Security Manager for IIS

Release Notes

Date Published: March 2010

 
 

 

Security Manager for Microsoft Internet Information Services (IIS) helps secure your enterprise from internal and external attacks. Security Manager for IIS can monitor your IIS computers to identify intrusion events and perform forensic analysis on log files. The product reports events from FTP and IIS log files on monitored computers running IIS to identify a variety of occurrences.

This module for the Security Manager product includes several new features. This version also improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Security Manager forum on Qmunity, our community Web site that also includes product notifications, blogs, and the Security Manager user group.

This document outlines why you should install this module, lists any installation requirements, and identifies any known issues.

Return to Top

Supported Products

This release supports the following products:

  • IIS 5
  • IIS 6
  • IIS 7
  • IIS 7.5

Return to Top

Why Install This Module?

Security Manager for IIS monitors, analyzes, and consolidates events from log files on monitored Windows computers to detect a variety of occurrences. The following sections outline the key features and functions provided by this version, as well as issues resolved in this release.

Updated Platform Support

This version of Security Manager for IIS provides support for IIS 7.5 on Windows Server 2008 R2 and Windows 7 computers, and includes new computer groups for those Windows versions.

Processing Rules Moved From NetIQ Change Guardian for Windows

In this release, the following event management processing rules have been moved from the NetIQ Change Guardian for Windows product (Change Guardian for Windows) to the Security Manager for IIS module:

  • IIS - FTP Servers
  • IIS - Web Servers

The updated Security Manager for IIS module includes the same rules that were previously in Change Guardian for Windows, but with updated content. Installing Security Manager for IIS installs the updated rules in a new Processing Rule Group, and deletes the old versions of the rules from the Change Guardian for Windows Processing Rule Group.

Module Renamed

In this release, objects in the Security Manager consoles that were previously named "Log Manager for IIS" have been renamed to "Support for IIS," and the IIS archival processing rules have been moved from the previous Log Manager for IIS module to the Support for IIS module.

Return to Top

System Requirements

The following table lists additional requirements for a Windows agent. For more information about agent requirements, see the Installation Guide for NetIQ Security Manager.

Category Requirement
Processor 1.5 GHz Intel Pentium III or equivalent.
Memory 40 MB minimum. The amount of memory usage varies and depends on the environment, including event rate and other factors.
Operating System All supported Windows agent platforms.
Software
  • Ensure you have Security Manager 6.0 or later installed.
  • Ensure you have the latest version of the Security Manager Self-Monitoring module installed. This module is required for optimum functionality of the product.
  • Install the Windows agent on a separate computer from the Security Manager database server or central computer.

Return to Top

Installing This Module

Install the module using the Module Installer utility. If this is the first time you have installed the module, ensure you also add a license. For more information about installing modules, see the Installation Guide for NetIQ Security Manager.

You can verify successful installation of the module in the Module Installer. After the installation completes, verify the Status column indicates the module is current and the module version listed in the Installed Version column is the same as the version in the Available Version column.

After you install the module, run the Configuration Wizard to configure the module to enable FTP logging. For more information about using the Configuration Wizard, see the User Guide for NetIQ Security Manager.

Return to Top

Upgrading This Module

The steps required to upgrade your environment to the latest version of Security Manager for IIS are different depending on what you currently have installed. Select the appropriate upgrade path from the following scenarios.

To upgrade your environment:

  1. If you have NetIQ Change Guardian for Windows and you have already installed this Security Manager for IIS updated module, you should also upgrade Change Guardian for Windows to the latest version (2.0.2) to ensure you have the minimum version of these modules for proper interoperability in your environment.
  2. If you install Change Guardian for Windows 2.0 after installing this Security Manager for IIS updated module, the processing rule groups in Security Manager for IIS will be duplicated in the Change Guardian for Windows processing rule groups. To resolve this issue, reinstall Security Manager for IIS.
  3. After you install this module, run the Configuration Wizard to configure the module to enable FTP logging. For more information about using the Configuration Wizard, see the User Guide for NetIQ Security Manager.

Return to Top

Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

Superseded Release Notes Not Removed on Upgrade

The Security Manager for IIS module replaces the Log Manager for IIS module. However, a known issue exists where Security Manager cannot remove old release notes files when installing updated modules. Release notes are installed by default in the \Program Files\NetIQ Security Manager\OnePoint\Documentation\Release Notes folder on the central computer, but may have been moved or copied to a different location in your environment. After upgrading this module, you should manually delete any superseded release notes in the default folder or in other folders.

Removal of Monitoring Guides

Since monitoring information for updated Security Manager modules is now available in the module release notes, monitoring guides have been discontinued. However, a known issue exists where Security Manager cannot remove old monitoring guides when installing updated modules. To reduce the risk of users referencing outdated monitoring guides, Security Manager now replaces the old monitoring guide in the default documentation folder with a blank monitoring guide. Monitoring guides are installed by default in the \Program Files\NetIQ Security Manager\OnePoint\Documentation\Monitoring Guides folder on the central computer, but may have been moved or copied to a different location in your environment. After installing an updated module, you should manually delete any outdated monitoring guides that were copied or moved to other folders.

Return to Top

Contact Information

Please contact us with your questions and comments. We look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For interactive conversations with your peers and NetIQ experts, become an active member of Qmunity, our community Web site that offers product forums, product notifications, blogs, and user groups.

Return to Top

Legal Notice

Return to Top