McAfee M4050 Troubleshooting Guide - Page 20

Disabling non-required Services, Setting System Policies, Setting a Desktop Firewall

Page 20 highlights

McAfee® Network Security Platform 6.0 Hardening the Manager Server for Windows 2008 Disabling non-required Services Disable the following services.  DHCP Client  FTP  Print spooler  Remote access auto connection manager  Remote procedure call locator  Remote registry  Server  TCP/IP NetBIOS helper service  Telephony service. Note: Enable these services only if it is absolutely required. Setting System Policies Ensure to set the following system policies:  Implement the System key and strong encryption of the password database by running SYSKEY.EXE  Use Microsoft security compliance toolkit or set local security policy  Display legal notice at during interactive logon window.  Do not display username that was earlier used to login.  Disable Posix  Clear virtual memory page file during shutdown  Disable autorun  Disable LMHOSTS lookup while setting the advanced TCP/IP settings. Setting User Policies Ensure to set the following user policies:  Rename the administrator account.  Disable guest account .  Passwords should be at least 8 ASCII characters.  Enable locking of screensaver. Setting a Desktop Firewall It is recommended that a desktop firewall operates on the Manager server. The following ports are required for Manager-Sensor communication. Note: Ensure that there are no other open ports using a scanning tool such as Vulnerability Manager. 11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

McAfee® Network Security Platform 6.0
Hardening the Manager Server for Windows 2008
11
Disabling non-required Services
Disable the following services.
DHCP Client
FTP
Print spooler
Remote access auto connection manager
Remote procedure call locator
Remote registry
Server
TCP/IP NetBIOS helper service
Telephony service.
Note:
Enable these services only if it is absolutely required.
Setting System Policies
Ensure to set the following system policies:
Implement the System key and strong encryption of the password database by
running SYSKEY.EXE
Use Microsoft security compliance toolkit or set local security policy
Display legal notice at during interactive logon window.
Do not display username that was earlier used to login.
Disable Posix
Clear virtual memory page file during shutdown
Disable autorun
Disable LMHOSTS lookup while setting the advanced TCP/IP settings.
Setting User Policies
Ensure to set the following user policies:
Rename the administrator account.
Disable guest account .
Passwords should be at least 8 ASCII characters.
Enable locking of screensaver.
Setting a Desktop Firewall
It is recommended that a desktop firewall operates on the Manager server. The following
ports are required for Manager-Sensor communication.
Note:
Ensure that there are no other open ports using a scanning tool such as
Vulnerability Manager.