+ All Categories
Home > Documents > IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX...

IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX...

Date post: 26-Sep-2020
Category:
Upload: others
View: 9 times
Download: 0 times
Share this document with a friend
23
IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal Reserve Bank of Atlanta
Transcript
Page 1: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference

Session: SEM-1182 Presented by: Ed Redmond Federal Reserve Bank of Atlanta

Page 2: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

DISCLAIMER

Network Controls

The views presented here are my own personal views and not the views of the Federal Reserve Bank of Atlanta nor the Federal Reserve System.

Page 3: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

WHAT IS THE NEED FOR THIS? So many settings ...

Network Controls System Admins need to ensure that the servers they are responsible for are configured properly

Page 4: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

WHERE IS THIS SETTING COMING FROM? Using RSOP

Network Controls If a setting is misconfigured, SysAdmins will use RSOP to determine what GPO is configuring that setting

Page 5: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

LOOK AT ALL THOSE SERVERS… So many servers…. So little time…

Network Controls

Page 6: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

IS THERE SOME WAY TO AUTOMATE THIS Using WMI queries with PowerShell

Network Controls What I found when Googling “wmi user right assignment”

Page 7: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

IS THERE A BETTER WAY TO AUTOMATE THIS Using WMI queries with BigFix Relevance

Network Controls What I found when Googling “BigFix WMI query”

Page 8: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

LET’S TRY THIS OUT Using WMI queries with BigFix Relevance

Network Controls

Page 9: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

I THINK WE ARE ON TO SOMETHING Cleaning up the output of WMI query

Network Controls Use string inspectors to clean up the output

Page 10: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

I THINK WE ARE ON TO SOMETHING Cleaning up the output of WMI query

Network Controls Still using string inspectors to clean up the output

Page 11: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

WORK SMARTER NOT HARDER BigFix can determine if configured properly

Network Controls BigFix can do analysis for us… Assume only “LOCAL SERVICE” should be assigned the Change System Time right.

Page 12: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

Notice the GPOID returned by the WMI query? Can I actually find out the name of the GPO?

IT LEFT ME WANTING MORE… Can we report more than just the setting?

Network Controls Investigated to see what is actually returned by WMI

Page 13: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

YOU GOTTA DIG A LITTLE DEEPER RSOP_GPO Class

Network Controls Found this when Googling “RSOP_GPO”

Page 14: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

Assumed that the guidName was the same thing as the GPOID in previous WMI query

YOU GOTTA DIG A LITTLE DEEPER Querying RSOP_GPO Class using BigFix

Network Controls Performing a general query for RSOP_GPO class

Page 15: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

It looks like the “name” property is the same as the name of the GPO displayed in the RSOP results.

YOU GOTTA DIG A LITTLE DEEPER Querying RSOP_GPO Class using BigFix

Network Controls Performed a query of RSOP_GPO using the GPOID we found earlier…

Page 16: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

YOU GOTTA DIG A LITTLE DEEPER Cleaning up output

Network Controls We can clean up the output like we did earlier

Page 17: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

YOU GOTTA DIG A LITTLE DEEPER Cleaning up output

Network Controls Still cleaning up the output…

Page 18: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

YOU GOTTA DIG A LITTLE DEEPER Making the query more dynamic

Network Controls Since we do not know the guid of the GPO that is configuring a particular setting we need to make our query more dynamic

Page 19: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

WONDER TWIN POWERS ACTIVATE!!! Joining both queries

Network Controls For more robust information, we can join both of our previous queries..

Page 20: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

SO WHAT’S THE BIG DEAL? Efficiencies Gained

Network Controls

•  Deployed this for 42 settings across ~4500 servers (189,000 settings)

•  Reduced misconfigurations from 20,000+ to around 800

•  Saves about 30 man hours per week

Page 21: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

HELPFUL WEBSITES

Network Controls BigFix Forum https://forum.bigfix.com

BigFix.me

https://bigfix.me IBM Inspector Documentation

https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/Tivoli%20Endpoint%20Manager/page/Inspector%20Documentation

BigFix Support

https://support.bigfix.com/ BigFix Developer

https://developer.bigfix.com/

Page 22: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

QUESTIONS

Network Controls

Page 23: IDENTIFYING MISCONFIGURATIONS USING BIGFIX RELEVANCE€¦ · MISCONFIGURATIONS USING BIGFIX RELEVANCE IBM InterConnect 2017 Conference Session: SEM-1182 Presented by: Ed Redmond Federal

CONTACT INFO

Network Controls

Ed Redmond Email: [email protected] BigFix Forum: eredmond


Recommended