Announcing the availability of RealSecure SiteProtector X-Press 
Update (XPU) enhancements to support Internet Scanner XPU 6.10 
and Internet Scanner XPU 6.11. For additional information, please refer 
to the supporting Readme files attached.

The available X-Press Updates for SiteProtector include the following: 

* SiteProtector XPU Version: May 20, 2002 (SP_XPU_20020520)
  Applicable Versions:  Applicable to SiteProtector 1.2
  ===========================================================
  This SiteProtector XPU supports Internet Scanner XPU 6.10. SiteProtector
1.2 
  must be installed before this XPU can be applied (SiteProtector 1.0 with
Service 
  Release 3). 

* SiteProtector XPU Version: May 22, 2002 (SP_XPU_20020522)
  Applicable Versions: Applicable to SiteProtector 1.2
  ===========================================================
  This SiteProtector XPU supports Internet Scanner XPU 6.11. SiteProtector
1.2 
  must be installed before this XPU can be applied (SiteProtector 1.0 with
Service 
  Release 3). 

For more information on this release, please contact the following:
 
* For additional product information:
   - SiteProtector:
http://www.iss.net/products_services/enterprise_protection/rssite_protector/
   - Internet Scanner:
http://www.iss.net/products_services/enterprise_protection/vulnerability_ass
essment/ 
   - X-Press Updates: http://www.iss.net/db_data/xpu/IS.php 
   - Jamie Lau, X-Press Updates Product Manager, [EMAIL PROTECTED] 
 
* For sales information:
   - [EMAIL PROTECTED]
   - 888-901-7477 (North America)

* For education, consulting and support information, including ISS SecureU 
  training on SiteProtector and Internet Scanner:
   - Customer Support - [EMAIL PROTECTED], 888-447-4861
   - CSG West - John Franklin, Business Development Manager, 
     [EMAIL PROTECTED], 949-916-8037
   - CSG East - Joel Williams, Business Development Manager, 
     [EMAIL PROTECTED], 404-236-3971
   - SecureU training - 
     http://education.iss.net/course_descriptions/iss_courses/advanced.php, 
     888-263-8739.

=============================================================
SiteProtector X-Press Update Release Notes - May 20, 2002
=============================================================

SiteProtector XPU Version: May 20, 2002 (SP_XPU_20020520)
Applicable Versions:  Applicable to SiteProtector 1.2


**PLEASE READ COMPLETELY BEFORE INSTALLING THE XPU**


1. X-Press Update Contents 
=============================================================

This SiteProtector XPU supports Internet Scanner XPU 6.10. 
SiteProtector 1.2 must be installed before this XPU can be applied 
(SiteProtector v 1.0 with Service Release 3). 

SiteProtector XPUs update the SiteProtector console and Site DB 
to reflect new exploits and vulnerabilities.  XPUs also contain 
new and modified Help files for these security issues 
and updated policies for sensors.

SiteProtector XPUs are sequential, and applying an XPU
requires the installation of previous SiteProtector XPUs not 
already included on the Site. It may also be necessary for Service 
Releases to also be installed prior to applying an XPU.

It is also possible to apply sensor XPUs through SiteProtector.

ISS advises installing all X-Press Updates to ensure
your systems are up to date for the latest vulnerabilities
and attacks.


2. Installing X-Press Updates
=============================================================

2.1 Using SiteProtector to Install X-Press Updates

By default, the SiteProtector update mechanism intermittently
checks the main ISS Web site (https://www.iss.net) for a file 
called XPU_1_2.xml.  This XML file contains information regarding
all available product updates.  When a new update is indicated,
SiteProtector updates the database with the relevant 
information so that SiteProtector console displays that the new 
update is available.  By default, XPU_1_2.XML is downloaded every 
24 hours.

The first time you apply an update, it is automatically
downloaded to a repository on the RealSecure application server and applied
remotely to the components you've chosen.  Subsequent updates will
attempt to use the application server's cached copy of the update.

