19.2 Configuring a Standalone AutoSync Client

Use a standalone AutoSync client when your Core Services computer is not directly connected to the Internet, or when you do not want that computer to download from the Internet. The standalone AutoSync client runs separately from Core Services and queries the AutoSync server for security knowledge updates.

NOTE:While using the standalone AutoSync client, if the Secure Configuration Manager Core Services and the standalone AutoSync client are in two different computers, you must manually copy the patch database to the \Program Files (x86)\NetIQ\Secure Configuration Manager\Core Services\SyncStore folder in the Secure Configuration Manager Core Services computer.

19.2.1 Connecting the AutoSync Client to Core Services

To use a standalone AutoSync client, you need to specify configuration information so the AutoSync client can query and receive updates from the NetIQ AutoSync server. The AutoSync server is a NetIQ Corporation server that provides security knowledge updates when queried by an AutoSync client. In addition to basic AutoSync settings, you can also set up a connection to a proxy Internet server. For more information, see Connecting to the AutoSync Server through Proxy.

To configure Core Services to communicate with a standalone AutoSync client:

  1. Install the Standalone AutoSync client. For more information about installing the client, see the Secure Configuration Manager Installation Guide.

  2. Log on to a console computer and open the console.

  3. On the Tools menu, click AutoSync Wizard.

  4. Click Settings.

  5. Expand AutoSync Client System.

  6. Specify the Host Name/IP address of the AutoSync client computer. Secure Configuration Manager supports IPv4 and IPv6 addresses.

  7. Specify the Port number for communications with the AutoSync client computer.

    NOTE:If Core Services runs in a FIPS-enabled environment, you must set the port to 1621. For more information, see Connecting the AutoSync Client to Core Services in a FIPS-Enabled Environment and Enabling FIPS Communication.

  8. Click OK.

19.2.2 Connecting the AutoSync Client to Core Services in a FIPS-Enabled Environment

If you run Secure Configuration Manager in an environment that uses Federal Information Processing Standard (FIPS) algorithms for secure communication, you must configure the AutoSync client to communicate with Core Services. For more information about FIPS, see Enabling FIPS Communication.

To configure the client for FIPS-enabled communication:

  1. Complete the steps in Connecting the AutoSync Client to Core Services. However, ensure that the port number is set to 1621.

  2. Using an Administrator account, log on to the computer where you installed the standalone AutoSync client.

  3. Run the config.bat file. By default, the file is located in the %Program Files%\NetIQ\Secure Configuration Manager\AutoSync Client\bin folder.

  4. On the Network tab of the NetIQ AutoSync Client Configuration Utility, change Enable FIPS Support to true.

  5. Click OK.

  6. Restart the NetIQ AutoSync Client service.