Solved

McAfee / EPO blocking Ghostcast server

Posted on 2009-07-15
9
1,747 Views
Last Modified: 2013-12-09
Hi There,

I am having problems trying to create an image from a machine in ghostcast server.  I know that McAfee 8.7 (Managed by EPO 4)  is blocking the communication, I just dont know how to allow it through.  I have added ghostsrv.exe to the IRC communications exceptions as this was what the log said it was blocking yet I still cannot create an image of the machine I want to.

Could anyone please advise how I might use Epo to ammend the policy on the ghostcast server to allow for communications without having to disable Mcafee on the machine every 1 minute.

Thank you for your help in advance.
0
Comment
Question by:dgi001
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 9

Expert Comment

by:dexIT
ID: 24861762
I had a similar issue creating an image a while back, but it was caused by Windows firewall. Is that off or on?
0
 

Author Comment

by:dgi001
ID: 24867293
The windows firewall is off, with no other firewall software installed.  Just so you know I can trace it to McAfee as when I disbale everything I can locally it works for about a minute before the policy kicks in it re-enables protection.

I am unkeen to ammend the policy on the ghostcast server to allow it to be disabled and would rather find out a possible way to allow the process to run as an exception.

Interestingly enough when deploying images I have to disable the AV locally on the server but it seems to work for much longer and deployent of images can be done (Hopefully if a resolution is found this wont happen)

Thank you
0
 
LVL 2

Expert Comment

by:Robert_IT
ID: 24993719
dgi001

1. Don't recommend imaging a host machine with the McAfee Agent installed because you will duplicate the agent GUID (check McAfee KB for more information on this topic).
https://kc.mcafee.com/corporate/index?page=content&id=KB56086

Simple solution to this issue is to delete the GUID before imaging the master image, since SYSPREP won't catch this item. Now you can safely leave the agent alone.

2. I am going to assume your eliminating the McAfee EPO agent communications, so I will focus on the client side of the logs. Otherwise EPO policy will likely need exclusions created for whatever is being blocked. We can cross that bridge later, but the basic exclusion will be pretty well explained by whatever you find in your local logs.

On the bottom right of your taskbar you should see the McAfee shield, and hopefully it has a somewhat red looking ORB color around it. The RED color only occurs when significant events occur, so now need to proceed to view the local McAfee AV logs by right clicking on the McAfee Shield, and selecting each policy type.

What your looking for is any process that's being blocked. In your case the events are most likely in the Access Protection portion of the logs.

So start by reviewing the AV logs and look for a process being blocked. Once you find it you need to create a local exception.

Symantec also has an article that references what I mentioned as well, see http://service1.symantec.com/SUPPORT/on-technology.nsf/0437f27e11eaa7ef88256ebb0049cfe6/ae79d907756216db8825734e0059c0e1?OpenDocument

My personal view on system images is to keep things as flat as possible. We don't push client software, AV, or anything else that's non-essential into our Vista images.

Let me know if you need any more help.

p.s. For your EPO admin, you might find this post I made on the McAfee forums helpful with other general exclusions.

http://community.mcafee.com/showthread.php?t=229802
0
Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

 
LVL 2

Expert Comment

by:Robert_IT
ID: 24993740
Keep in mind you really need to eliminate the EPO client server communications, otherwise your server policy will override any local policy changes, which is why I don't recommend the agent being installed. Keep it if you like, but eliminated the GUID and remove it from the EPO console, so the server does not talk to the host.

If you have syncronization turned on your EPO server might also start taking automatic control as well, but this all depends on your EPO server policy settings. The policy takes a top down approach, so keep in mind this will be a factor.

Bottom line, recommend you eliminate the client server communications, delete the computer object from EPO, delete the GUID, and then create your localized exclusions.

Have fun!
0
 
LVL 7

Accepted Solution

by:
enzogoy earned 125 total points
ID: 25010176
Actually you do not want to deactivate it - all you have to do is set an exclusion for Ghostsvr.exe. To do this open the VirusScan Console and double-click on Access Protection to open Access Protection Properties.  Select the Port Blocking tab and Edit the Prevent IRC communications on Port 6666 - 6669t. In the Excluded Proccess field, type Ghostsvr.exe and click OK. Do this for both rules - one being for the Inbound direction and the other being for the outbound direction.  As soon as I did this, it worked perfectly.
0
 

Author Comment

by:dgi001
ID: 25011712
Thank you for your comments above, I ill go through them as soon as possible and post back :)
0
 

Author Closing Comment

by:dgi001
ID: 31603818
Thank you very much for your help
0
 
LVL 2

Expert Comment

by:Robert_IT
ID: 25272200
WOW, the other guy gets the points and I already provided the same answer, what gives here?

Check the link to Symantec that I provided. All he did was repeat what was offered in the URL I researched and provided.

FOUL!
0
 
LVL 7

Expert Comment

by:enzogoy
ID: 25272421
Calm down.  I'll give the point back to you.  Not really a big deal coz all we want to do here is to offer our help.

Now any admin around.  Could you please transfer the point I got for this question to Robert_IT.

By the way, I didn't get the answer from your link.  I actualy ask the same question a few years ago.
:)
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

OVERVIEW This guide provides information on the process performed when the Symantec Endpoint Protection (SEP) client checks in with the Symantec Endpoint Protection Manager (SEPM). AUDIENCE Information Technology personnel responsible for suppo…
I recently had to create a utility which aim is to update McAfee's Virusscan and that had to be launched from a command line. I thought I’d share my experience with you. Why is it useful to be able to update an Antivirus from the command line?…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question