McAfee HISCDE-AB-IA Product Guide - Page 95

Troubleshooting the Solaris client

Page 95 highlights

Working with Host Intrusion Prevention Clients Overview of the Solaris client Policy Trusted Applications Host Intrusion Prevention 8.0 Firewall Available options Only Mark as trusted for IPS and New Process Name to add trusted applications. None Troubleshooting the Solaris client If a problem was caused while installing or uninstalling the client, there are several things to investigate. These can include ensuring that all required files were installed in the correct directory, uninstalling and then reinstalling the client, and checking process logs. In addition, you might encounter problems with the operation of the client. You can check whether the client is running, and stop and restart the client. The Solaris client has no user interface to troubleshoot operation issues. It does offer a command-line troubleshooting tool, hipts, located in the /opt/McAfee/hip directory. To use this tool, you must provide a Host Intrusion Prevention client password. Use the default password that ships with the client (abcde12345), or send a Client UI policy to the client with either an administrator's password or a time-based password set with the policy, and use this password. Use the troubleshooting tool to: • Indicate the logging settings and engine status for the client. • Turn message logging on and off. • Turn engines on and off. Log on as root and run the following commands to aid in troubleshooting: To... Run... Obtain the current status of the client indicating which hipts status type of logging is enabled, and which engines are running. Turn on logging of specific messages types. hipts logging on Turn off logging of all message types. Logging is off by hipts logging off default. Display the message type indicated when logging is set to hipts message :on "on." Messages include: • error • warning • debug • info • violations Hide the message type indicated when logging is set to hipts message :off "on." Message error is off by default. Display all message types when logging is set to "on." hipts message all:on Hide all message types when logging is set to "on." hipts message all:off Turn on the engine indicated. Engine is on by default. Engines include: • MISC • FILES • GUID • MMAP hipts engines :on McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 95

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Available options
Policy
Only Mark as trusted for IPS and New Process Name to
add trusted applications.
Trusted Applications
None
Host Intrusion Prevention 8.0 Firewall
Troubleshooting the Solaris client
If a problem was caused while installing or uninstalling the client, there are several things to
investigate. These can include ensuring that all required files were installed in the correct
directory, uninstalling and then reinstalling the client, and checking process logs. In addition,
you might encounter problems with the operation of the client. You can check whether the
client is running, and stop and restart the client.
The Solaris client has no user interface to troubleshoot operation issues. It does offer a
command-line troubleshooting tool,
hipts,
located in the /
opt/McAfee/hip
directory. To use this
tool, you must provide a Host Intrusion Prevention client password. Use the default password
that ships with the client (abcde12345), or send a Client UI policy to the client with either an
administrator’s password or a time-based password set with the policy, and use this password.
Use the troubleshooting tool to:
Indicate the logging settings and engine status for the client.
Turn message logging on and off.
Turn engines on and off.
Log on as root and run the following commands to aid in troubleshooting:
Run...
To...
hipts status
Obtain the current status of the client indicating which
type of logging is enabled, and which engines are running.
hipts logging on
Turn on logging of specific messages types.
hipts logging off
Turn off logging of all message types. Logging is off by
default.
hipts message <message name>:on
Display the message type indicated when logging is set to
“on.” Messages include:
error
warning
debug
info
violations
hipts message <message name>:off
Hide the message type indicated when logging is set to
“on.” Message error is off by default.
hipts message all:on
Display all message types when logging is set to “on.”
hipts message all:off
Hide all message types when logging is set to “on.”
hipts engines <engine name>:on
Turn on the engine indicated. Engine is on by default.
Engines include:
MISC
FILES
GUID
MMAP
Working with Host Intrusion Prevention Clients
Overview of the Solaris client
95
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5