05.08.2013 Views

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Introducing <strong>Trend</strong> <strong>Micro</strong> Control Manager<br />

when agent sits behinds a NAT device (or TMCM server sits behind a NAT device)<br />

since the connection can only route to the NAT device, not the product behind the<br />

NAT device (or the TMCM server sitting behind a NAT device). One common<br />

work-around is that a specific mapping relationship is established on the NAT device<br />

to direct it to automatically route the in-bound request to the respective agent.<br />

However, this solution needs user involvement and it does not work well when<br />

large-scale product deployment is needed.<br />

The MCP deals with this issue by introducing a one-way communication model.<br />

With one-way communication, only the agent initiates the network connection to the<br />

server. The server cannot initiate connection to the agent. This one-way<br />

communication works well for log data transfers. However, the server dispatching of<br />

commands occurs under a passive mode. That is, the command deployment relies on<br />

the agent to poll the server for available commands.<br />

HTTPS Support<br />

The MCP integration protocol applies the industry standard communication protocol<br />

(HTTP/HTTPS). HTTP/HTTPS has several advantages over TMI:<br />

• A large majority of people in IT are familiar with HTTP/HTTPS, which makes it<br />

easier to identify communication issues and find solutions those issues<br />

• For most enterprise environments, there is no need to open extra ports in the<br />

firewall to allow packets to pass<br />

• Existing security mechanisms built for HTTP/HTTPS, such as SSL/TLS and<br />

HTTP digest authentication, can be used.<br />

Using MCP, Control Manager has three security levels:<br />

• Normal security: Control Manager uses HTTP for communication<br />

• Medium security: Control Manager uses HTTPS for communication if HTTPS<br />

is supported and HTTP if HTTPS is not supported<br />

• High security: Control Manager uses HTTPS for communication<br />

One-Way and Two-Way Communication Support<br />

MCP supports one-way and two-way communication.<br />

B-5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!