McAfee M4050 Troubleshooting Guide - Page 19

Hardening the Manager Server for Windows 2008, Pre-installation

Page 19 highlights

CHAPTER 3 Hardening the Manager Server for Windows 2008 Implementation of Manager varies from environment to environment. The Manager's physical and logical position in the network influences specific remote access and firewall configuration requirements. The following best practices on managing configurable features on Manager impacts the security of Manager. Pre-installation Use a dedicated machine for the Manager server and then install Manager and the embedded MySQL database. Other than the host-based firewall, no other software should be installed on the server. Before installation of Manager do the following:  Ensure that the server is located in a physically secure environment.  Connect the server on a protected or isolated network.  If the hard disk is old, use fdisk (a command line utility) to remove all partitions and create new partitions. Installation Installation of Manager should be performed as follows:  Install the US version of Windows Server 2008.  Use NTFS on all partitions. Post Installation After installation of Manager perform the following installations:  Install the latest Windows Server 2008 patches, service packs, and hot fixes from Microsoft.  Install a Virus Scanner and update the signatures. Note: Exclude "Network Security Manager" and "MySQL" directories from being scanned. Also keep a check on the following:  Minimize the number of Windows roles and features that are installed.  Uninstall applications that are not necessary. 10

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

10
C
HAPTER
3
Hardening the Manager Server for Windows 2008
Implementation of Manager varies from environment to environment.
The Manager's
physical and logical position in the network influences specific remote access and firewall
configuration requirements. The following best practices on managing configurable
features on Manager impacts the security of Manager.
Pre-installation
Use a dedicated machine for the Manager server and then install Manager and the
embedded MySQL database. Other than the host-based firewall, no other software should
be installed on the server. Before installation of Manager do the following:
Ensure that the server is located in a physically secure environment.
Connect the server on a protected or isolated network.
If the hard disk is old, use fdisk (a command line utility) to remove all partitions and
create new partitions.
Installation
Installation of Manager should be performed as follows:
Install the US version of Windows Server 2008.
Use NTFS on all partitions.
Post Installation
After installation of Manager perform the following installations:
Install the latest Windows Server 2008 patches, service packs, and hot fixes from
Microsoft.
Install a Virus Scanner and update the signatures.
Note:
Exclude “Network Security Manager” and “MySQL” directories from being
scanned.
Also keep a check on the following:
Minimize the number of Windows roles and features that are installed.
Uninstall applications that are not necessary.