings\All
Users\Application Data\McAfee\Host Intrusion Prevention; or C:\ProgramData\McAfee\Host
Intrusion Prevention on Windows Vista, Windows 2008, and Windows 7.
To enable logging, modify HKLM\Software\McAfee\HIP in the registry by adding the DWORD
type FwLogLevel entry with a value of 0x7.
Stopping Host IPS services
The
/stop
parameter stops Host IPS services if the user has administrative authority to stop
services. If the user has authority to stop services on the computer, the following occurs:
Host IPS services are turned off. The
Host IPS checkbox on the IPS Policy tab is
automatically deselected.
Host IPS services are not stopped. An entry is made in ClientControl.log.
The McAfee Agent enforces policies at next policy enforcement interval.
If the McAfee Agent enforces policies while you are engaged in an activity that requires that
protection be disabled (e.g. patching Windows), your activity might be blocked by the
enforced policies.
Even if stopping Host IPS services is successful, policy settings might allow the McAfee Agent
to restart them at the next Agent-Server Communication Interval (ASCI). To prevent this:
1
In ePolicy Orchestrator, open the Host Intrusion Prevention: General policy.
2
Select the
Advanced
tab.
3
Deselect
Perform product integrity check
.
4
Run an agent wake-up call.
Command-line syntax
Conventions:
[ ] means
required
.
[xxx, ...] means
one or more
.
< > means
user-entered data
.
Major arguments:
Only one of the following
major
arguments is allowed per invocation:
/help
/start
/stop
/log
/engine
/export
However, you can specify more than one log option when changing log settings.
Running the utility with the /help command provides the most up-to-date help information and
notes.
Usage:
clientcontrol [arg]
Argument definitions:
/help
Appendix B — Troubleshooting
Clientcontrol.exe utility
145
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5