Introducing ePolicy Orchestrator 4.5

Posted: August, 05 2009

ePolicy Orchestrator 4.5 components and what they do

ePolicy Orchestrator 4.5 provides a scalable platform for centralized policy management and enforcement of your security products and the systems on which they reside. It also provides comprehensive reporting and product deployment capabilities, all through a single point of control.

The ePolicy Orchestrator software is comprised of these components:

  • ePO server— The center of your managed environment. The server delivers security policy
    and tasks, controls updates, and processes events for all managed systems.
  • Database — The central storage component for all of the data created and used by ePO.

You can choose whether to house the database on your ePO server or on a separate system, depending on the specific needs of your organization.

  • Master repository — The central location for all McAfee updates and signatures, residing on the ePO server. Master repository retrieves user-specified updates and signatures from McAfee or user-defined source sites.
  • Distributed repositories — Placed strategically throughout your environment to provide access for managed systems to receive signatures, product updates, and product installations with minimal bandwidth impact. Depending on how your network is set up, you can set up SuperAgent, HTTP, FTP, or UNC share distributed repositories.
  • McAfee Agent — A vehicle of information and enforcement between the ePO server and each managed system. The agent retrieves updates, ensures task implementation, enforces policies and forwards events for each managed system.
  • Remote Agent Handlers — A server that you can install in various network locations to help manage agent communication, load balancing, and product updates.

Remote agent handlers

Can help you manage the needs of large or complex network infrastructures by allowing you more control over agent-to-server communication.
NOTE: Depending on the needs of your organization and the complexity of your network, you might not need to use all of these components.

The ePO server

The ePO server provides management, reporting, and enforcement capabilites and includes:

  • A robust database that accrues information about product operation on the client systems in your network.
  • A querying system that lets you monitor the security status in your company, and quickly
    act on gathered data.
  • A software repository that stores the products and product updates (for example, DAT files) that you deploy to your network.

The ePolicy Orchestrator server can segment the user population into discrete groups for customized policy management. Each server can manage up to 250,000 systems.

The McAfee Agent

The agent is installed on the systems you intend to manage with ePolicy Orchestrator. Systems cannot be managed by ePolicy Orchestrator without an installed agent.
While running silently in the background, the agent:

  • Gathers information and events from managed systems and sends them to the ePolicy Orchestrator server.
  • Installs products and updates on managed systems.
  • Enforces policies and tasks on managed systems and sends events back to the ePO server.

You can deploy the agent from the console (to Windows systems) or copy the agent installation package onto removable media or into a network share for manual or login script installation on your systems. Agents must be installed manually on UNIX systems.

You may also be interested in: