
Method Action Notes
Unmanaged
McAfee
products on
Windows
systems
Using the System Tree, the McAfee ePO
administrator selects the systems to be
converted from unmanaged status to
managed status and selects Actions | Agent |
Deploy Agents.
• An agent must already be present
on the target system in
unmanaged mode.
Unmanaged
McAfee
products on
UNIX‑based
platforms
Type the following command on the system
containing the agent you want to convert
from unmanaged to managed status:
<agent install path>/bin/msaconfig ‑m
‑d <Path of location containing
agentfipsmode, srpubkey.bin ,
reqseckey.bin and SiteList.xml>
If you are using McAfee ePO server 4.6,
export agentfipsmode file along with the
mentioned files and rename the
reqseckey.bin and srpubkey.bin to
req2048seckey.bin and sr2048pubkey
.bin respectively.
• You must have root privileges to
perform this action.
• You must use the srpubkey.bin,
reqseckey.bin and SiteList
.xml files from the McAfee ePO
server.
When to deploy from ePolicy Orchestrator
There are specific settings that must be configured on your ePolicy Orchestrator before deploying
McAfee Agent.
Deploying the McAfee Agent from ePolicy Orchestrator can support many systems simultaneously.
• Systems must already be added to the System Tree.
If you have not yet created the System Tree groups, you can deploy the agent installation package
to systems at the same time that you add groups and systems to the System Tree. However, McAfee
does not recommend this procedure if you are importing large domains or Active Directory
containers. These activities generate significant network traffic.
• The user must have local administrator privileges on all target systems. Domain administrator
rights are required on a system to access the default Admin$ shared folder. The McAfee ePO server
service requires access to this shared folder in order to install agents.
• The McAfee ePO server must be able to communicate with the target systems.
Before beginning a large agent deployment, ping some targets by machine name in each segment
of your network to verify that the server can communicate. If the targeted systems respond to the
ping, ePolicy Orchestrator can reach the segments.
The ability to successfully use ping commands from the McAfee ePO server to managed systems is
not required for the agent to communicate with the server. It is, however, a useful test to determine
if you can deploy agents to those client systems from the McAfee ePO server.
• The Admin$ share folder on Windows target systems must be accessible from the McAfee ePO
server. Verify that this is true on a sample of target systems. This test also validates your
administrator credentials, because you cannot access remote Admin$ shares without administrator
rights.
From the McAfee ePO server, click Windows Start | Run, then type the path to the target system's
Admin$ share, specifying system name or IP address. For example, type \\<System Name>\Admin$.
If the systems are properly connected over the network, and your credentials have sufficient rights,
and the Admin$ share folder is present, a Windows Explorer dialog box appears.
2
Installing the agent
Installation vs. deployment
20
McAfee
®
Agent 4.8.0 Product Guide
Commenti su questo manuale