Procedure
- On the management computer, open a supported web browser.
- Type the following URL (accept the security certificate
if necessary):
https://<target server IP address>:8445
The Log On screen appears. - Select the Open Configuration Wizard check box.
- Type the following default user name and password:
-
User name: admin
-
Password: imsva
The Configuration Wizard screen appears. -
Configuring System Settings
Procedure
- Click Next.The Local System Settings screen appears.
- Modify the device host name, internal communication port, IP address, and netmask
if necessary.
Also, configure your network settings and set the device system time.
Note
The local system settings take effect immediately when you click the Next > button. If the IP address or time settings are changed, IMSVA will restart. Wait until IMSVA is online and then log on again.
Configuring Deployment Settings
Procedure
- Click Next. The Deployment Settings screen appears.
- Select Parent Device or Child Device.
-
Parent Device: If this is the first device you are setting up, you must select this option. You can configure additional child devices at a later time. Also, decide if you want to use the NTP service.
-
Child Device: If you select this option, specify the parent management console settings. Make sure the user account you use here has full administration rights.
-
Configuring SMTP Routing
Procedure
- Click Next. The SMTP Routing screen appears.
- Specify the incoming message settings. See Specifying Message Rules.
- Specify the message delivery settings. See Specifying Message Delivery Settings.
Configuring Notification Settings
Procedure
- Click Next. The Notification Settings screen appears.
- Under Email Settings, configure the
following:
-
To address(es): Specify the recipient email addresses.
-
Sender's email address: Specify the email address to appear as the sender.
-
Server name or IP address: Specify the Fully Qualified Domain Name (FQDN) or the IP address of the SMTP server that delivers email on the network.
-
SMTP server port: Specify the port number that IMSVA uses to connect to the SMTP server.
-
Preferred charset: IMSVA will use this setting to encode the notification messages.
-
Message header: Specify the text to appear at the top of the notification.
-
Message footer: Specify the text to appear at the bottom of the notification.
-
- Under SNMP Trap, configure the
following:
Note
SNMP Trap is the notification message sent to the Simple Network Management Protocol (SNMP) server when events that require administrative attention occur.-
Server name: Specify the FQDN or IP address of the SNMP server.
-
Community: Specify the SNMP server community name.
-
SNMP version: Select SNMPv1 or SNMPv2c.
Note
Community is the group that computers and management stations running SNMP belong to. To send the alert message to all SNMP management stations, specifypublic
as the community name. For more information, refer to the SNMP documentation. -
Configuring the Update Source
Procedure
- Click Next. The Update Source screen appears.
- Configure the following update settings, which will determine from where IMSVA will receive its component updates
and through which proxy (if any) IMSVA
needs to connect to access the Internet:
Option Description Source Click Trend Micro ActiveUpdate server to receive updates directly from Trend Micro. Alternatively, click Other Internet source and specify the URL of the update source that will check the Trend Micro ActiveUpdate server for updates. You can specify an update source of your choice or type the URL of your Control Manager serverhttp://<IP address of Control Manager server or CQDN>/ Tvcs Download/ActiveUpdate/
, if applicable.Proxy Settings Select the Use a proxy server for pattern, engine, and license updates, Web Reputation queries, certificate validation check, and communication with Cloud Pre-Filter, Trend Micro Email Encryption, and the Time-of-Click Protection service check box and configure the proxy type, server name, port, user name, and passwords.
Configuring LDAP Settings
Procedure
- Click Next. The LDAP Settings screen appears.
- Specify a meaningful description for the LDAP server.
- Complete the following to enable LDAP settings:
- For LDAP server type, select one of the
following:
-
Domino
-
Microsoft Active Directory
-
Microsoft AD Global Catalog
-
Open LDAP
-
Sun iPlanet Directory
-
- To enable one or both LDAP servers, select the check boxes next to Enable LDAP 1 or Enable LDAP 2.
- Specify the names of the LDAP servers and the port numbers they listen on.
- Under LDAP cache expiration for policy services and EUQ services, specify a number that represents the time to live next to the Time to Live in minutes field.
- Under LDAP admin, specify the administrator account,
its corresponding password, and the base-distinguished name. See the following table
for a guide on
what to specify for the LDAP admin settings.
LDAP Server Types
LDAP ServerLDAP Admin Account (examples)Base Distinguished Name (examples)Authentication MethodActive Directory™Without Kerberos:user1@domain.com
(UPN) ordomain\user1
With Kerberos: user1@domain.comdc=domain, dc=comSimpleAdvanced (with Kerberos)Active Directory Global CatalogWithout Kerberos:user1@domain.com
(UPN) ordomain\user1
With Kerberos:user1@domain.com
dc=domain, dc=comdc=domain1,dc=com (if mutiple unique domains exist)SimpleAdvanced (with Kerberos)OpenLDAPcn=manager, dc=test1, dc=comdc=test1, dc=comSimpleLotus Domino™user1/domainNot applicableSimpleSun™ iPlanet Directoryuid=user1, ou=people, dc=domain, dc=comuid=user1, ou=people, dc=domain, dc=comSimple - For Authentication method, click Simple or Advanced authentication. For Active Directory advanced authentication, configure the Kerberos authentication default realm, Default domain, KDC and admin server, and KDC port number.
- Select the Enable encrypted communication between IMSVA and LDAP check box and click Browse to upload a CA certificate file to verify the certificate used by the LDAP server.
- For LDAP server type, select one of the
following:
Configuring Internal Addresses
-
If you are configuring a rule for outgoing messages, the internal address list applies to the senders.
-
If you are configuring a rule for incoming messages, the internal address list applies to the recipients.
Procedure
- Click Next. The Internal Addresses screen appears.
- To define internal domains and user groups, do one of the
following:
-
Select Enter domain from the drop-down list, specify the domain in the text box, and then click >>.
-
Select Search for LDAP groups from the drop-down list. A screen for selecting the LDAP groups appears. Specify an LDAP group name to search in the text box and click Search. The search result appears in the list box. To add it to the Selected list, click >>.
-
Click the Import button to import a text file containing a list of predefined domains.
Note
IMSVA can only import a domain list from a text file (.txt
). Ensure that the text file contains only one domain per line. You can also use wildcard characters to specify the domain. For example,*.com
or*.example.com
. -
Configuring Control Manager Server Settings
Procedure
- Click
Next. The TMCM Server Settings screen appears.
- If you will use Control Manager to manage
IMSVA, do the following:
- Enable the agent (installed with IMSVA by default).
- Next to Server, specify the Control Manager IP address or FQDN.
- Next to Communication protocol, select
HTTP or HTTPS and
specify the corresponding port number. The default port number for HTTP access is 80, and the default port number for HTTPS is 443.
- Under Web server authentication, specify the user name and password for the web server if it requires authentication.
- If a proxy server is between IMSVA and Control Manager, select Enable proxy.
- Specify the proxy server port number, user name, and password.
Activating the Product
Verifying Settings Summary
Procedure
- Click Next. The Review Settings screen appears.
- If the settings are correct, click Finish.To modify any specified setting, click Back and make changes.