McAfee M4050 Troubleshooting Guide - Page 21

Configuring Audit Events, Sensor to Manager

Page 21 highlights

McAfee® Network Security Platform 6.0 Hardening the Manager Server for Windows 2008 Port 80 443 3306 8500 8501 8502 8503 8504 8555 Description HTTP port Communication Client to Manager HTTPS Client to Manager MySQL database Open only while using external SQL database Command channel(UDP) Manager to Sensor Install port(TCP) Sensor to Manager Alert channel(TCP) Sensor to Manager Packet log channel(TCP) Sensor to Manager File transfer channel(TCP) Sensor to Manager Alert viewer(TC) Client to Manager When email notification or SNMP forwarding is configured on Manager and there is firewall between Manager and SNMP Server, ensure that the following ports are allowed through firewall. Port Description Communication 25 SMTP port Manager to SMTP server 162 SNMP forwarding Manager to SNMP server If you have ePO integration configured on Manager, and there is firewall between Manager and the ePO Server, ensure the following port is also allowed through firewall. Port Description Communication 8443 ePO Manager to ePO server communication port Configuring Audit Events Set the following events to be audited:  Audit account logon events  Audit account management  Audit logon events  Audit object access (Failure) 12

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

McAfee® Network Security Platform 6.0
Hardening the Manager Server for Windows 2008
12
Port
Description
Communication
80
HTTP port
Client to Manager
443
HTTPS
Client to Manager
3306
MySQL database
Open only while using external SQL database
8500
Command channel(UDP)
Manager to Sensor
8501
Install port(TCP)
Sensor to Manager
8502
Alert channel(TCP)
Sensor to Manager
8503
Packet log channel(TCP)
Sensor to Manager
8504
File transfer channel(TCP)
Sensor to Manager
8555
Alert viewer(TC)
Client to Manager
When email notification or SNMP forwarding is configured on Manager and there is firewall
between Manager and SNMP Server, ensure that the following ports are allowed through
firewall.
Port
Description
Communication
25
SMTP port
Manager to SMTP server
162
SNMP forwarding
Manager to SNMP server
If you have ePO integration configured on Manager, and there is firewall between Manager
and the ePO Server, ensure the following port is also allowed through firewall.
Port
Description
Communication
8443
ePO
communication port
Manager to ePO server
Configuring Audit Events
Set the following events to be audited:
Audit account logon events
Audit account management
Audit logon events
Audit object access (Failure)