Tuesday 10 April 2012

Forefront Endpoint protection installation Step By Step

Microsoft had done several improvement in FEP ,now FEP have two main management components

  • system center configuration manager for deployment and basic reporting
  • system center operations manager for real-time reporting

for comparison between both the features of both SCOM FEP MP and SCCM  please give this a look  “http://technet.microsoft.com/en-us/library/ff823786.aspx

Forefront Endpoint Protection Server Prerequisites
Memory : +2 GB of RAM
Available disk space :1 G for installation 3 for the database
Operating system : 2003 sp2 or above
SQL: SQL 2005 Sp3 or above  with the following installed and running
SCCM: Sp2 +R2/ R3   with the following role points installed and configured
  • Hardware Inventory
  • Software Distribution
  • Desired Configuration Management
  • Reporting Services
Hotfix :KB2271736  ( http://support.microsoft.com/kb/2271736 )
Microsoft .Net Framework 3.5 Service Pack 1
 
prerequisites for client deployment
Windows XP sp3 or above
SCCM agent
SCOM agent to deliver real time information
FEP will be able to remove the following AV out of the box (Must not be password protected )
  • Symantec Endpoint Protection version 11
  • Symantec Endpoint Protection Small Business Edition version 12
  • Symantec Corporate Edition version 10
  • McAfee VirusScan Enterprise version 8.5 and version 8.7
  • TrendMicro OfficeScan version 8.0 and version 10.0
  • Forefront Client Security version 1 including the Operations Manager agent
for more information please visit :http://technet.microsoft.com/en-us/library/ff823830.aspx
note : SCCM can handle more than 10K clients but SCOM can not

Step One : creating the lab
  • AD + SQL 2008 with all roles installed and working
  • SCCM : agent installed on all lab  ,using SQL on the AD server
  • SCOM : fully installed using the AD sql server  agent  installed on windows servers only
  • Client1 : Windows 7 + SCCM agent Only
Drawing1
 
Installing the prerequisites :
  • installing SCCM needed rules and configuration 
  • install the reporting point where the SQL Reporting is installed
image
image
image
please note the folder name , in many instances I found that this folder are not created automatically and need to be created manually
image
image

now we wait for a bit of time until SCCM transfers the needed files to the RS node and install them (5 or 10 minutes )
we go to the properties of the Reporting services role and we complete the needed information
image

next we configure the data source settings
image
ok

Step Two:enable the needed client Agents
we start by Hardware Agent
image

Advertised programs client agent
image

the desired configuration management agent ( you can  for this one to make it as low as 15 Minutes )
image

Step three:  installing FEP
we have two kinds of installation

  • Basic Setup
This procedure details the steps for installing Forefront Endpoint Protection based upon the Configuration Manager deployment.
  • Basic with a Remote Reporting Database Setup
This procedure details the steps for installing Forefront Endpoint Protection based upon the Configuration Manager deployment and allows you to specify a different Microsoft SQL Server for the Forefront Endpoint Protection reporting database.
 
So we will be using the basic setup
image
image
note: use advanced only if you need to make FEP server services running on separate server  this is necessary only with large number of users
image
image

spyNET configuration I always like to make it advanced for the added value of it
image
image
image
click next to install
image
and we done

Step Four: installing the SCOM Management Pack and importing it
this step is a straight through you will only need a management pack imported ,the client installed and the scom agent installed and that’s about it

image

image
image
image
image
image
this is how it looks like
image
also the reporting

image

No comments:

Post a Comment