Beruflich Dokumente
Kultur Dokumente
Author:
Create date:
Change date:
Document version no.:
Page 1 of 71
Document information
History
Date
Author
Version
19/04-2011
1.0
N/A
1.2
15/10-2011
16/10-2011
Kent Agerlund
1.4
05/07-2011
1.3
Proof readers
Name
Version
Date of approval
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 2 of 71
Table of contents
Document information .................................................................................................... 2
History ....................................................................................................................... 2
Proof readers .............................................................................................................. 2
Table of contents ........................................................................................................... 3
Configuration Manager Site Topologies and FEP 2010 ........................................................ 4
Single-Site Deployment ................................................................................................... 4
Centralized policy control and centralized FEP administration .......................................... 6
Centralized policy control and decentralized FEP administration....................................... 8
Decentralized policy control and decentralized FEP administration ................................. 11
Decentralized policy control and FEP administration with centralized FEP reporting ......... 13
Installing SQL 2008 R2 requirements ............................................................................. 15
Preparing the Site server for the FEP 2010 installation ..................................................... 21
Installing FEP 2010 ....................................................................................................... 23
Templates ................................................................................................................... 26
Template settings ..................................................................................................... 26
Changes made to the default template settings ........................................................... 26
Common settings for all templates .......................................................................... 26
Common settings for all server policies .................................................................... 27
Default desktop ..................................................................................................... 27
ConfigMgr Server Policy .......................................................................................... 28
Alerts .......................................................................................................................... 29
Reports ....................................................................................................................... 31
DCM Settings ............................................................................................................... 31
Configure WSUS to automatically approve FEP 2010 definition updates ............................. 32
FEP 2010 Update Rollup 1 information ........................................................................... 35
Installing FEP 2010 Update Rollup 1............................................................................... 36
Installing the KB2554364 hotfix on the FEP reporting server ......................................... 36
Extracting the FEP2010 Update Rollup installation files ................................................. 38
Installing the Update Rollup 1 on the Configuration Manager Site server (FepExt) .......... 39
Installing the Update Rollup 1 on the FEP 2010 Reporting Server (FepReport)................ 41
Installing the Update Rollup 1 on the FEP 2010 Console machines (FepUx) .................... 43
Deploying the FEP 2010 Update Rollup 1 to Clients ......................................................... 45
Configuring Configuration Manager 2007 SUP to distribute FEP definition updates to your FEP
2010 clients ................................................................................................................. 47
Configuring FEP 2010 clients to use Configuration Manager as the primary source for
definition updates ..................................................................................................... 59
Configuring the FEP 2010 Definition Update Automation tool............................................ 61
Automating the execution of the FEP 2010 Definition Update Automation tool using Task
Scheduler (Method 1) ................................................................................................... 62
Automating the execution of the FEP 2010 Definition Update Automation tool using
Configuration Manager Status Filter Rules (Method 2) ..................................................... 67
Testing the FEP 2010 Definition Update Automation tool ................................................. 69
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 3 of 71
Single-Site Deployment
In a single-site Configuration Manager deployment, Forefront Endpoint Protection is installed
on the Configuration Manager site server. Configuration Manager administrators can perform
the following tasks from the Configuration Manager console:
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 4 of 71
Hierarchical Deployment
In a hierarchical Configuration Manager deployment, a parent site has one or more attached
child sites in the hierarchy. A parent site contains pertinent information about its child sites,
and it can control many operations at the child sites. A site that has no parent site is known
as a central site.
Depending on the needs and requirements of an organization, you can deploy Forefront
Endpoint Protection to achieve the following scenarios:
Decentralized policy control and FEP administration with centralized FEP reporting
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 5 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 6 of 71
The following table lists the tasks that can be accomplish when Forefront Endpoint Protection
is installed on the parent primary site only.
Task
Connected to the
parent site
Connected to the
child sites
Yes
Yes
Yes
Yes
Yes
No
Yes
Limited
Yes
Yes
Yes
Yes
No
No
No
Limited
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 7 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 8 of 71
The following table lists the tasks that you can accomplish when Forefront Endpoint
Protection is installed on the parent site and child sites.
Task
Connected to the
parent site
Connected to the
child sites
Yes
Yes
Yes
Yes
Yes
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 9 of 71
Important:
At a child site, there are two FEP Deployment packages, one from the parent site and one
from the child site. When deploying the Forefront Endpoint Protection client software from
the child site, you must deploy by using the software package from the parent site. The first
three letters of the software package Package ID indicate from which site the software
package originates.
When you install Forefront Endpoint Protection on the child site first, and then install
Forefront Endpoint Protection on the parent site, the FEP Policies package on the client site
is disabled, and the FEP Policies package from the parent site is propagated to the child
site. Policies created on the child site no longer exist. It is recommended that you export the
policies from the child site before you install Forefront Endpoint Protection on the parent site.
