<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP for Endpoints - Deploying on VMView VDIs in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3334856#M4988</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;A id="link_15" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/461515" target="_self"&gt;&lt;SPAN class=""&gt;aswantek&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;I have reviewed your queries.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.) Can a specific group/policy be used instead of the "default" policy as defined in the "Business" pull down. This is quite important in our environment - Yes, you can create specific group/policy from the Policy tab&amp;nbsp; accordingly and enable the features as per your requirements.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.) When creating the VDI template, does it need to connect/register with the AMP cloud? I am not sure why you would register the template as it never is "used" in production except to generate the non-peristent VDIs - Are you mentioning about creating the golden image for Identity persistence here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.) One of the CISCO docs recommends Identity Persistence of By hostname across business be used. Is that reasonable? Its completely based on your environment . Without knowing about your environment we cannot really commend on the same.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.) Also recommended was to NOT install TETRA. Is that reasonable? Its recommended to avoid using TETRA in Server environment and also if there is any other antivirus already running in the system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Jetsy&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2018 07:50:55 GMT</pubDate>
    <dc:creator>Jetsy Mathew</dc:creator>
    <dc:date>2018-02-21T07:50:55Z</dc:date>
    <item>
      <title>AMP for Endpoints - Deploying on VMView VDIs</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3334576#M4987</link>
      <description>&lt;P&gt;Has anyone had any real world experience deploying AMP for Endpoints on Virtual Desktops (VMView to be specific) Our VDI environment uses &lt;STRONG&gt;non-persistent&lt;/STRONG&gt; WIndows 7 and WIndows 10 desktops. The official CISCO/Firepower documentation is a&amp;nbsp; bit vague. I have a few questions:&lt;/P&gt;
&lt;P&gt;1.) Can a specific group/policy be used instead of the "default" policy as defined in the "Business" pull down. This is quite important in our environment.&lt;/P&gt;
&lt;P&gt;2.) When creating the VDI template, does it need to connect/register with the AMP cloud? I am not sure why you would register the template as it never is "used" in production except to generate the non-peristent VDIs&lt;/P&gt;
&lt;P&gt;3.) One of the CISCO docs recommends Identity Persistence of By hostname across business be used. Is that reasonable?&lt;/P&gt;
&lt;P&gt;4.) Also recommended was to NOT install TETRA. Is that reasonable?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3334576#M4987</guid>
      <dc:creator>aswantek</dc:creator>
      <dc:date>2019-03-09T01:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints - Deploying on VMView VDIs</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3334856#M4988</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;A id="link_15" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://supportforums.cisco.com/t5/user/viewprofilepage/user-id/461515" target="_self"&gt;&lt;SPAN class=""&gt;aswantek&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;I have reviewed your queries.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.) Can a specific group/policy be used instead of the "default" policy as defined in the "Business" pull down. This is quite important in our environment - Yes, you can create specific group/policy from the Policy tab&amp;nbsp; accordingly and enable the features as per your requirements.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.) When creating the VDI template, does it need to connect/register with the AMP cloud? I am not sure why you would register the template as it never is "used" in production except to generate the non-peristent VDIs - Are you mentioning about creating the golden image for Identity persistence here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.) One of the CISCO docs recommends Identity Persistence of By hostname across business be used. Is that reasonable? Its completely based on your environment . Without knowing about your environment we cannot really commend on the same.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.) Also recommended was to NOT install TETRA. Is that reasonable? Its recommended to avoid using TETRA in Server environment and also if there is any other antivirus already running in the system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Community-Member lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Jetsy&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 07:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3334856#M4988</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2018-02-21T07:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints - Deploying on VMView VDIs</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3337902#M4989</link>
      <description>&lt;P&gt;We are having issues following the limited documentation provided by CISCO with regard to deploying the AMP connector on VMView VDI desktops. Is there a DEFINITIVE step by step document that goes through this process?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 15:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3337902#M4989</guid>
      <dc:creator>aswantek</dc:creator>
      <dc:date>2018-02-26T15:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints - Deploying on VMView VDIs</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3723214#M4990</link>
      <description>&lt;P&gt;Hi Aswantek, I have successfully deployed Cisco AMP on non-persistent virtual desktops in a XenServer / XenDesktop environment.&amp;nbsp;&amp;nbsp;It took some time to get it to a functional state without filling the write-cache disk and without causing performance issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You first need to make sure you have all the correct exclusions for your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Steps I followed are:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp; Modify the policies for both your Cisco AMP default group and&amp;nbsp;your target group as follows:&lt;/P&gt;
&lt;P&gt;a) Disable Tetra Engine&lt;/P&gt;
&lt;P&gt;b) Enable Identity Persistence with the option "By Hostname across Business"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; Download the connector (with policy) and install onto your imaging machine using command-line install with the switches:&amp;nbsp; &amp;nbsp;/skipdfc 1 /skiptetra 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp; Once installed, stop the Cisco AMP service.&amp;nbsp; Easiest way is from command-line:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;%programfiles%\cisco\amp\x.x.x\sfc.exe -k &amp;lt;protectionpassword&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.&amp;nbsp; Run the following commands to recreate the local.xml file (contains GUID)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;del "%PROGRAMFILES%\Cisco\AMP\local.xml"&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;PRE&gt;&lt;STRONG&gt;echo ^&amp;lt;config^&amp;gt;^&amp;lt;/config^&amp;gt; &amp;gt; "%PROGRAMFILES%\Cisco\AMP\local.xml"&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;5.&amp;nbsp; Shutdown the machine without restarting the service.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 03:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-deploying-on-vmview-vdis/m-p/3723214#M4990</guid>
      <dc:creator>phil.reeves</dc:creator>
      <dc:date>2018-10-11T03:51:30Z</dc:date>
    </item>
  </channel>
</rss>

