Jump to content

No way to resend policies in ERA 6.X?


Recommended Posts

I had to import a configuration made by ESET support to see what firewall rules they created for allowing RSOP.  That blew away all of my firewall rules and left me with none.  So I figured I'd just resend the policy.  I hope it's because I don't know how to do it and not that it can't.  

 

I had to get a co-worker to export his endpoints configuration so I could import it back onto my endpoint.

Link to comment
Share on other sites

  • ESET Staff

Hi @cpetry,

 

In theory you can create a new static group with that special configuration and policy,

so when you "move" a terminal there, the configuration and policy should be

automatically apply.

Link to comment
Share on other sites

I don't have a special configuration and or policy.  I want to resend the policies that are currently supposed to be applied to the endpoint.  I imported some botched config sent to me from ESET support that blew away my endpoints firewall rules.  I figured, no problem, these settings are policy enforced, I can resend the policies or reboot and the ERA should reinforce/resend the policies I have.  Well, no, that didn't happen, and I don't see a way in tasks or the GUI to reinforce/resend policies.

 

So instead, I just had a co-worker export his endpoint configuration, which was received from the ERA to begin with, and I imported that into my endpoint.  That worked...

Link to comment
Share on other sites

As far as I can tell, here is no specific client or server task that can force the re-application of an existing policy to a client. Crazy, I know. You can try to create a duplicate policy, then move the client to the new one. Once it applies, you can then place them back under the old policy.

 

Go to the Policies under Admin, select your policy, then the gear or Actions, and then duplicate.

Edited by sreece
Link to comment
Share on other sites

  • ESET Staff

How was the configuration applied on the Endpoint?  It was locally imported?

When policy is set from ERA, it is "enforced" on the Endpoint. It means, that even when you import policy settings, ERA agent should overwrite the settings set by the imported configuration.

 

Please note, that as of now, it is not possible to merge various list in firewall, means that if you want to extend your policy with the rules send by ESET support, you should either edit the master policy, or created a new duplicated one from the master, with the new rules added.

Link to comment
Share on other sites

Yes, I locally imported the config sent to me via ESET support.  So that prevented the ERA from overwriting it I guess because that's exactly how it behaved.  My firewall rules were blank for over an hour until I finally gave up and re-improted a config from a working client.

 

I need to get ESET support to send me the rules in non config.xml format.  I haven't heard back... 

Link to comment
Share on other sites

  • ESET Staff

I have asked our QA engineers to reproduce the issue. We have tried with the most recent build of ERA Agent, ERA Server, and Endpoint Security, all version 6.3, and we were not able to achieve the state you are describing. When we have attempted to import a configuration, none of the changes were applied. Policy was still enforced. Can you please confirm, that ERA agent is still running on the target computer? Also please let us know a specific version numbers for Agent and Endpoint, of possible, so we can try to simulate your specific environment. 

Link to comment
Share on other sites

I'm running the latest version of everything.  Yes, policies that weren't the firewall rules were still there.  My firewall rules were blanked out.  After I imported the config from another client my firewall rules all came back.  The built-in rules were all blown away and the rules in the config from ESET weren't in the list.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...