+ All Categories
Home > Documents > Interchange Patch Manager

Interchange Patch Manager

Date post: 11-Feb-2017
Category:
Upload: carson-platero
View: 38 times
Download: 1 times
Share this document with a friend
40
Customer tools for the road ahead SHIFT YOUR LANDESK INVESTMENT INTO OVERDRIVE Learn more at Momentum.LANDESK.com
Transcript
Page 1: Interchange Patch Manager

Customer tools for the road ahead

SHIFT YOUR LANDESK INVESTMENT

INTO OVERDRIVELearn more at

Momentum.LANDESK.com

Page 2: Interchange Patch Manager

C a r s o n P l a t e r oC o n s u l t a n tL A N D E S K P r o f e s s i o n a l S e r v i c e s

LANDESK Patch Manager 2016

Page 3: Interchange Patch Manager

Agenda

What’s new in LANDESK Patch Manager 2016 Getting started How we scan and remediate Understanding the Patch and Compliance Tool Configure devices Managing Security Content Scanning devices Patching devices

Page 4: Interchange Patch Manager

LDMS Improvements to Patch Manager - Summary

Improved Charts Improved Patch Definition Group

options Ability to provide Tags for Definitions Integration with Rollout Projects tool Improved Icons

Page 5: Interchange Patch Manager

Dashboards and charts

Double-click to create a related query

Chart colors – can choose from different themes

Display the dashboard in a separate window

Copy to clipboard as an image

Page 6: Interchange Patch Manager

Download updates improvements

Apply group settings by Definition Type and Severity

Actions available: Assign Scan Status Assign Autofix Status Add to Custom Groups Assign Tags Add to rollout projects

Page 7: Interchange Patch Manager

Definition Tagging

Add one or more tags to patch definitions

Add specifics tags based on Download Updates Definition group filter criteria

Integration with Rollout Projects Tool

Page 8: Interchange Patch Manager

LANDESK Patch and Compliance“Why”

Page 9: Interchange Patch Manager

Main tasks for configuration Patch and Compliance

o Configure the LANDESK Agent Security and Compliance Settingso Download vulnerability definitions from a LANDESK Content Servero Create a scan job to detect vulnerabilities in your environmento Use the scan results to determine what you are going to patch in your

environmento Download patches for detected vulnerabilitieso Repair detected vulnerabilities by installing patches to affected deviceso View reports to see patch status and repair history

Page 10: Interchange Patch Manager

Managing ContentWhat is the definition of a definition?

Page 11: Interchange Patch Manager

Understand LANDESK Content typeso Linux: Security Threats and Vulnerabilities

o Mac: Security Threats, Antivirus (Kaspersky, LANDESK, McAfee and Symantec)

o Windows:

o Antivirus updates for LANDESK Antivirus and for 3rd party Antivirus vendors.

(Avast, AVG, Avira, Bitdefender, Bullguard, eScan, ESET, eTrust, Gdata, Kaspersky, McAfee, Microsoft Forefront, Windows Defender, Panda, Shavlik, Sophos, Symantec, Trend Micro, and Vipre)

o Driver Updates: Dell Poweredge Servers, HP Client, Lenovo Think Client, Lenovo Thinkserver, Microsoft

o Applications to block (Malware, Hacking Tools, Etc)

o LANDESK File Reputation

o Microsoft Windows Security Threats

o Microsoft Windows Spyware

o SCAP (Secure Content Automation Tool)

o Software Updates (Intel, LANDESK, Lenovo, Thinkvantage)

o Vulnerabilities

(7-zip, Acro Software, Adobe, AOL, Apple, Box, Cisco, Citrix, Filezilla, Foxit, GlavSoft Google, HP, IAC, IBM, ICQ, IDM, Intel, LibreOffice, McAfee, Microsoft, Mozilla, Notepad++, Nuance, Nullsoft, OpenOffice, Opera, Oracle, Pidgin, Qualcomm, RealNetworks, RealVNC, Skype, Sun, TechSmith, The Gimp Team, TortoiseSVN, TightVNC, Trend Micro, UltraVNC, VideoLAN, VMWare, Winzip, Wireshark, Xmind, Yahoo)

Page 12: Interchange Patch Manager

Content scanning and remediation behavior

Page 13: Interchange Patch Manager

Selecting and downloading content types

Vulnerability Content LANDESK Content comes in different categories. A regular schedule should be configured to

download Security and Patch content at regular intervals.

Different content types can have separate download tasks.

Page 14: Interchange Patch Manager

Managing downloaded content

Many customers patch monthly. Definition Group Setting can be used to sort definitions into groups and rollout projects.

