cancel
Showing results for 
Search instead for 
Did you mean: 

Endpoint Security Firewall of Linux will not pull rules from ePO

I am attempting to centrally manage Red Hat 6.10 firewall rules with a 5.9.1 ePO server.  I have installed McAfee Endpoint Security Firewall for Linux 10.6.3 on the Red Hat machine.  The McAfee agent and Endpoint Security Threat Prevention are communicating with the ePO.  However, I cannot get the Red Hat machine to pull the firewall policies that I have created in ePO.  Any idea what I am missing?  I cannot seem to find any documentation on this process, so I am going into this blind.  Where are the base McAfee firewall rules being pulled from?

7 Replies
Highlighted
McAfee Employee patrakshar
McAfee Employee
Report Inappropriate Content
Message 2 of 8

Re: Endpoint Security Firewall of Linux will not pull rules from ePO

starting point will be to look at the McAfee Endpoint Security for Linux License Extension 

version. have you upgraded the extension to 10.6.3 or later?

Can you please let me know how exactly you are finding that policies not enforced properly?

Re: Endpoint Security Firewall of Linux will not pull rules from ePO

The log shows "Failed to get license from McAfee agent.  Setting license status as paid".  "Received registration acknowledgement from ESP".  

Where can I find the licensing information in ePO or on the host itself?

 

When I run mfw on the local Red Hat machine, I get the default McAfee policies.  However, the policies that I created under the rules tab do not propagate to endpoints like the Windows ones do.  I can manually create local policies on the Red Hat machine though.     

McAfee Employee patrakshar
McAfee Employee
Report Inappropriate Content
Message 4 of 8

Re: Endpoint Security Firewall of Linux will not pull rules from ePO

This is very old error. https://kc.mcafee.com/corporate/index?page=content&id=KB88495

Can you follow the workaround mentioned in the article and confirm the state?

Do you see proper agent to server communication from that machine?

Re: Endpoint Security Firewall of Linux will not pull rules from ePO

I followed the steps in the workaround.  I am now seeing the following output:

INFO TpAgentAdaptor [6764] McAfee Agent is running with mode: 1 (0-Unmanaged, 1-ePO Managed, 2-ePO Cloud Managed, 3-Unknown)

 

INFO Preference [6764] Product is using a valid license.


INFO ScanFactoryBroker [6764] Starting Scan Factory before starting the OAS Scan Manager

The McAfee agent is communicating regularly with the ePO server.  Threat Prevention virus-definitions are even updating automatically.  However, anytime I attempt to run a client task, I get the following error message: 

Run client task message expired

The firewall still will not pull its policies and settings from the ePO server. 

McAfee Employee ktankink
McAfee Employee
Report Inappropriate Content
Message 6 of 8

Re: Endpoint Security Firewall of Linux will not pull rules from ePO

Hi @mgran2019 Which McAfee Agent version are you using?  Could you please install the McAfee Agent Linux 5.6.2.209 version and retest this?

Re: Endpoint Security Firewall of Linux will not pull rules from ePO

Hi @ktankink 

My agents are running version 5.6.1.157.  My organization only provides access to this version and earlier releases.  I am not seeing 5.6.2.209 on our repository.  Is there a location that I can download it directly from McAfee? 

McAfee Employee ktankink
McAfee Employee
Report Inappropriate Content
Message 8 of 8

Re: Endpoint Security Firewall of Linux will not pull rules from ePO

Hi @mgran2019 Products can be downloaded from the McAfee Download Grant site (https://www.mcafee.com/content/enterprise/en-us/downloads/my-products/downloads.html) if you have your Support grant number, or from the ePO Server Software Manager.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community