Jump to content

Create All in one installer include polices


hungtt
 Share

Recommended Posts

Hi all,

I created All in one installer include policy below :

ESET Remote Administrator Agent : defined clients connect to ERA PROXY on "Servers to connect to" and "Http Proxy"

ESET Endpoint for Windows : Tool --> proxy server --> ERA PROXY

But after install on clients, clients not connected to ERA PROXY, it still connected to ERA SERVER.

Please help me check this.

Thanks.

 
 
Link to comment
Share on other sites

Do you still have the default proxy policies applied to All group in ERA? If so then the server-side policies will still override the policies you selected in the All-In-One installer after connecting to the server. So what may have happeed is that the client did connect to ERA Proxy initially, but after policy replication Proxy Server setting gets overwritten by server-side policies. I reckon it's better to think of the all-in-one installer policy selection as a temporary configuration used before connecting to ERA.

Link to comment
Share on other sites

Hi V2TW,

I want to install all in one to clients in fact clients not communicate ERA server via direct.ERA server will communicate clients via ERA proxy.

So how to can I do that ?

Link to comment
Share on other sites

  • ESET Staff

Not sure what version you are using, but when you are creating installer in ERA 6.5, you can specify configuration policy for AGENT but also fields Server hostname and Port. These are connection parameters for installed AGENT and will override settings in AGENT's policy.

 

Link to comment
Share on other sites

Hi MartinK,

I'm using ERA 6.5

I created all in one install below file attach.After install on client, I run NETSTAT -an on cmd, client connect to ERA SERVER IP with port 3128.

I want after install all in one on clients, cliest must to connect ERA PROXY with port 3128 and 2222.

How to I can do it ?

 

1.jpg

2.jpg

3.jpg

4.jpg

5.jpg

Link to comment
Share on other sites

  • ESET Staff

There are two different proxies (ERA PROXY and HTTP Proxy) used in ERAv6 environment. ERA PROXY is used for AGENT->SERVER connection, and HTTP Proxy is used for downloading modules update / repository packages from ESET servers.

In case you wan't AGENTs to connecto to SERVER through ERA Proxy (AGENT -> PROXY -> SERVER), use IP/hostname of PROXY in field Server hostname. It may be misleading, but this is IP/hostname where AGENT will be connecting = either SERVER or PROXY.

HTTP Proxy should be configured using AGENTs configuration policy as is for endpoints.

Link to comment
Share on other sites

Hi MartinK,

I tried method as you advice.After install on clients, clients connected to ERA PROXY via port 2222.And I have to create policy change HTTP PROXY on ERA SERVER --> assign to clients.

So can I integrated this policy ( http proxy) on ALL IN ONE installer ?

 

 

 

Link to comment
Share on other sites

  • ESET Staff
2 minutes ago, hungtt said:

So can I integrated this policy ( http proxy) on ALL IN ONE installer ?

Yes you could include it in installer, but be aware that once newly installed AGENT connect to SERVER or PROXY, it will receive configuration policies from SERVER, and they will override this configuration parameter in case such policy exists.

Link to comment
Share on other sites

Hi MartinK,

I tried install again with information below

ERA Server : 210.245.23.111

ERA Proxy : 10.10.10.254

Client 10.10.10.3 not access internet, only communicate with ERA Proxy.

All in one installer include 2 policies :

1.Change agent IP communication between client and ERA Proxy : client will connect to ERA PROXY port 2222

2.Change HTTP proxy endpoint on client : client will connect ERA PROXY port 3128 ( ERA Proxy installed Apache Http)

After installed on clinet, erverything is ok : client connected ERA PROXY port 2222 and 3128, it can active and update DB via ERA Proxy ( client not access internet).

When I log on web console ERA server, i check detail of this client, it don't have 2 policies integrated All in one installer ,

then return this client to check, HTTP Proxy on client had changed to IP ERA SERVER.So that I must assign policy HTTP Proxy on client via web console again ?

Please check video demo via link : hxxp://fsend.vn/WnwPkfYv ( this link will remove after 7 days)

 

Link to comment
Share on other sites

  • ESET Staff
7 hours ago, hungtt said:

A Proxy ( client not access internet).

 

When I log on web console ERA server, i check detail of this client, it don't have 2 policies integrated All in one installer ,

then return this client to check, HTTP Proxy on client had changed to IP ERA SERVER.So that I must assign policy HTTP Proxy on client via web console again ?

Please check video demo via link : hxxp://fsend.vn/WnwPkfYv ( this link will remove after 7 days)

 

Policies selected during installation are used to change default configuration of EES/EAV or AGENT. They are not consider as applied policies. Also configuration applied during installation (selected policies) should not lock settings. Changing default settings during installation is useful in case special configuration is required to be applied immediately and not after AGENT connects to SERVER -> suitable for offline environments, environments where password-protected installation of EES/EAV is required and also in AGENT-less (non-mananged) environment.

Once AGENT connects to SERVER (or PROXY) it will start to use only policies that re assigned to it in Webconsole. Settings used during installation (extracted from selected policies) will remain used until another policy assigned to AGENT will override them. It is recommended to assign policies to client computers, as install-time configuration may be lost during re-installation of EES/EAV.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...