4 Replies Latest reply on Mar 13, 2012 2:01 AM by headless

    Unable to install Agent Handler

      Hi

       

      I have had problems trying to install an Agent Handler in our DMZ.; I get the "Server did not detect a compatible ePo server..." error when installing.

      All the required ports are open as confirmed by our security team. I contacted McAfee phone support and I wasl told to configure the install parameters for the server as follows:

       

      ePO Server: <our SQL server>,1433

      ePO Server Port: leave as default 8443

       

      I questioned using the SQL server but I was told this is way it is done, it failed. I did try using our ePO server without port 1433 and with port 8443 but it still failed.

      From the server in the DMZ I  tried telnetting to both the SQL server on port 1433 and our ePO server on port 80 and both failed.

      I then telnetted to our WSUS server on port 80 and it worked, also from the DMZ.

       

      The host file on the Agent Handler server in the DMZ has the details for both the SQL server and the ePO server.

       

      So I decided to try installing the Agent Handler on the internal network as a way of testing the install and I still get the same error.

       

      Internally, from a client pc I can telnet to the ePO server on port 80.

      Internally, from the ePO server I can telnet to the SQL server on port 1433.

       

      My question is, if I can telnet to the ePO and SQL server why does the installation of the Agent Handler on the internal network fail?

       

      Cheers

       

      Chris

        • 1. Re: Unable to install Agent Handler
          tao

          Can you post the AH error log?  Also, not sure if you have this already but here's the Agent Handler Config:

           

          http://www.mcafee.com/us/resources/white-papers/wp-agent-handler-epo-4-5.pdf

           

          Default Port Setup

          AHPorts.PNG

          • 2. Re: Unable to install Agent Handler

            Hi Tao

             

            Thanks for the reply and my apologies in getting back to you so late.

             

            I have managed to install AH on the internal network. Turns out I was using the wrong version - 4.05 instead of 4.06. The ports have been opened as per the diagram and according to the security team, the telnet tests are going from the server I am trying to install AH on in the DMZ to the firewall but are not getting through. One of the security tchs is coming to see me today to check out the firewall I know of plus one or two others that are also involved tah I was not aware of.

             

            I will keep this discussion updated.

             

            Cheers

             

            Chris

            • 3. Re: Unable to install Agent Handler
              hem

              If the installation is failing then please post the log files if you can.

              • 4. Re: Unable to install Agent Handler

                Hi Tao

                 

                At last I have a solution!! Seems there was a rule missing from our firewall and this was correctd and I was able to telnet to the ePO and SQL servers.

                 

                I still couldn't connect to the SQL server on install, kept telling me "it couldn't connect with the current credentials"

                The account I was using to connect to the SQL server was a dbo on the ePO database so it had rights however, to get it to connect I had to give the account dbcreator rights to the database.

                I assume that is because it had to write tothe database as part of the AH install; I have left it at that even after the install. I may try and remove the dbcreator right to see if it still connects okay.

                 

                Tanks for your help.

                 

                Cheers

                 

                Chris