Product guide

Task
For option definitions, click ? in the interface.
1
In the McAfee ePO console, click Menu | Software | Software Manager.
2
On the Software Manager page under Product Categories, click Software Not Checked In | Licensed.
3
Select McAfee ePO Deep Command 2.1 from the products list, select McAfee ePO Deep Command Gateway Server,
then click Download.
4
Extract the package contents to a temporary location on your server in the DMZ where the Agent
Handler is installed.
5
Double-click the SetupAGS.exe file, then in the Welcome page, click Next.
6
Select the license type, accept the license agreement, then click OK.
The Destination Folder page displays a default folder where the software installation files are copied.
7
Click Change to specify a folder, or Next to use the default location.
8
Use the default ports for AMT listen, SOCKSv5 Proxy Listen, and HTTP Proxy Listen, or change the ports, as
required, then click Next.
If the ports are changed, update the Stunnel configuration file (stunnel.conf) with these port
numbers. See Configure Stunnel for instructions.
9
Click Install, then click Finish.
Generate certificates for Stunnel
Generate certificates from McAfee ePO Deep Command Root CA to use with Stunnel configuration.
Before you begin
Install Stunnel on the DMZ server where the Agent Handler or McAfee ePO is installed.
See http://www.stunnel.org/ to download and obtain more information on the software.
Provide published DNS name and IP address in the Agent Handler Settings page. These
settings allow an agent to connect to the correct, published, network interface of an
Agent Handler. See the McAfee ePO documentation for detailed instructions.
Task
1
In the McAfee ePO console, click Menu | Configuration | Server Settings.
2
In Setting Categories, select Intel
®
AMT Credentials, then click Edit.
3
Click Generate Certificate Set, select the Agent Handler, then click OK.
Only Agent Handlers that are enabled and have a Public DNS entry are displayed.
4
Save the <Agent_Handler_FQDN>.zip file to your computer, then extract its content.
The .zip contains these files:
CN_McAfee_ePO_Deep_Command_Root.crt — Public Root Certificate
<Agent_Handler_FQDN>.crt — Signed certificate
<Agent_Handler_FQDN>.key — Private key
Setting up your environment for Remote Access
Generate certificates for Stunnel
5
McAfee ePO Deep Command 2.1.0 Product Guide
59