Solved

McAfee / EPO blocking Ghostcast server

Posted on 2009-07-15
9
1,732 Views
Last Modified: 2013-12-09
Hi There,

I am having problems trying to create an image from a machine in ghostcast server.  I know that McAfee 8.7 (Managed by EPO 4)  is blocking the communication, I just dont know how to allow it through.  I have added ghostsrv.exe to the IRC communications exceptions as this was what the log said it was blocking yet I still cannot create an image of the machine I want to.

Could anyone please advise how I might use Epo to ammend the policy on the ghostcast server to allow for communications without having to disable Mcafee on the machine every 1 minute.

Thank you for your help in advance.
0
Comment
Question by:dgi001
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 9

Expert Comment

by:dexIT
ID: 24861762
I had a similar issue creating an image a while back, but it was caused by Windows firewall. Is that off or on?
0
 

Author Comment

by:dgi001
ID: 24867293
The windows firewall is off, with no other firewall software installed.  Just so you know I can trace it to McAfee as when I disbale everything I can locally it works for about a minute before the policy kicks in it re-enables protection.

I am unkeen to ammend the policy on the ghostcast server to allow it to be disabled and would rather find out a possible way to allow the process to run as an exception.

Interestingly enough when deploying images I have to disable the AV locally on the server but it seems to work for much longer and deployent of images can be done (Hopefully if a resolution is found this wont happen)

Thank you
0
 
LVL 2

Expert Comment

by:Robert_IT
ID: 24993719
dgi001

1. Don't recommend imaging a host machine with the McAfee Agent installed because you will duplicate the agent GUID (check McAfee KB for more information on this topic).
https://kc.mcafee.com/corporate/index?page=content&id=KB56086

Simple solution to this issue is to delete the GUID before imaging the master image, since SYSPREP won't catch this item. Now you can safely leave the agent alone.

2. I am going to assume your eliminating the McAfee EPO agent communications, so I will focus on the client side of the logs. Otherwise EPO policy will likely need exclusions created for whatever is being blocked. We can cross that bridge later, but the basic exclusion will be pretty well explained by whatever you find in your local logs.

On the bottom right of your taskbar you should see the McAfee shield, and hopefully it has a somewhat red looking ORB color around it. The RED color only occurs when significant events occur, so now need to proceed to view the local McAfee AV logs by right clicking on the McAfee Shield, and selecting each policy type.

What your looking for is any process that's being blocked. In your case the events are most likely in the Access Protection portion of the logs.

So start by reviewing the AV logs and look for a process being blocked. Once you find it you need to create a local exception.

Symantec also has an article that references what I mentioned as well, see http://service1.symantec.com/SUPPORT/on-technology.nsf/0437f27e11eaa7ef88256ebb0049cfe6/ae79d907756216db8825734e0059c0e1?OpenDocument

My personal view on system images is to keep things as flat as possible. We don't push client software, AV, or anything else that's non-essential into our Vista images.

Let me know if you need any more help.

p.s. For your EPO admin, you might find this post I made on the McAfee forums helpful with other general exclusions.

http://community.mcafee.com/showthread.php?t=229802
0
 
LVL 2

Expert Comment

by:Robert_IT
ID: 24993740
Keep in mind you really need to eliminate the EPO client server communications, otherwise your server policy will override any local policy changes, which is why I don't recommend the agent being installed. Keep it if you like, but eliminated the GUID and remove it from the EPO console, so the server does not talk to the host.

If you have syncronization turned on your EPO server might also start taking automatic control as well, but this all depends on your EPO server policy settings. The policy takes a top down approach, so keep in mind this will be a factor.

Bottom line, recommend you eliminate the client server communications, delete the computer object from EPO, delete the GUID, and then create your localized exclusions.

Have fun!
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 7

Accepted Solution

by:
enzogoy earned 125 total points
ID: 25010176
Actually you do not want to deactivate it - all you have to do is set an exclusion for Ghostsvr.exe. To do this open the VirusScan Console and double-click on Access Protection to open Access Protection Properties.  Select the Port Blocking tab and Edit the Prevent IRC communications on Port 6666 - 6669t. In the Excluded Proccess field, type Ghostsvr.exe and click OK. Do this for both rules - one being for the Inbound direction and the other being for the outbound direction.  As soon as I did this, it worked perfectly.
0
 

Author Comment

by:dgi001
ID: 25011712
Thank you for your comments above, I ill go through them as soon as possible and post back :)
0
 

Author Closing Comment

by:dgi001
ID: 31603818
Thank you very much for your help
0
 
LVL 2

Expert Comment

by:Robert_IT
ID: 25272200
WOW, the other guy gets the points and I already provided the same answer, what gives here?

Check the link to Symantec that I provided. All he did was repeat what was offered in the URL I researched and provided.

FOUL!
0
 
LVL 7

Expert Comment

by:enzogoy
ID: 25272421
Calm down.  I'll give the point back to you.  Not really a big deal coz all we want to do here is to offer our help.

Now any admin around.  Could you please transfer the point I got for this question to Robert_IT.

By the way, I didn't get the answer from your link.  I actualy ask the same question a few years ago.
:)
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Some site administrators might be considering how to filter incoming traffic to a site by identifying the domains or networks of the traffic source, in the same way that a spam filter does on an email server, such as blocking all emails sent from th…
By the time you finish reading this article, you may have already lost all your money because you don't know the simple steps to securing your BitCoin wallet. BitCoin is an incredible invention. It is a decentralized currency system, which is the…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now