Solved

McAfee ePo 4.6.6 Export Policies and Audit Settings

Posted on 2013-11-14
5
3,763 Views
Last Modified: 2013-11-18
I start at my company six months ago and took over there ePo 4.6.6 enviroment which wasn't documented.

Here are my questions.
1) Is it possible to run a report to view all active policies and there settings to make sure they meet the companie security requirements.

2) Is it possible to export the policies not McAfee groups into a test enviroment which runs a seperate server?

In a nutshell I am trying to find the best way to audit / view all current policies and a way to keep our test epo enviromen semi in sync policy wise
0
Comment
Question by:compdigit44
  • 2
  • 2
5 Comments
 
LVL 61

Expert Comment

by:gheist
ID: 39650564
1) yes, it is called "Policy Catalog", pick ones that have reference count >0
2) yes, but it does not migrate to new version that way
0
 
LVL 61

Expert Comment

by:btan
ID: 39651034
Also best practices, can catch
- Main section on
a) "Managing endpoint security with policies and packages"
> By default all policies are inherited from the "My Organization" level, the highest point in the System Tree. This means all policies for all products flow downward into the groups and subgroups below it. Always set your policies at the My Organization level and let your policies flow downward. Probably from the "Menu | Policy | Policy Catalog", you can catch more of the overall Agent policy deployed to various assets/groups

b) "Reporting on your managed environment with Queries"
> The Query Builder and Report Builder creates and runs queries and reports that result in user-configured data in user-configured charts and tables. The data for these queries and reports can be obtained from any registered internal or external database in your ePolicy Orchestrator system.
> also on "Creating custom event queries" fro managed systems

http://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/23000/PD23051/en_US/epo_450_best_practices_guide_en-us.pdf.pdf?searchid=1384520006363

also  - Settings for an existing policy are overwritten by an imported policy in ePO 4.x
https://kc.mcafee.com/corporate/index?page=content&id=KB71780&actp=search&viewlocale=en_US&searchid=1384520006363

and for DLP policy - https://kc.mcafee.com/corporate/index?page=content&id=KB60758&actp=search&viewlocale=en_US&searchid=1384520006363

including
- How to migrate ePO from a 32-bit system to a 64-bit system (or to a different installation path)
https://kc.mcafee.com/corporate/index?page=content&id=KB71078
 - How to back up the ePO databases using OSQL commands
https://kc.mcafee.com/corporate/index?page=content&id=KB59562
- How to back up and restore the ePO database using SQL Server Management Studio
https://kc.mcafee.com/corporate/index?page=content&id=KB52126


Another ref worth looking is from commoncriteria portal - see the section 7 on "TOE
Summary Specification", specifically for policy, see "7.3.8 Product Policy Management" and "7.3.11 Benchmark Management"

http://www.commoncriteriaportal.org/files/epfiles/st_vid10484-st.pdf
0
 
LVL 19

Author Comment

by:compdigit44
ID: 39652025
thank you for the replies. I am not the greatest at ePO but learning. I do know wht policy catalog stores all of the policies for ePO. What I am looking for is a way to dump all active policies to a spread sheet or another format so I can view the setting of all policies at once.

i am asking this question because my manager asked me to produce a report for all active polices in ePO and there settings.
0
 
LVL 61

Accepted Solution

by:
btan earned 500 total points
ID: 39652643
0
 
LVL 19

Author Comment

by:compdigit44
ID: 39656775
thanks, it to bad McAfee doesn have a tool that could do this....
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now