Does the groupshield use an engine earlier than 4320? If so, the engine must be upgraded for it to accept the new dats (size of dat hit critical mass for early engine).
"There is no patch for stupidity
I'm on separate boxes with 40k clients. If done again, I would separate the two if I had the budget but it does work well. An advantage of separation is to separate the load of the SQL and master from each other and if one goes down it won't affect the other...easier to recover.
"There is no...
You may want to try to add the process(s) to low risk process settings within the VS8.0i policies. If you do, please post if it works (or how well) as I will be testing this within the next couple months as my environment has many groups with custom exception directory/file lists that I would...
By hand as far as I have been aware. Not only that you cannot copy from one ODS task to another that I am aware of. If you find a way to do either please post :-)
"There is no patch for stupidity
Some responses to some of CCIS's comments...
Forensics teams are extremely expensive. Most large companies will cringe when even thinking of the price tag of a team of highly paid individuals showing up. Knowing what you have available is just good business practice. Auditing is crucial such...
In the future if this still occurs...
Have a firewall rule to alert if going to one of the hotmail sites.
If you think you may have the culprit seize the machine, make a copy of the drive, and check out the contents.
Like the above people have said...check the headers for clues.
Hotmail...
Could you set a small script to run after update has completed then remove it after the next update? I've never used it but should be easy to do...assuming it works :-) Just a thought...
I run the report that may be found by doing the following...
Reports --> Coverage --> Product Updates by Custom Event Groups --> Enter Value = Repository Activity
You now will receive info for total activity which may be pretty useless. So...go to the "Within" tab and set "Enter Value" =...
40k+ clients 8 repos 1000s of sites :-)
Notes:
Careful with the number of repositories as you must begin to worry about replication time and network traffic.
If using IIS secure the server!!!
During rollout time periods run the report that will show the utilization across the...
One person's crap is another persons gold. I have taken two courses by SANS. The other course was Intrusion Detection. I'm sorry your experience with SANS wasn't pleasurable but mine was. I found the instructors competent (Skoudis, Mike Poor, and Marty Roesch <--(SNORT author). Everyone has...
I handle a very large environment and five minutes would kill me by traffic or server utilization. My environment is 1000s of locations and 10000s of users. I set mine to 120 min to reduce the traffic. My ASCII is set to 6 hours and I do not do global updating. Settings may be tweaked...
Confirm that you have VS4.5.1 in your repository. If it is not then it will not be able to set policies for that app. VS4.5.1 is out of support I believe and if you need it you will have to talk to McAfee to get the package as it probably has been pulled from their downloads.
...environment first!
I have enclosed a snippet of code that may help you. This was written for 7.0 but should work for 7.1 & 8.0i I think.
:: *******************************************************
:VS
:: *******************************************************
:: Remove registry keys...
...computer. This is a fair amount of importing but workable.
The policies only maintain the exception lists on the On-Access scanning. It does *not* maintain exception lists on the On-Demand scanning. This means that the ODS must be done manually per task. If you have multiple anti-virus...
Last week's McAfee weekly bulletin also had Exchange 5.5 and Exchange 2000 (& GroupShield) exception lists. These were different then what I had excluded previously so all who have exchange should view.
Depends upon application. In my environment I have separate sets of exclusions. Domain Controllers, exchange servers (along w/ groupwise), SQL servers, and etc. Any databases should be excepted as it can cause poor performance along with "other" issues. I know many people do not use them but...
Microsoft now in the spyware removal business...
http://www.microsoft.com/presspass/press/2004/dec04/12-16GIANTPR.asp
REDMOND, Wash. -- Dec. 16, 2004 -- Microsoft Corp. today announced that it has acquired GIANT Company Software Inc., a provider of top-rated anti-spyware and Internet security...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.