Example: bachelor of science

About This Guide - help.deepsecurity.trendmicro.com

Trend Micro Deep security Best Practice Guide 2 About This Guide Deep security provides a single platform for server security to protect physical, virtual, and cloud servers as well as hypervisors and virtual desktops. Tightly integrated modules easily expand to offer in-depth defenses, including anti-malware, web reputation, intrusion prevention, firewall, integrity monitoring, and log inspection. It is available in agentless and agent-based options that can all be managed through a single console across physical, virtual, and cloud server deployments. This Guide is intended to help users get the best productivity out of the product. It contains a collection of best practices that are based on knowledge gathered from previous enterprise deployments, lab validations, and lessons learned in the field.

2 . About This Guide Deep Security provides a single platform for server security to protect physical, virtual, and cloud servers as well as hypervisors and virtual desktops.

Tags:

  Guide, Security

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of About This Guide - help.deepsecurity.trendmicro.com

1 Trend Micro Deep security Best Practice Guide 2 About This Guide Deep security provides a single platform for server security to protect physical, virtual, and cloud servers as well as hypervisors and virtual desktops. Tightly integrated modules easily expand to offer in-depth defenses, including anti-malware, web reputation, intrusion prevention, firewall, integrity monitoring, and log inspection. It is available in agentless and agent-based options that can all be managed through a single console across physical, virtual, and cloud server deployments. This Guide is intended to help users get the best productivity out of the product. It contains a collection of best practices that are based on knowledge gathered from previous enterprise deployments, lab validations, and lessons learned in the field.

2 Examples and considerations in this document serve only as a Guide and not a representation of strict design requirements. These guidelines do not apply in every environment but can help Guide you through configuring Deep security for optimum performance. Trend Micro Incorporated reserves the right to change this document and products without notice. Before installing and using the software, please review the Readme file and the latest version of the applicable user documentation. Trend Micro Deep security Best Practice Guide 3 This Best Practice Guide contains: Deployment considerations and recommendations. Guidance in sizing server and storage resources for Deep security implementation. Upgrade guidelines and scenarios.

3 Recommended configuration to maximize system performance and reduce administrative overhead. Best practice tips for VDI, private and public cloud environments. Trend Micro Deep security Best Practice Guide 4 Acknowledgments This Guide was made by the following individuals who volunteered their time and expertise to this project: Marlon Beri a, Aldrin Ceriola, Saif Chaudhry, Jennifer Chua, Jason Dablow, Erwin Dusojan, Mohamed Inshaff, Jill Maceda, Marion Mora, Winfred Lin, Robert See, Hugo Strydom, Reuel Morales, Raphael Bottino, Tomokuni Naoki, Iwata Toshiyuki, Ebenizer Padu, Igor Valoto, Simon Zhang, Martin Tarala, Andy Dai, Chen Lin, Davy Ariokta Trinugraha,Kyle Klassen and Fernando Cardoso. We would also like to thank the following people for their significant support and contribution during development and review: Shiela Aballa, Rodel Villarez, Ziv Huang, Marty Tsai, Cellina Lin, Chris Lai, Paul Liang, Zion Li Document version: Last updated: January 31, 2019 Trend Micro Deep security Best Practice Guide 5 Table of Contents 1 Environment.

4 7 Operating Systems and Database System ..7 VMware vSphere and NSX Compatibility with Deep security ..7 VMware Tools and NSX Endpoint Drivers (for Agentless Anti-Malware) ..7 Environmental Recommendations for TMCM Integration .. 8 2 Sizing Considerations .. 9 3 Installation and Deployment .. 10 Deep security Components .. 10 Deep security Manager ..10 Deep security Agent/Relay .. 13 Deep security Virtual Appliance (DSVA) .. 17 Database .. 19 VMware Components .. 21 Deployment Scenario Samples .. 23 Testing Deep security .. 25 4 Upgrade and Migration .. 26 Deep security Manager Upgrade Recommendations: .. 26 Upgrade vCNs to NSX: .. 26 5 Configuration .. 27 UI Configurations.