Page 15: Interchange Patch Manager

New distribution group settings options in LDMS 2016

LDMS 2016 offers great flexibility in organizing downloaded content automatically

New tabbed interface in the Download Updates tool

Filter Scan Autofix Groups and Tags Rollout Projects

Page 16: Interchange Patch Manager

Patch Group Examples

0 New Patches 1 Pilot Baseline

Year

Page 17: Interchange Patch Manager

“I’ve downloaded content… Now what?”

Page 18: Interchange Patch Manager

Which Patches Should I Deploy?

11,000+ Windows Vulnerabilities Severity

Microsoft NA – carefully review before deploying Use Filters

Suffixes _Manual _Upgrade _Fixit _Detect_Only _All_Updates

Page 19: Interchange Patch Manager

Patch Definition Review

Replaced By Repairable Detected Multiple Versions Upgrade Product

Page 20: Interchange Patch Manager

Disable Replaced Rules

Check once in a while Scan – Replaced or Partial Replaced

Page 21: Interchange Patch Manager

Agent ConfigurationAgent Settings

Page 22: Interchange Patch Manager

Configuring Agent Settings

The Agent Configuration settings are in the Agent Configuration Tool These settings control the behaviors of the settings when scanning and repairing vulnerabilities on the client.

These settings include such things as whether or not the user will see the Vulnerability Scanner interface, options to defer repairs, reboot behaviors, scanning and repair schedules, etc.

Page 23: Interchange Patch Manager

Patch Maintenance

Meaningful Name State AND Time Windows Only Scan and Download

Now Repair\Reboot

in Window Reboot Settings

Must Agree

Page 24: Interchange Patch Manager

Pre-Repair / Post-Repair

Succeeded=true Or Zero (0)

Message=“Hello World” If running script depends on file being there or access to

share

Page 25: Interchange Patch Manager

Scanning and RepairGetting the work done

Page 26: Interchange Patch Manager

Scanning Devices

Scanning of your devices can be started in several ways:

1. Right-click computer and select “Patch and Compliance scan now…”2. Regular schedule driven by the local scheduler on the client3. Running Vulscan.exe (Vulnerability scanner) from the command line4. As part of a repair by right-clicking on a group and clicking “Repair”

(In this case the scan and the repair will both be run in succession)

Typically vulnerability scans should be run daily.

Page 27: Interchange Patch Manager

Reviewing scan results

After scanning your environment, those vulnerabilities that have been found will show up in the Detected section of the tree.

You can then take action on them by multi-selecting and then choosing right-click repair, or drag them into a group, etc.

Page 28: Interchange Patch Manager

Repairing vulnerabilities

Repairing vulnerabilities can be initiated in several ways including the following:

Right-click definitions and choose “Repair” (Up to 100 at a time) Right-click a group and choose “Repair” (Can be greater than 100) Autofix (or Autofix by Scope) As part of a rollout project

Page 29: Interchange Patch Manager

Repair by Group

Dynamic Can contain more than 100 definitions Will repair definitions at that level or below

Useful for repairing baseline plus recent tested patches

Page 30: Interchange Patch Manager

TroubleShootingWhat to do if reboot and retry fail

Page 31: Interchange Patch Manager

Clean Repair History

Right-Click Device -> Security and Patch Information Clean/Repair History

Lookup Wusa.exe and MSIExec errors Patch Download – make sure core has downloaded patch

Page 32: Interchange Patch Manager

Reboot and Try Again (Why!)

Detection is often based upon file scanning Without a reboot old file is still in place

If after a reboot a definition is still detected, try running it manually on the workstation. Possibly a more useful error message will display

Page 33: Interchange Patch Manager

Custom DefinitionsPlagiarism is Good

Page 34: Interchange Patch Manager

Custom Definitions Made Easy

Take what’s there and make it new again! Right Click Definition Clone -> Change -> Save

Page 35: Interchange Patch Manager

Custom Variables

Change Install Behavior of Patches

Close Browsers and Apps Used by Install Actions

Page 36: Interchange Patch Manager

Query Filter

Only Used in Custom Defs Target Double Check Does Hit Database

Page 37: Interchange Patch Manager

Stop Processes

Distribution and Patch Setting must be set to Kill Processes

Page 38: Interchange Patch Manager

Install Actions

Use Reuse Change

Page 39: Interchange Patch Manager

Hands on Lab

Page 40: Interchange Patch Manager

Thank youYour feedback is welcome. Please fill out the survey for this session in the interchange 16 app.


Recommended