McAfee HISCDE-AB-IA - Host Intrusion Prevention Product Manual page 96

Product guide for use with epolicy orchestrator 4.5
Table of Contents

Advertisement

Working with Host Intrusion Prevention Clients
Overview of the Solaris client
To...
BO
HTTP
Turn off the engine indicated.
Turn on all engines.
Turn off all engines.
TIP:
In addition to using the troubleshooting tool, consult the HIPShield.log and HIPClient.log
files in the
/opt/McAfee/hip/log
Verifying Solaris installation files
After an installation, check that all the files were installed in the appropriate directory on the
client. The /
opt/McAfee/hip
File/Directory Name
HipClient; HipClient-bin
HipClientPolicy.xml
hipts; hipts-bin
*.so
log directory
Installation history is written to
about the installation or removal process of the Host Intrusion Prevention client.
Verifying the Solaris client is running
The client might be installed correctly, but you might encounter problems with its operation. If
the client does not appear in the ePO console, for example, check that it is running, using either
of these commands:
/etc/rc2.d/S99hip status
ps –ef | grep Hip
Stopping the Solaris client
You might need to stop a running client and restart it as part of troubleshooting.
Task
1
To stop a running client, first disable IPS protection. Use one of these procedures:
• Set IPS Options to Off in the ePO console and apply the policy to the client.
• Logged in at root, run the command:
2
Run the command:
Restarting the Solaris client
You might need to stop a running client and restart it as part of troubleshooting.
96
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
Run...
hipts engines <engine name>:off
hipts engines all:on
hipts engines all:off
directory to verify operations or track issues.
directory should contain these essential files and directories:
Description
Solaris client
Policy rules
Troubleshooting tool
Host Intrusion Prevention and McAfee Agent shared object modules
Contains debug and error log files
/opt/McAfee/etc/hip-install.log
hipts engines MISC:off
/sbin/rc2.d/S99hip stop
. Refer to this file for any questions

Advertisement

Table of Contents
loading

This manual is also suitable for:

Host intrusion prevention 8.0

Table of Contents