Applying X-Press Updates requires administrative status.
To apply X-Press Updates, right-click on a sensor or a group of
sensors, and then select "to apply update."  You must apply
XPUs to both the sensors and the SiteProtector console before the new checks
and signatures can go into effect.  However, applying the updates 
to sensors will result in the appropriate updates automatically being
downloaded and applied to the SiteProtector console.

When an X-Press Update is scheduled on more than 20 assets,
the sensor controller performs the requested operation
on 20 assets in parallel before moving to another block of
20 assets. This operation is repeated until all the assets 
are configured.


2.2 Automating Application of X-Press Updates

You can automate the updating of components by creating
a recurring update schedule for those components and by ensuring
that a new XPU_1_2.XML is scheduled to be downloaded intermittently.
You can customize this automation by group.

It is also possible to automate application of updated policies to 
sensors.  

Network Sensor customers should note that it is necessary to 
manually install the Network Sensor Policy Group File before 
the policy can be edited to enable the new signatures.

Be aware that automating installation of updates will apply any
available new updates; this is not limited to X-Press Updates only.


2.3 Manually Downloading and Applying X-Press Updates

If your SiteProtector system cannot access the ISS Web site and a 
proxy server is not in place to provide this visibility, 
you can download the updates from the ISS Download Center 
and manually apply them.  

The easiest way to do this is to manually retrieve 
https://www.iss.net/XPU_1_2.xml and save it in the
Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu
directory.  You must then download the Internet Scanner Policy update
into the \Program Files\ISS\RealSecure SiteProtector\Application Server
\XPU\Update\Site_Protector\ directory.  You will also need to 
download all Internet Scanner XPUs (6.1-6.10) and place these files in 
the \Program Files\ISS\RealSecure SiteProtector\Application Server
\XPU\Update\RealSecure directory.  A tool to automate that process is forthcoming.
If you do that, instruct the SiteProtector console not to go to the web 
any more; edit the properties for SP Core, pick the X-Press and Product Update
tab, and uncheck the "Auto Download" box.  

The following files are relevant to this XPU. 
- Readme
- Internet Scanner Policy Update for XPU 6.10
- Internet Scanner XPU 6.10 (sensor update)


2.4 Customizing SiteProtector Updates

Navigate to your SiteProtector host asset and choose SP Core, then
Edit Properties, the X-Press and Product Update tab and select
interval, Web site, and other properties.


2.5 Using a Proxy Server to Download XPUs

SiteProtector uses the proxy settings from Internet Explorer on the
Application Server host to download XPUs.  To modify these,
navigate to Start, Settings, Control Panel, Internet Options,
Connections, LAN Settings, Proxy Server, and then add the proxy server
host and port.

Note that you must use a proxy server that does not require 
authentication.  If your proxy server requires authentication, you
must manually download XPUs from the ISS Download Center, as discussed above.

IMPORTANT
The proxy settings in IE are associated with a user name.  For SiteProtector
to read them, you have to modify the service to log in as that user name.
Find the service "RealSecure SiteProtector Sensor Controller Service," 
right-click and choose properties, click the log-on tab, and enter the user
information for a user with the proxy settings configured.


3. Updating Policies
=============================================================

Updated policies are contained in the SiteProtector XPU.
Once you have applied XPUs to both the sensor(s) and to 
SiteProtector, you must push the policy to the sensors.
It is possible to automate this.

Default RealSecure policies will have new signatures added, but
not enabled.  You must customize the policies to enable
the new signatures.

Default Internet Scanner policies will have new checks enabled
as appropriate for each default policy.

If you utilize custom policies, the new checks and signatures 
will be added to your policy, but not automatically enabled.  
Customize your custom policies to enable new checks
and signatures.


4.  Updating SiteProtector Help Files
=============================================================

Once you apply the SiteProtector XPU, new and revised Help files
will be placed in a directory on the RealSecure sensor controller.  If you
have chosen a default installation for the SiteProtector console, the Help
files will be located in the following directory:
\Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu\Install\HelpFile 
Updates.
This will be true for every SiteProtector XPU.

