McAfee / EPO blocking Ghostcast server

Hi There,

I am having problems trying to create an image from a machine in ghostcast server.  I know that McAfee 8.7 (Managed by EPO 4)  is blocking the communication, I just dont know how to allow it through.  I have added ghostsrv.exe to the IRC communications exceptions as this was what the log said it was blocking yet I still cannot create an image of the machine I want to.

Could anyone please advise how I might use Epo to ammend the policy on the ghostcast server to allow for communications without having to disable Mcafee on the machine every 1 minute.

Thank you for your help in advance.
dgi001Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

dexITCommented:
I had a similar issue creating an image a while back, but it was caused by Windows firewall. Is that off or on?
0
dgi001Author Commented:
The windows firewall is off, with no other firewall software installed.  Just so you know I can trace it to McAfee as when I disbale everything I can locally it works for about a minute before the policy kicks in it re-enables protection.

I am unkeen to ammend the policy on the ghostcast server to allow it to be disabled and would rather find out a possible way to allow the process to run as an exception.

Interestingly enough when deploying images I have to disable the AV locally on the server but it seems to work for much longer and deployent of images can be done (Hopefully if a resolution is found this wont happen)

Thank you
0
Robert_ITCommented:
dgi001

1. Don't recommend imaging a host machine with the McAfee Agent installed because you will duplicate the agent GUID (check McAfee KB for more information on this topic).
https://kc.mcafee.com/corporate/index?page=content&id=KB56086

Simple solution to this issue is to delete the GUID before imaging the master image, since SYSPREP won't catch this item. Now you can safely leave the agent alone.

2. I am going to assume your eliminating the McAfee EPO agent communications, so I will focus on the client side of the logs. Otherwise EPO policy will likely need exclusions created for whatever is being blocked. We can cross that bridge later, but the basic exclusion will be pretty well explained by whatever you find in your local logs.

On the bottom right of your taskbar you should see the McAfee shield, and hopefully it has a somewhat red looking ORB color around it. The RED color only occurs when significant events occur, so now need to proceed to view the local McAfee AV logs by right clicking on the McAfee Shield, and selecting each policy type.

What your looking for is any process that's being blocked. In your case the events are most likely in the Access Protection portion of the logs.

So start by reviewing the AV logs and look for a process being blocked. Once you find it you need to create a local exception.

Symantec also has an article that references what I mentioned as well, see http://service1.symantec.com/SUPPORT/on-technology.nsf/0437f27e11eaa7ef88256ebb0049cfe6/ae79d907756216db8825734e0059c0e1?OpenDocument

My personal view on system images is to keep things as flat as possible. We don't push client software, AV, or anything else that's non-essential into our Vista images.

Let me know if you need any more help.

p.s. For your EPO admin, you might find this post I made on the McAfee forums helpful with other general exclusions.

http://community.mcafee.com/showthread.php?t=229802
0
Top Threats of Q1 & How to Defend Against Them

WEBINAR: Join WatchGuard CTO and our Threat Research Team on Aug. 2nd to hear the findings from our Q1 Internet Security Report! Learn more about the top threats detected in the first quarter and how you can defend your business against them!

Robert_ITCommented:
Keep in mind you really need to eliminate the EPO client server communications, otherwise your server policy will override any local policy changes, which is why I don't recommend the agent being installed. Keep it if you like, but eliminated the GUID and remove it from the EPO console, so the server does not talk to the host.

If you have syncronization turned on your EPO server might also start taking automatic control as well, but this all depends on your EPO server policy settings. The policy takes a top down approach, so keep in mind this will be a factor.

Bottom line, recommend you eliminate the client server communications, delete the computer object from EPO, delete the GUID, and then create your localized exclusions.

Have fun!
0
enzogoyCommented:
Actually you do not want to deactivate it - all you have to do is set an exclusion for Ghostsvr.exe. To do this open the VirusScan Console and double-click on Access Protection to open Access Protection Properties.  Select the Port Blocking tab and Edit the Prevent IRC communications on Port 6666 - 6669t. In the Excluded Proccess field, type Ghostsvr.exe and click OK. Do this for both rules - one being for the Inbound direction and the other being for the outbound direction.  As soon as I did this, it worked perfectly.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
dgi001Author Commented:
Thank you for your comments above, I ill go through them as soon as possible and post back :)
0
dgi001Author Commented:
Thank you very much for your help
0
Robert_ITCommented:
WOW, the other guy gets the points and I already provided the same answer, what gives here?

Check the link to Symantec that I provided. All he did was repeat what was offered in the URL I researched and provided.

FOUL!
0
enzogoyCommented:
Calm down.  I'll give the point back to you.  Not really a big deal coz all we want to do here is to offer our help.

Now any admin around.  Could you please transfer the point I got for this question to Robert_IT.

By the way, I didn't get the answer from your link.  I actualy ask the same question a few years ago.
:)
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Anti-Virus Apps

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.