12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

13Managing <strong>McAfee</strong> DLP systemsAdding servers to <strong>McAfee</strong> DLP systems5 Highlight and copy the entire text, including the BEGIN and END CERTIFICATE lines.6 Open a web browser and logon to the Network <strong>McAfee</strong> DLP Manager.7 In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Sys Config | System Administration | DirectoryServices.8 From the Actions menu, select Create <strong>McAfee</strong> Logon Collector.9 Type the IP address of the <strong>McAfee</strong> Logon Collector into the IP Address field.10 Select the Paste from Clipboard option and paste the Base 64 text into the box.Alternatively, you can export the certificate from <strong>McAfee</strong> Logon Collector to your desktop, thenBrowse to it from the Import MLC Certificate | From File field.11 Click Apply.This authenticates the <strong>McAfee</strong> Logon Collector to <strong>McAfee</strong> DLP Manager.12 Click the Export link to save the NetDLP certificate to your desktop.The file name is netdlp_certificate.cer.13 Open a web browser, enter the IP address of the <strong>McAfee</strong> Logon Collector in the address bar, and logon.14 Select Menu | Configuration | Trusted CA.15 Click New Authority.16 Browse to the netdlp_certificate.cer file you saved to your desktop.17 Click Open, then Save.This authenticates <strong>McAfee</strong> DLP Manager to <strong>McAfee</strong> Logon Collector.18 Open a Remote Desktop session on the <strong>McAfee</strong> Logon Collector server and restart it.When the server comes up, the SSL connection between the servers is complete.How <strong>McAfee</strong> Logon Collector enables user identification<strong>McAfee</strong> Logon Collector is used to map IP addresses to user identities within Active Directory servers.Without it, users might be hard to identify because they might be logged into different or multipleworkstations. IP addresses change when DHCP servers assign new addresses, and more than one usermight be logged on to the same workstation.When a <strong>McAfee</strong> Logon Collector is configured with <strong>McAfee</strong> DLP Manager, it resolves user identities byretrieving collections of user account information from all Active Directory servers that have beenadded to the DLP system. Supporting multiple domain controllers means that large‐scale enterpriseoperations can be served by <strong>McAfee</strong> applications.For <strong>McAfee</strong> DLP, that means that after <strong>McAfee</strong> Logon Collector is enabled, <strong>McAfee</strong> DLP administratorscan configure Active Directory‐based queries and rules to find out what activities specific users areengaging in on the network.How <strong>McAfee</strong> DLP uses SIDsBecause <strong>McAfee</strong> Logon Collector allows <strong>McAfee</strong> DLP to key on SIDs (Security Identifiers) instead ofsAMAccountnames, the identities of individual users can be resolved and their traffic can be270 <strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!