NetIQ Change Guardian for Windows |
Version 2.0 Service Pack 2 |
Release Notes |
Date Published: March 2010 |
|
This service pack for the Change Guardian for Windows (CGW) product improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the NetIQ Change Guardian Products forum on Qmunity, our community Web site that also includes product notifications and blogs. This document outlines why you should install this service pack, provides information about installing the service pack, and identifies known issues. For more information about this release and for the latest Release Notes, see the Change Guardian for Windows Web site. Why Install This Service Pack?CGW delivers user activity monitoring and detailed auditing of changes to files, folders, shares, processes, and the system registry on Windows servers, all without the need for native auditing. With real-time detection and notification capabilities, CGW enables you to identify and address unmanaged changes and other issues in a timely manner. This version includes moving Logon/Logoff Monitoring and Vulnerable Port Monitoring from Change Guardian for Windows to the Security Manager for Windows module. This version also includes several quality and usability improvements, plus the following:
Some Event-based Rules Moved to Security Manager Support for WindowsAfter you apply this service pack, you can find the Change Guardian for Windows Logon/Logoff Monitoring and Change Guardian for Windows Vulnerable Port Monitoring in the Security Manager Development Console as part of the Support for Windows processing rule group. The rules associated with logon and logoff monitoring and vulnerable port monitoring are more consistent with the functionality of Security Manager. Moving the rules from Change Guardian to Security Manager improves the usability of both products by locating the rules where customers would expect them. You should create custom processing rule groups for custom rules you created using Change Guardian for Windows Logon/Logoff Monitoring and Change Guardian for Windows Vulnerable Port Monitoring. Moving your custom rules from default NetIQ processing rule groups ensures future autosync updates to the Security Manager Support for Windows module do not overwrite your customizations. Future Updates Do Not Require Managed Server RestartThis service pack allows the Change Guardian for Windows agent to load and unload the driver without restarting. Though you must restart managed servers after installing this service pack, future CGW updates do not require you to restart monitored servers. CGW Does Not Capture Some File Read Events from Windows Server 2008 ComputersBefore you apply this service pack, if you create a file filter to monitor file read events on Windows Server 2008 computers, only files accessed through a command line command such as type <file.txt> or edit <file.txt> generate events. After you apply this service pack, file filters created to monitor file read events on Windows Server 2008 computers generate alerts as expected. (ENG255840) Monitoring Remote File Shares Can Cause Performance IssuesBefore you apply this service pack, if you use CGW to monitor a remote file share, and your file filtering rules include attribute changes and permission changes, a delay can occur when someone modifies and saves files on the share. After you apply this service pack, this configuration no longer causes a delay. (ENG271947) Monitoring Started Processes on Windows Server 2008 Computers Can Consume ResourcesBefore you apply this service pack, if you configure a filter to monitor a started process event on Windows Server 2008 computers, and then configure Memory Pool Monitor (poolmon) to monitor the mpgc tag, the process records additional data and consumes significant memory resources. After you apply this service pack, this configuration no longer consumes memory resources. (ENG273860) Installing This Service PackThis section provides you with information you need to install this service pack. If this installation is not an upgrade, you may need additional information. For more information about planning and installation, see the User Guide for NetIQ Change Guardian for Windows. Managed and Unmanaged Computer RequirementsManaged and unmanaged computers that you want to monitor with CGW must be in the same configuration group, and must be running one of the following operating systems:
CGW also supports monitoring on computers running the Windows Server 2008 R2, Windows Server 2008 Core, or the Windows 7 operating system, but you must first upgrade to Security Manager 6.5 Service Pack 2. CGW currently supports monitoring files and processes on Windows XP and Windows 2000 computers. However, the product does not support monitoring file shares or registries on Windows XP and Windows 2000 computers. Installing This Service PackPerform the following steps to install this service pack. To install this service pack:
After a successful installation, the setup program gives you the option to configure CGW before you exit. To enable CGW to monitor computers, you must add those computers to the Change Guardian for Windows computer group To add computers you want to monitor:
After you install this service pack, you must upgrade your agents. For information about upgrading your agents, see "Upgrading from Previous Versions" in the User Guide for NetIQ Change Guardian for Windows. Known IssuesNetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.
