© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Configuring Groups and Policies Building an Agent Kit
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Objectives At the end of this lesson, you will be able to meet these objectives: Identify the purpose of using an Agent kit Describe how to build an Agent kit Identify the purpose of using scripts for installing and uninstalling Windows CSAs Describe how to control registration of hosts to CSA MC
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Agent Kits CSA MC allows the creation of custom Agent installation kits to reduce the administrative burden required to deploy Agents on new systems. Upon creation, new Agent kits are associated with one or more groups.
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Building an Agent Kit
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Building an Agent Kit (Cont.)
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Building an Agent Kit (Cont.)
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Building an Agent Kit (Cont.)
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Building an Agent Kit (Cont.)
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Agent Kit Status When you create an Agent kit, it is given one of four status levels: Ready Needs Rule Generation Incomplete Undeployable
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Agent Reboot vs. No Reboot Operating System CSA Features Not Available Until System Reboot WindowsNetwork shield rules are not applied. Buffer overflow protection is enforced for new processes only. COM component access control rules are enforced for new processes only. Data access control rules are not applied until the web service is restarted. Solaris and Linux Buffer overflow protection is enforced for new processes only. Network access control rules are applied to new socket connections only. File access control rules are applied to new files only.
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v You can use scripts to perform the following functions on Windows Agent kits: Scripted install Scripted uninstall Scripted Agent Installs and Uninstalls
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Controlling Host Registration
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v Summary Agent kits reduce the administrative burden of deploying Cisco Security Systems on new systems. Agent kits are given status levels that indicate the progress of the Agent kit configuration. If a system is not rebooted after CSA installation, certain functionalities will not be available. Scripts can be used to silently install and uninstall Windows CSAs on end user systems.
© 2006 Cisco Systems, Inc. All rights reserved. HIPS v