McAfee M4050 Troubleshooting Guide - Page 15

Hardening the Manager Server for Windows 2003, Introduction, Install a desktop firewall

Page 15 highlights

CHAPTER 2 Hardening the Manager Server for Windows 2003 This section describes methods for hardening your McAfee® Network Security Manager (Manager) server. Introduction Manager implementation varies between environments. The Manager server's positioning in the network, both physically and logically, may influence specific remote access and firewall configuration requirements. The following best practices are intended to cover the configurable features that can impact the security of Manager. This information should be used in combination with the McAfee® Network Security Platform Release Notes and the rest of the documentation set. McAfee's recommendations, at a high level:  Install a desktop firewall on the server and open the proper ports  Harden the MySQL installation  Harden the Manager host Install a desktop firewall It is recommended that you operate a desktop firewall on the Manager server. Certain ports are used within the McAfee Network Security Platform. Some of these required for Manager--McAfee® Network Security Sensor (Sensor) and Manager client-server communication. All remaining unnecessary ports should be closed. The ports used by Network Security Platform are listed in Install a desktop firewall (on page 2). Harden the MySQL installation Ensure the cmd window used for making changes to database tables in the "mysql" database stays opened in the mysql shell until validation is completed. This is necessary to enable you to rollback the changes in case you need to. Rollback procedures are shown at the end of this section. Use another cmd window, where necessary, to validate hardening changes you have made. 6

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

6
C
HAPTER
2
Hardening the Manager Server for Windows 2003
This section describes methods for hardening your McAfee
®
Network Security Manager
(Manager) server.
Introduction
Manager implementation varies between environments. The Manager server’s positioning
in the network, both physically and logically, may influence specific remote access and
firewall configuration requirements.
The following best practices are intended to cover the configurable features that can
impact the security of Manager. This information should be used in combination with the
McAfee
®
Network Security Platform Release Notes and the rest of the documentation set.
McAfee’s recommendations, at a high level:
Install a desktop firewall on the server and open the proper ports
Harden the MySQL installation
Harden the Manager host
Install a desktop firewall
It is recommended that you operate a desktop firewall on the Manager server. Certain
ports are used within the McAfee Network Security Platform. Some of these required for
Manager--McAfee
®
Network Security Sensor (Sensor) and Manager client-server
communication. All remaining unnecessary ports should be closed. The ports used by
Network Security Platform are listed in Install a desktop firewall (on page
2
).
Harden the MySQL installation
Ensure the cmd window used for making changes to database tables in the “mysql”
database stays opened in the mysql shell until validation is completed.
This is necessary to enable you to rollback the changes in case you need to. Rollback
procedures are shown at the end of this section.
Use another cmd window, where necessary, to validate hardening changes you have
made.