After installing Forefront Endpoint Protection on the parent site, you can import the policies
on the parent site.
Uninstalling Forefront Endpoint Protection on the parent site while Forefront Endpoint
Protection is also installed on child sites disrupts Forefront Endpoint Protection functionality
of the child sites. Repair the Forefront Endpoint Protection installation on each child site after
Forefront Endpoint Protection is uninstalled from the parent site.
FEP clients deployed at the child sites appear only in the following Client Deployment Status
categories at the parent site:
Deployed
Out of date
The reason for this is that the information for these categories is based on Configuration
Manager hardware inventory data that the parent site receives from the child sites.
The information for the following deployment categories is based on the Configuration
Manager advertisements: Removed, Failed, and Pending. Because the parent site cannot see
the advertisements created at a child site, deployment information for these categories is not
displayed at the parent site. You can view the full deployment status for deployed FEP client
software at the child site.
Policy distribution status for FEP policies assigned to collections at a child site can take up to
24 hours to display at the parent site.
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 10 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 11 of 71
Important:
Do not install Forefront Endpoint Protection on the parent site because this disables the
existing policies on the child sites and enables the following scenarios, Centralized policy
control and decentralized FEP administration.
The following table lists the tasks that you can accomplish when Forefront Endpoint
Protection is installed at the child sites only.
Task
No
Yes
No
No
Yes
Yes
No
Yes
No
No
No
Yes
Yes
Yes
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 12 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 13 of 71
Important:
Do not install full Forefront Endpoint Protection on the parent site, because this disables the
existing policies on the child sites and enables the following scenarios, Centralized policy
control and decentralized FEP administration.
The following table lists the Forefront Endpoint Protection tasks that you can accomplish
when Forefront Endpoint Protection is installed at the child sites only.
Task
No
Yes
No
No
Yes
Yes
No
Yes
Yes
Yes
No
Yes
Yes
Yes
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 14 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 15 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 16 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 17 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 18 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 19 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 20 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 21 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 22 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 23 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 24 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 25 of 71
Templates
The product ships with several default templates.
Template name
Target collection
Default workstation
Default server
Mail Server policy
ConfigMgr Server Policy
OpsMgr Server Policy
File Server Policy
Domain Controller Server
Policy
SharePoint Server Policy
SQL Server Policy
FEP
FEP
FEP
FEP
FEP
FEP
FEP
Template settings
All default settings are documented on TechNet - http://technet.microsoft.com/enus/library/gg477039.aspx
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 26 of 71
Windows Firewall
Manager Windows firewall disabled
Default desktop
Scheduled scans
Weekly scan, Friday 09:00 AM
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 27 of 71
Advanced
Enabled Scan removable storage
devices such as USB flash drives
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 28 of 71
Alerts
Email settings
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 29 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 30 of 71
Reports
All reports are accessible from http://servername/reports.
DCM Settings
Forefront Clients use desired configuration management to update status information in
Configuration Manager. By default 4 Configuration baselines are created and applied to
specific collections. Baselines written in bold are non-default baselines.
Baseline
Applied Collection
Schedule
FEP Collections\Deployment
Status\Deployment Succeeded
FEP Collections\Deployment
Status\out of date
FEP Collections\Deployment
Status\Deployment Succeeded
FEP Collections\Deployment
Status\out of date
FEP Collections\Deployment
Status\Deployment Succeeded
FEP Collections\Deployment
Status\out of date
FEP Collections\Deployment
Status\Deployment Succeeded
FEP Collections\Deployment
Status\out of date
FEP Collections\Deployment
Status\Deployment
Succeeded\Deployed Desktops
Daily
Daily
Daily
Daily
Daily
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 31 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 32 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 33 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 34 of 71
FEP 2010 client support for the following Windows Embedded 7 client operating
systems and Windows Server 2008 Core:
Windows ThinPC
Windows Server 2008 Server Core (x86 or x64)
Addition of two new preconfigured policy templates for Microsoft Forefront Threat
Management Gateway and Microsoft Lync 2010
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 35 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 36 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 37 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 38 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 39 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 40 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 41 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 42 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 43 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 44 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 45 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 46 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 47 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 48 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 49 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 50 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 51 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 52 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 53 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 54 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 55 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 56 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 57 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 58 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 59 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 60 of 71
Automating the execution of the FEP 2010 Definition Update Automation tool using
Task Scheduler (Method 1)
Automating the execution of the FEP 2010 Definition Update Automation tool using
Configuration Manager Status Filter Rules (Method 2)
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 61 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 62 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 63 of 71
/AssignmentName
FEP2010_DefUpdates
/PackageName FEP2010
DefUpdates /RefreshDP
Then click OK
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 64 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 65 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 66 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 67 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 68 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 69 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 70 of 71
Forefront Endpoint Protection 2010 installation and configuration guide for Configuration Manager 2007 v1.4.docx
Page 71 of 71