McAfee HISCDE-AB-IA Product Guide - Page 99

Verifying Linux installation files, Verifying the Linux client is running, Stopping the Linux client

Page 99 highlights

Working with Host Intrusion Prevention Clients Overview of the Linux client To... Turn off the engine indicated. Turn on all engines. Turn off all engines. Run... hipts engines :off hipts engines all:on hipts engines all:off TIP: In addition to using the troubleshooting tool, consult the HIPShield.log and HIPClient.log files in the McAfee/hip/log directory to verify operations or track issues. Verifying Linux installation files After an installation, check to see that all the files were installed in the appropriate directory on the client. The opt/McAfee/hip directory should contain these essential files and directories: File Name HipClient; HipClient-bin HipClientPolicy.xml hipts; hipts-bin *.so log directory Description Linux client Policy rules Troubleshooting tool Host Intrusion Prevention and McAfee Agent shared object modules Contains debug and error log files Installation history is written to /opt/McAfee/etc/hip-install.log. Refer to this file for any questions about the installation or removal process of the Host Intrusion Prevention client. Verifying the Linux client is running If the client does not appear in the ePO console, for example, check that the client is running. To do this, run this command: ps -ef | grep Hip Stopping the Linux client You might need to stop a running client and restart it as part of troubleshooting. Task 1 To stop a client, disable IPS protection. Use one of these procedures: • Set IPS Options to Off in the ePO console and apply the policy to the client. • Run the command: hipts engines MISC:off 2 Run the command: hipts agent off Restarting the Linux client You might need to stop a running client and restart it as part of troubleshooting. Task 1 Run the command: hipts agent on. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 99

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Run...
To...
hipts engines <engine name>:off
Turn off the engine indicated.
hipts engines all:on
Turn on all engines.
hipts engines all:off
Turn off all engines.
TIP:
In addition to using the troubleshooting tool, consult the HIPShield.log and HIPClient.log
files in the McAfee/hip/log directory to verify operations or track issues.
Verifying Linux installation files
After an installation, check to see that all the files were installed in the appropriate directory
on the client. The
opt/McAfee/hip
directory should contain these essential files and directories:
Description
File Name
Linux client
HipClient; HipClient-bin
Policy rules
HipClientPolicy.xml
Troubleshooting tool
hipts; hipts-bin
Host Intrusion Prevention and McAfee Agent shared object modules
*.so
Contains debug and error log files
log directory
Installation history is written to
/opt/McAfee/etc/hip-install.log
. Refer to this file for any questions
about the installation or removal process of the Host Intrusion Prevention client.
Verifying the Linux client is running
If the client does not appear in the ePO console, for example, check that the client is running.
To do this, run this command:
ps –ef | grep Hip
Stopping the Linux client
You might need to stop a running client and restart it as part of troubleshooting.
Task
1
To stop a client, disable IPS protection. Use one of these procedures:
Set
IPS Options
to
Off
in the ePO console and apply the policy to the client.
Run the command:
hipts engines MISC:off
2
Run the command:
hipts agent off
Restarting the Linux client
You might need to stop a running client and restart it as part of troubleshooting.
Task
1
Run the command:
hipts agent on.
Working with Host Intrusion Prevention Clients
Overview of the Linux client
99
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5