5 27 Dashboard .. 27 Alerts 27 Policies 27 Smart Folders .. 29 Module Configurations .. 30 Anti-Malware .. 30 Web Reputation .. 41 Firewall 42 Intrusion Prevention .. 46 Integrity Monitoring .. 48 Log Inspection .. 51 Application Control ..52 Connected Threat Defense (CTD) .. 53 Administration and System Settings .. 56 Recommendation Scan .. 56 System Settings .. 57 Trend Micro Deep security Best Practice Guide 6 6 Performance Tuning and Optimization .. 61 Deep security Manager .. 61 6. Configure Deep security Manager's Maximum Memory Usage .. 61 Configure Multiple Managers .. 62 Performance 63 6. 2 Database .. 67 Exclude Database files from Anti-Malware scans.

6 67 Auto-growth and Database Maintenance ..67 Database 68 Deep security Relay .. 68 Deep security Relay Location .. 68 Relay Groups .. 68 NSX .. 69 NSX Firewall .. 69 NSX security Policy .. 69 7 Disaster and Recovery .. 71 High Availability .. 71 Removing a virtual machine from Deep security protection in a disaster .. 72 Recovering a physical machine (with Deep security Agent) in a Disaster .. 73 Recovering an inaccessible Deep security Virtual Appliance .. 74 Isolating a Deep security Issue .. 74 8 Other Deployment Scenarios .. 77 Multi-Tenant Environment .. 77 Environments using Teamed NICs .. 78 Air-Gapped Environments .. 79 Solaris Zones .. 79 Microsoft Cluster Servers.

7 79 Microsoft Hyper-V .. 80 Virtualized Environments (VDI) .. 80 Private, Public & Hybrid Cloud Environments .. 84 SAP .. 87 IBM Rational ClearCase .. 87 Docker support .. 87 Automation Activation from Gold Image .. 90 Oracle RAC cluster .. 95 SAML .. 95 Trend Micro Deep security Best Practice Guide 7 1 Environment Deep security consists of several components working together to provide protection. The information provided in this section will help you determine the compatibility and recommended software for: a) Operating Systems b) Database Systems c) VMware vSphere and NSX Compatibility d) VMware Tools and NSX Guest Introspection Driver Operating Systems and Database System Refer to the Installation Guide .

8 VMware vSphere and NSX Compatibility with Deep security VMware and Deep security compatibility charts often change, especially as new versions of vSphere are being released. To get the latest compatibility chart, refer to the compatibility matrix article. VMware Tools and NSX Endpoint Drivers (for Agentless Anti-Malware) The agentless anti-malware operations provided by Deep security requires the NSX File Introspection Driver to be installed on the virtual machines in order to be protected. VMware includes the VMware NSX File Introspection Driver in VMware Tools , but the installation program does not install it on guest VMs by default. To install it on a guest VM, review the installation options in the table below: Available VMware Tools Installation Options Installation Option vShield Endpoint Action Typical NSX File Introspection Driver does NOT install DO NOT select this option Complete NSX File Introspection Driver Endpoint installs Select if you want all features Custom You must explicitly install NSX File Introspection Driver Expand VMware Device Drivers > VMCI Driver.

9 Select NSX File Introspection Driver and choose This feature will be installed on local drive . Table 1: VMware Tools Installation Options NOTE The NSX Driver bundled with VMware Tools is now called Guest Introspection upon upgrading vSphere to version Update 2. However, Guest Introspection service is used for NSX or higher. If you are using NSX and below, the name of this service is VMware Endpoint. Trend Micro Deep security Best Practice Guide 8 Environmental Recommendations for TMCM Integration We recommend using Trend Micro Control Manager Service Pack 3 with Patch 2 (or higher) to implement the Connected Threat Defense strategy in defense against emerging threats and targeted attacks.

10 Trend Micro Deep security Best Practice Guide 9 2 Sizing Considerations Sizing recommendations depend on the type of environment and various other factors such as network, hardware, software and applications. See for the latest sizing guidelines for Deep security Manager, its database, Deep security Agent, and Deep security Virtual Appliance. Trend Micro Deep security Best Practice Guide 10 3 Installation and Deployment Deep security is composed of several components that need to communicate with each other. If you re deploying in a highly segmented network environment, knowledge About the various ports it uses will be useful for preventing unintended functionality disruptions. Make sure that all required ports are open and not reserved for other purposes.


Related search queries