If you have chosen a non-standard implementation for the SiteProtector console,
and have placed Help files in a different location, you will 
need to move the Help files delivered in the XPU from the above
directory to your customized location.


5. Updating the Security Fusion Module
=============================================================

Applying a SiteProtector XPU automatically updates the
security fusion module so that it can correctly correlate
new and updated checks and signatures.


6. Customer Support
=============================================================

Technical Support is available 24 hours a day through the 
Americas Location. All other locations are open Monday through 
Friday, 9:00 am to 6:00 pm, during their local time, excluding 
ISS published holidays.

Telephone (in the U.S.): +1-888-447-4861
Telephone (outside the U.S.): +1-404-236-2700
Email: [EMAIL PROTECTED]


7.  Required Information for Bugs
==============================================================

If you encounter a problem with this release, please make notes that 
are as detailed as possible about the following:

 * Build versions
 * Sensor and console host configurations
 * Network deployment
 * Network traffic rates
 * Network traffic characteristics
 * Specific failure symptoms or undesirable behavior

This information helps us reproduce the problem and resolve it as
quickly as possible.
=============================================================
SiteProtector X-Press Update Release Notes - May 22, 2002
=============================================================

SiteProtector XPU Version: May 22, 2002 (SP_XPU_20020522)
Applicable Versions:  Applicable to SiteProtector 1.2


**PLEASE READ COMPLETELY BEFORE INSTALLING THE XPU**


1. X-Press Update Contents 
=============================================================

This SiteProtector XPU supports Internet Scanner XPU 6.11. 
SiteProtector 1.2 must be installed before this XPU can be applied 
(SiteProtector v 1.0 with Service Release 3). 

SiteProtector XPUs update the SiteProtector console and Site DB 
to reflect new exploits and vulnerabilities.  XPUs also contain 
new and modified Help files for these security issues 
and updated policies for sensors.

SiteProtector XPUs are sequential, and applying an XPU
requires the installation of previous SiteProtector XPUs not 
already included on the Site. It may also be necessary for Service 
Releases to also be installed prior to applying an XPU.

It is also possible to apply sensor XPUs through SiteProtector.

ISS advises installing all X-Press Updates to ensure
your systems are up to date for the latest vulnerabilities
and attacks.


2. Installing X-Press Updates
=============================================================

2.1 Using SiteProtector to Install X-Press Updates

By default, the SiteProtector update mechanism intermittently
checks the main ISS Web site (https://www.iss.net) for a file 
called XPU_1_2.xml.  This XML file contains information regarding
all available product updates.  When a new update is indicated,
SiteProtector updates the database with the relevant 
information so that SiteProtector console displays that the new 
update is available.  By default, XPU_1_2.XML is downloaded every 
24 hours.

The first time you apply an update, it is automatically
downloaded to a repository on the RealSecure application server and applied
remotely to the components you've chosen.  Subsequent updates will
attempt to use the application server's cached copy of the update.

Applying X-Press Updates requires administrative status.
To apply X-Press Updates, right-click on a sensor or a group of
sensors, and then select "to apply update."  You must apply
XPUs to both the sensors and the SiteProtector console before the new checks
and signatures can go into effect.  However, applying the updates 
to sensors will result in the appropriate updates automatically being
downloaded and applied to the SiteProtector console.

When an X-Press Update is scheduled on more than 20 assets,
the sensor controller performs the requested operation
on 20 assets in parallel before moving to another block of
20 assets. This operation is repeated until all the assets 
are configured.


2.2 Automating Application of X-Press Updates

You can automate the updating of components by creating
a recurring update schedule for those components and by ensuring
that a new XPU_1_2.XML is scheduled to be downloaded intermittently.
You can customize this automation by group.

It is also possible to automate application of updated policies to 
sensors.  

Network Sensor customers should note that it is necessary to 
manually install the Network Sensor Policy Group File before 
the policy can be edited to enable the new signatures.

Be aware that automating installation of updates will apply any
available new updates; this is not limited to X-Press Updates only.


