Installing McAfee Groupshield 5.0

OutHouse

Lifer
Jun 5, 2000
36,410
616
126
Ill be doing this tomorrow on a brand new box that is replacing a POS HP. I have a lot of done a lot of research and have a few docs printed so i think I am prepared

if anybody has done this, can you give me any pointers or *watch out* for's???
 

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
Sure.

Make sure nobody is connected to the server. Disable all of the exchange services.

After you install, change the settings so it only scans Selected Extensions, only have it download the signatures once a night during off hours. Otherwise it may run a rescan of the store and lock up the server if people are connected to it. Also whatever AV you're using for realtime scan (not for mail scanning), add the exchange partition to it's exclusion list because everytime Groupshield scans a file it's going to flip out the other AV and could corrupt the store.

edit:
I don't remember if the Groupshield also handles the realtime scanning - if it does, don't have it scan network shares and don't choose the option for Deleting infected files.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
To help with that question, GroupShield doesn't do the system-wide real-time scanning, it was intended to be teamed up with NetShield back in the day, or VirusScan Enterprise 7.x or 8.0i today (or whatever you want to use).

You can have GroupShield block certain extensions outright, like the obvious ones (.exe, .bat, .com, .scr, .pif and so on). If your crew is prone to sending around big frivilous PowerPoint slideshows for their own amusement, you can add .PPS too :evil:
 

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
Originally posted by: mechBgon
To help with that question, GroupShield doesn't do the system-wide real-time scanning, it was intended to be teamed up with NetShield back in the day, or VirusScan Enterprise 7.x or 8.0i today (or whatever you want to use).

You can have GroupShield block certain extensions outright, like the obvious ones (.exe, .bat, .com, .scr, .pif and so on). If your crew is prone to sending around big frivilous PowerPoint slideshows for their own amusement, you can add .PPS too :evil:

I didn't think it did, but haven't look at it for several years. If you don't have a mail filter at the perimeter of the network, then I 2nd adding blocks for executable attachments. I never do it within the network because we need to email scripts and software updates from time to time, but we have another mail filter just for inbound email.
 

OutHouse

Lifer
Jun 5, 2000
36,410
616
126
Originally posted by: SagaLore
Sure.

Make sure nobody is connected to the server. Disable all of the exchange services.

After you install, change the settings so it only scans Selected Extensions, only have it download the signatures once a night during off hours. Otherwise it may run a rescan of the store and lock up the server if people are connected to it. Also whatever AV you're using for realtime scan (not for mail scanning), add the exchange partition to it's exclusion list because everytime Groupshield scans a file it's going to flip out the other AV and could corrupt the store.

edit:
I don't remember if the Groupshield also handles the realtime scanning - if it does, don't have it scan network shares and don't choose the option for Deleting infected files.

Would uploading the INI file from the current groupshield setup take care of all those settings?