Microsoft Exchange 2003 and Exchange 2007 Servers Can Experience Performance IssuesMicrosoft identified a critical issue with Microsoft Exchange 2003 and Exchange 2007. The Microsoft Exchange WebDAV code, when used in conjunction with Change Guardian for Windows, results in the Microsoft Exchange Server stopping. NetIQ Security Manager is not impacted by this issue. Microsoft issued a hotfix to resolve the issue for all Microsoft Exchange 2007 customers. If you are a Microsoft Exchange 2007 Customer, refer to this article on the Microsoft Support Web site. Microsoft Exchange 2003 customers can receive the hotfix only if you have an Extended Hotfix Support Agreement. If you are an Exchange Server 2003 customer with a Microsoft Extended Support Agreement, see this article on the Microsoft Support Web site for more information. Until you apply the Microsoft hotfix, Microsoft recommends that you not monitor your Microsoft Exchange 2003 and Exchange 2007 Servers with Change Guardian for Windows. If you need assistance with regard to ceasing to monitor these servers, please contact NetIQ Technical Support. Upgrading Can Leave Outdated References to Removed FeaturesUpgrading to this service pack from CGW 2.0 or CGW 2.0 Service Pack 1 does not completely remove links to features moved to Security Manager for Windows. Links to Configure Change Guardian for Windows Logon/Logoff Monitoring and Configure Change Guardian for Windows Vulnerable Port Monitoring remain in the Security Manager configuration wizard and in the Security Manager Development Console, but do not initiate the features. (ENG283743, ENG284125) Changing Configuration Group Password Can Cause Data Save Failures after CGW InstallationIf you create two or more Security Manager central computers, change the configuration group password on one central computer, and then install CGW on another central computer, CGW cannot save or read configuration data, and no error message appears. Until this Security Manager issue is resolved, you can avoid the issue by installing CGW on the central computer, and then changing the configuration group password on that computer. (ENG277589) Files Replicated Using DFSR Return Unexpected Event ResultsMicrosoft Distributed File System Replication (DFSR) is a replication engine used to keep folders synchronized among multiple servers. During the process of synchronization, DFSR performs a number of tasks in a staging area before applying them to the target computer. These tasks in the staging area are not performed as file operations, so events generated by CGW can appear sporadic. (DOC271853, DOC284318) Contact InformationPlease contact us with your questions and comments. We look forward to hearing from you. For detailed contact information, see the Support Contact Information Web site. Legal NoticeTHIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT ARE FURNISHED UNDER AND ARE SUBJECT TO THE TERMS OF A LICENSE AGREEMENT OR A NON-DISCLOSURE AGREEMENT. EXCEPT AS EXPRESSLY SET FORTH IN SUCH LICENSE AGREEMENT OR NON-DISCLOSURE AGREEMENT, NETIQ CORPORATION PROVIDES THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SOME STATES DO NOT ALLOW DISCLAIMERS OF EXPRESS OR IMPLIED WARRANTIES IN CERTAIN TRANSACTIONS; THEREFORE, THIS STATEMENT MAY NOT APPLY TO YOU. This document and the software described in this document may not be lent, sold, or given away without the prior written permission of NetIQ Corporation, except as otherwise permitted by law. Except as expressly set forth in such license agreement or non-disclosure agreement, no part of this document or the software described in this document may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, or otherwise, without the prior written consent of NetIQ Corporation. Some companies, names, and data in this document are used for illustration purposes and may not represent real companies, individuals, or data. This document could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein. These changes may be incorporated in new editions of this document. NetIQ Corporation may make improvements in or changes to the software described in this document at any time. © 2010 NetIQ Corporation. All rights reserved. U.S. Government Restricted Rights: If the software and documentation are being acquired by or on behalf of the U.S. Government or by a U.S. Government prime contractor or subcontractor (at any tier), in accordance with 48 C.F.R. 227.7202-4 (for Department of Defense (DOD) acquisitions) and 48 C.F.R. 2.101 and 12.212 (for non-DOD acquisitions), the government's rights in the software and documentation, including its rights to use, modify, reproduce, release, perform, display or disclose the software or documentation, will be subject in all respects to the commercial license rights and restrictions provided in the license agreement. Check Point, FireWall-1, VPN-1, Provider-1, and SiteManager-1 are trademarks or registered trademarks of Check Point Software Technologies Ltd. ActiveAudit, ActiveView, Aegis, AppManager, Change Administrator, Change Guardian, Compliance Suite, the cube logo design, Directory and Resource Administrator, Directory Security Administrator, Domain Migration Administrator, Exchange Administrator, File Security Administrator, Group Policy Administrator, Group Policy Guardian, Group Policy Suite, IntelliPolicy, Knowledge Scripts, NetConnect, NetIQ, the NetIQ logo, PSAudit, PSDetect, PSPasswordManager, PSSecure, Secure Configuration Manager, Security Administration Suite, Security Manager, Server Consolidator, VigilEnt, and Vivinet are trademarks or registered trademarks of NetIQ Corporation or its subsidiaries in the USA. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies. For purposes of clarity, any module, adapter or other similar material ("Module") is licensed under the terms and conditions of the End User License Agreement for the applicable version of the NetIQ product or software to which it relates or interoperates with, and by accessing, copying or using a Module you agree to be bound by such terms. If you do not agree to the terms of the End User License Agreement you are not authorized to use, access or copy a Module and you must destroy all copies of the Module and contact NetIQ for further instructions. | ||
Template date: March 5, 2010 |