2.3 Manually Downloading and Applying X-Press Updates

If your SiteProtector system cannot access the ISS Web site and a 
proxy server is not in place to provide this visibility, 
you can download the updates from the ISS Download Center 
and manually apply them.  

The easiest way to do this is to manually retrieve 
https://www.iss.net/XPU_1_2.xml and save it in the
Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu
directory.  You must then download the Internet Scanner Policy update
into the \Program Files\ISS\RealSecure SiteProtector\Application Server
\XPU\Update\Site_Protector\ directory.  You will also need to 
download all Internet Scanner XPUs (6.1-6.10) and place these files in 
the \Program Files\ISS\RealSecure SiteProtector\Application Server
\XPU\Update\RealSecure directory.  A tool to automate that process is forthcoming.
If you do that, instruct the SiteProtector console not to go to the web 
any more; edit the properties for SP Core, pick the X-Press and Product Update
tab, and uncheck the "Auto Download" box.  

The following files are relevant to this XPU. 
- Readme
- Internet Scanner Policy Update for XPU 6.11
- Internet Scanner XPU 6.11 (sensor update)


2.4 Customizing SiteProtector Updates

Navigate to your SiteProtector host asset and choose SP Core, then
Edit Properties, the X-Press and Product Update tab and select
interval, Web site, and other properties.


2.5 Using a Proxy Server to Download XPUs

SiteProtector uses the proxy settings from Internet Explorer on the
Application Server host to download XPUs.  To modify these,
navigate to Start, Settings, Control Panel, Internet Options,
Connections, LAN Settings, Proxy Server, and then add the proxy server
host and port.

Note that you must use a proxy server that does not require 
authentication.  If your proxy server requires authentication, you
must manually download XPUs from the ISS Download Center, as discussed above.

IMPORTANT
The proxy settings in IE are associated with a user name.  For SiteProtector
to read them, you have to modify the service to log in as that user name.
Find the service "RealSecure SiteProtector Sensor Controller Service," 
right-click and choose properties, click the log-on tab, and enter the user
information for a user with the proxy settings configured.


3. Updating Policies
=============================================================

Updated policies are contained in the SiteProtector XPU.
Once you have applied XPUs to both the sensor(s) and to 
SiteProtector, you must push the policy to the sensors.
It is possible to automate this.

Default RealSecure policies will have new signatures added, but
not enabled.  You must customize the policies to enable
the new signatures.

Default Internet Scanner policies will have new checks enabled
as appropriate for each default policy.

If you utilize custom policies, the new checks and signatures 
will be added to your policy, but not automatically enabled.  
Customize your custom policies to enable new checks
and signatures.


4.  Updating SiteProtector Help Files
=============================================================

Once you apply the SiteProtector XPU, new and revised Help files
will be placed in a directory on the RealSecure sensor controller.  If you
have chosen a default installation for the SiteProtector console, the Help
files will be located in the following directory:
\Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu\Install\HelpFile 
Updates.
This will be true for every SiteProtector XPU.

If you have chosen a non-standard implementation for the SiteProtector console,
and have placed Help files in a different location, you will 
need to move the Help files delivered in the XPU from the above
directory to your customized location.


5. Updating the Security Fusion Module
=============================================================

Applying a SiteProtector XPU automatically updates the
security fusion module so that it can correctly correlate
new and updated checks and signatures.


6. Customer Support
=============================================================

Technical Support is available 24 hours a day through the 
Americas Location. All other locations are open Monday through 
Friday, 9:00 am to 6:00 pm, during their local time, excluding 
ISS published holidays.

Telephone (in the U.S.): +1-888-447-4861
Telephone (outside the U.S.): +1-404-236-2700
Email: [EMAIL PROTECTED]


7.  Required Information for Bugs
==============================================================

If you encounter a problem with this release, please make notes that 
are as detailed as possible about the following:

 * Build versions
 * Sensor and console host configurations
 * Network deployment
 * Network traffic rates
 * Network traffic characteristics
 * Specific failure symptoms or undesirable behavior

This information helps us reproduce the problem and resolve it as
quickly as possible.

Reply via email to