User guide

9
All policy files (*.lcp) are stored on the LCE server in XML format in the /opt/lce/daemons/policies directory.
If clients are being upgraded, their configuration files may be imported as a policy file after conversion by the LCE Conf
Converter.
Details for configuring policy files are included in their respective client type sections, described later in this document.
LCE Client Manager Interactive Mode
The tool is launched by an authorized user on the LCE server by running /opt/lce/daemons/lce_client_manager
from the server command line. When run without any options (interactive mode), a menu is presented to guide the user in
managing the clients.
# /opt/lce/daemons/lce_client_manager
**********************************************
* LCE Client Manager 1.0
* Please select an option from the menu below
**********************************************
[g] Grant authorization to a client or clients to connect to LCE
[r] Revoke a client or clients access to connect to LCE
[d] Display clients by policy assignment
[p] Display available policies
[a] Add a new policy
[c] Copy a policy
[m] Modify an existing policy
[s] Assign a policy to a client or clients
[v] Assign a client or clients to a new LCE server
[i] Import a file as a policy
[n] Assign a custom sensor name to a client or clients
[x] Remove a client
[q] Exit
lce_client_manager >>
To select an option, enter the letter that corresponds with its description. As each option is selected, a submenu is offered
that prompts for further information to complete the selected task.
[g] Grant Authorization to a Client
After a LCE Client is initially installed on a machine, configured to direct traffic to the LCE server, and started, the LCE
Client Manager must authorize the connection. This is done by selecting the “goption from the menu.
After selecting the “g option from the menu, the user is asked a yes or no question to authorize all clients or select the
client to authorize from a list. Selecting “no” will display a list of all unauthorized clients attempting to make a connection.
Entering the IP address or index number (ID number) of the client to authorize will write the information to the Policy Map
file upon exiting the LCE Client Manager utility. Select 0to return to the main menu. Selecting “yes” will cause all clients
pending authorization to be written to the Policy Map upon exiting the utility. After a confirmation message is written to the
terminal, the user is returned to the main menu.
Exit the utility with the “qmenu option to save the policy file to disk and activate the changes.
[r] Revoke Authorization to a Client
There are situations where client access to the LCE server needs to be revoked. This is done by selecting theroption
from the menu.