NetIQ Change Guardian for Windows

Version 2.0 Service Pack 2

Release Notes

Date Published: March 2010

 
 

 

This service pack for the Change Guardian for Windows (CGW) product improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the NetIQ Change Guardian Products forum on Qmunity, our community Web site that also includes product notifications and blogs.

This document outlines why you should install this service pack, provides information about installing the service pack, and identifies known issues. For more information about this release and for the latest Release Notes, see the Change Guardian for Windows Web site.

Why Install This Service Pack?

CGW delivers user activity monitoring and detailed auditing of changes to files, folders, shares, processes, and the system registry on Windows servers, all without the need for native auditing. With real-time detection and notification capabilities, CGW enables you to identify and address unmanaged changes and other issues in a timely manner. This version includes moving Logon/Logoff Monitoring and Vulnerable Port Monitoring from Change Guardian for Windows to the Security Manager for Windows module. This version also includes several quality and usability improvements, plus the following:

Some Event-based Rules Moved to Security Manager Support for Windows

After you apply this service pack, you can find the Change Guardian for Windows Logon/Logoff Monitoring and Change Guardian for Windows Vulnerable Port Monitoring in the Security Manager Development Console as part of the Support for Windows processing rule group.

The rules associated with logon and logoff monitoring and vulnerable port monitoring are more consistent with the functionality of Security Manager. Moving the rules from Change Guardian to Security Manager improves the usability of both products by locating the rules where customers would expect them.

You should create custom processing rule groups for custom rules you created using Change Guardian for Windows Logon/Logoff Monitoring and Change Guardian for Windows Vulnerable Port Monitoring. Moving your custom rules from default NetIQ processing rule groups ensures future autosync updates to the Security Manager Support for Windows module do not overwrite your customizations.

Future Updates Do Not Require Managed Server Restart

This service pack allows the Change Guardian for Windows agent to load and unload the driver without restarting. Though you must restart managed servers after installing this service pack, future CGW updates do not require you to restart monitored servers.

CGW Does Not Capture Some File Read Events from Windows Server 2008 Computers

Before you apply this service pack, if you create a file filter to monitor file read events on Windows Server 2008 computers, only files accessed through a command line command such as type <file.txt> or edit <file.txt> generate events. After you apply this service pack, file filters created to monitor file read events on Windows Server 2008 computers generate alerts as expected. (ENG255840)

Monitoring Remote File Shares Can Cause Performance Issues

Before you apply this service pack, if you use CGW to monitor a remote file share, and your file filtering rules include attribute changes and permission changes, a delay can occur when someone modifies and saves files on the share. After you apply this service pack, this configuration no longer causes a delay. (ENG271947)

Monitoring Started Processes on Windows Server 2008 Computers Can Consume Resources

Before you apply this service pack, if you configure a filter to monitor a started process event on Windows Server 2008 computers, and then configure Memory Pool Monitor (poolmon) to monitor the mpgc tag, the process records additional data and consumes significant memory resources. After you apply this service pack, this configuration no longer consumes memory resources. (ENG273860)

Return to Top

Installing This Service Pack

This section provides you with information you need to install this service pack. If this installation is not an upgrade, you may need additional information. For more information about planning and installation, see the User Guide for NetIQ Change Guardian for Windows.

Managed and Unmanaged Computer Requirements

Managed and unmanaged computers that you want to monitor with CGW must be in the same configuration group, and must be running one of the following operating systems:

  • Windows XP (32-bit)
  • Windows 2000 Service Pack 4
  • Windows Server 2003 Service Pack 1 or Service Pack 2 (32-bit or 64-bit)
  • Windows Server 2008 (32-bit or 64-bit)
  • Windows Vista (32-bit or 64-bit)

CGW also supports monitoring on computers running the Windows Server 2008 R2, Windows Server 2008 Core, or the Windows 7 operating system, but you must first upgrade to Security Manager 6.5 Service Pack 2.

CGW currently supports monitoring files and processes on Windows XP and Windows 2000 computers. However, the product does not support monitoring file shares or registries on Windows XP and Windows 2000 computers.

Installing This Service Pack

Perform the following steps to install this service pack.

To install this service pack:

  1. Using an account that is a member of the local Administrators group, run CGW202InstallationKit.exe on the Security Manager central computer.
  2. Run the setup program from the root folder of the Change Guardian installation kit.
  3. Click Begin Production Setup. The setup program verifies a supported version of Security Manager is installed, the Security Manager services are running, and your account has the required permissions.
  4. Follow the instructions in the setup program until you finish installing CGW.

After a successful installation, the setup program gives you the option to configure CGW before you exit. To enable CGW to monitor computers, you must add those computers to the Change Guardian for Windows computer group

To add computers you want to monitor:

  1. Select Start the Change Guardian for Windows Configuration Wizard, if it is not already selected.
  2. Click Finish.
  3. When the Configuration Wizard opens, select Select Computers to Monitor.
  4. Follow the instructions in the Configuration Wizard until you have selected the computers you want Change Guardian for Windows to monitor.
  5. Click Close.

After you install this service pack, you must upgrade your agents. For information about upgrading your agents, see "Upgrading from Previous Versions" in the User Guide for NetIQ Change Guardian for Windows.

Return to Top

Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

Microsoft Exchange 2003 and Exchange 2007 Servers Can Experience Performance Issues

Microsoft identified a critical issue with Microsoft Exchange 2003 and Exchange 2007. The Microsoft Exchange WebDAV code, when used in conjunction with Change Guardian for Windows, results in the Microsoft Exchange Server stopping. NetIQ Security Manager is not impacted by this issue.

Microsoft issued a hotfix to resolve the issue for all Microsoft Exchange 2007 customers. If you are a Microsoft Exchange 2007 Customer, refer to this article on the Microsoft Support Web site.

Microsoft Exchange 2003 customers can receive the hotfix only if you have an Extended Hotfix Support Agreement. If you are an Exchange Server 2003 customer with a Microsoft Extended Support Agreement, see this article on the Microsoft Support Web site for more information.

Until you apply the Microsoft hotfix, Microsoft recommends that you not monitor your Microsoft Exchange 2003 and Exchange 2007 Servers with Change Guardian for Windows. If you need assistance with regard to ceasing to monitor these servers, please contact NetIQ Technical Support.

Upgrading Can Leave Outdated References to Removed Features

Upgrading to this service pack from CGW 2.0 or CGW 2.0 Service Pack 1 does not completely remove links to features moved to Security Manager for Windows. Links to Configure Change Guardian for Windows Logon/Logoff Monitoring and Configure Change Guardian for Windows Vulnerable Port Monitoring remain in the Security Manager configuration wizard and in the Security Manager Development Console, but do not initiate the features. (ENG283743, ENG284125)

Changing Configuration Group Password Can Cause Data Save Failures after CGW Installation

If you create two or more Security Manager central computers, change the configuration group password on one central computer, and then install CGW on another central computer, CGW cannot save or read configuration data, and no error message appears. Until this Security Manager issue is resolved, you can avoid the issue by installing CGW on the central computer, and then changing the configuration group password on that computer. (ENG277589)

Files Replicated Using DFSR Return Unexpected Event Results

Microsoft Distributed File System Replication (DFSR) is a replication engine used to keep folders synchronized among multiple servers. During the process of synchronization, DFSR performs a number of tasks in a staging area before applying them to the target computer. These tasks in the staging area are not performed as file operations, so events generated by CGW can appear sporadic. (DOC271853, DOC284318)

Return to Top

Contact Information

Please contact us with your questions and comments. We look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

Return to Top

Legal Notice

Return to Top