There are a number of general settings to configure for a VMware vCenter Protect Agent policy. You must configure these settings before installing the agents on the desired target machines.
See an icon in the notification area |
The agents can be configured to run invisibly on each target machine, or you can elect to install an icon in the notification area of each machine that provides the users of the machines a certain amount of control over the service. If you want to allow users to control certain aspects of the VMware vCenter Protect Agent service, enable this option. Users will be able to launch the client-based program by double-clicking the icon. Note: The notification area icon will not be visible on the target machine for any currently logged on user until the next time the user logs on, or if the user starts the VMware vCenter Protect Agent program using the Windows Start menu. |
Perform manual operations |
Enables a user on a target machine to manually initiate an operation such as a patch or threat scan. |
Cancel operations |
Enables a user on a target machine to stop an operation that is in progress. |
Manage quarantine |
Enables a user to delete or restore items contained in the quarantine directory. The quarantine directory is used to temporarily store files suspected of containing threats (spyware, viruses, etc.). |
Temporarily suspend Active Protection |
Enables a user on a target machine to temporarily suspend Active Protection for 5, 15, 30, or 60 minutes. |
Disable Active Protection |
Enables a user on a target machine to permanently disable the Active Protection service. If a user permanently disables Active Protection the service will remain running but no Active Protection tasks will be performed. If this check box is not enabled, the user will still have the option to temporarily suspend Active Protection for 5, 15, 30, or 60 minutes. |
Turn off notification when Active Protection blocks known risks |
Enables a user on a target machine to turn off the notification messages that are issued whenever the Active Protection process detects a known bad risk and places a file into quarantine. |
Logging Level |
Specify the amount of logging you want the agent to perform. The options are:
Logging is typically only necessary when performing troubleshooting tasks. The log files will reside on each agent machine.
|
Maximum log size |
Specify the maximum log size. Specifying a very large log size will enable you to record a longer log history but it will of course require more system resources. The default value is 5 MB. If the log file becomes full a new log file is opened and logging will continue. If the second log file becomes full, the first log file is deleted and a new log file will be created. This means there will always be a maximum of two log files on the console. |
Check-In Interval |
Specifies how often the agents will check in with the console. At each check-in the agent refreshes its license and looks for any policy changes. It also checks if it is assigned a distribution server. If it is assigned a distribution server it will use it to download the latest scan engines and XML data files. If it is not assigned to a distribution server then the agent downloads the engines and data files from the Web. If an agent machine is offline when the next check-in interval occurs, the agent will immediately check in when network connectivity is restored. Note: Agent licenses must be refreshed at least once every 45 days or they will expire.
|
Engine and Data Download Location |
Specifies if a distribution server will be used by the agents when downloading the latest scan engines and XML data files. The agents will look for updated files every time they perform a scan. The available options are:
Note: If the agents are being used to deploy custom patches then you must specify the use of a distribution server. This is because there is no download URL for custom patches, meaning the agents cannot pull the custom patches from a vendor and must therefore be able to pull them from one or more distribution servers. Also Note: If you will be configuring an agent policy that contains a threat task it is strongly recommended that you use a distribution server. The threat definition file is rather large and using a distribution server to store the file will greatly improve the download performance for your agents.
|
Network
|
Note: Only shared credentials are contained in this list. If the credential you are looking for is not listed it probably means it is not defined as a shared credential. See Defining Credentials for information on how to share a credential. |
Save and Update Agents |
Saves all changes to the policy file and stores it on the console. Also updates any agent machines that are currently assigned this policy as follows:
The Agent Policy Editor will be closed. |
Cancel |
Indicates you want to exit the Agent Policy Editor without saving your most recent changes. A "Do you want to save your changes?" prompt will appear that gives you a second chance to save your changes. If you click Yes the policy will be saved and the associated agents updated (the same as Save and Update Agents). If you click No the Agent Policy Editor will be closed without saving your changes. |