<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cupfighter.net &#187; McAfee</title>
	<atom:link href="http://www.cupfighter.net/index.php/tag/mcafee/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cupfighter.net</link>
	<description>A blog by Schuberg Philis colleagues</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:27:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Get rid of Event ID 5156: The Windows Filtering Platform has allowed a connection</title>
		<link>http://www.cupfighter.net/index.php/2009/10/get-rid-of-event-id-5156-the-windows-filtering-platform-has-allowed-a-connection/</link>
		<comments>http://www.cupfighter.net/index.php/2009/10/get-rid-of-event-id-5156-the-windows-filtering-platform-has-allowed-a-connection/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 12:47:49 +0000</pubDate>
		<dc:creator>Cupfighter</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[Event ID 5156]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[windows vista]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=568</guid>
		<description><![CDATA[When you install McAfee on Windows Server 2008, and probably Windows Vista also, you can get a lot of messages in your security log. Like this one: Event ID 5156 means that WFP has allowed a connection. When most connections are allowed your security log will fill up very fast. You can disable Object Access [...]]]></description>
			<content:encoded><![CDATA[<p>When you install McAfee on Windows Server 2008, and probably Windows Vista also, you can get a lot of messages in your security log. Like this one:</p>
<p><img class="alignnone size-full wp-image-569" src="http://www.cupfighter.net/wp-content/uploads/2009/10/ID-5156.jpg" alt="ID 5156" width="455" height="317" /></p>
<p>Event ID 5156 means that WFP has allowed a connection. When most connections are allowed your security log will fill up very fast.</p>
<p>You can disable Object Access auditing but then you&#8217;ll miss other events which might be of interest. So, instead, let&#8217;s just disable Success Auditing for Filtering Platform Connections. It&#8217;s not possible to disable auditing subcategories with a policy or other GUI tool, but I found out that you can enable and disable specific subcategories with a special command-line tool: Auditpol.exe, which is included with Windows Vista and Windows Server 2008. I used the following command:</p>
<p>auditpol /set /subcategory:&#8221;Filtering Platform Connection&#8221; /success:disable /failure:enable</p>
<p>As you can see this disables Success auditing for the Filtering Platform Connection subcategory.</p>
<p>For more info check out this article:</p>
<p><a href="http://msdn.microsoft.com/en-us/library/bb309058(VS.85).aspx">http://msdn.microsoft.com/en-us/library/bb309058(VS.85).aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/10/get-rid-of-event-id-5156-the-windows-filtering-platform-has-allowed-a-connection/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Infamous McAfee 8.7 Error 1920, service McShield failed to start</title>
		<link>http://www.cupfighter.net/index.php/2009/09/infamous-mcafee-8-7-error-1920-service-mcshield-failed-to-start/</link>
		<comments>http://www.cupfighter.net/index.php/2009/09/infamous-mcafee-8-7-error-1920-service-mcshield-failed-to-start/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 15:41:30 +0000</pubDate>
		<dc:creator>Jan Jacob Bos</dc:creator>
				<category><![CDATA[McAfee]]></category>
		<category><![CDATA[certificates]]></category>
		<category><![CDATA[Error 1920]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=548</guid>
		<description><![CDATA[Solved issue to install McAfee 8.7]]></description>
			<content:encoded><![CDATA[<p>I could not install McAfee 8.7 on all server in several high secure environments. I got the infamous McAfee 8.7 Error 1920, service McShield failed to start. Also got the 5004 error from McLogEvent when I did a custom install and did not start McShield during install. I already tried all options from <a href="https://kc.mcafee.com/corporate/index?page=content&amp;id=KB59863">McAfee Support</a> (especially changing imagepath for mfeapfk.sys mfeavfk.sys, mfebopk.sys in the registry looked promising since I already had the latest version of the patch) after it didn&#8217;t work out, I&#8217;ve logged an incident at McAfee. I went up to 3rd level support, in the end it turned out that if I disabled all policies it worked. That made support think the issue was solved. That&#8217;s not true of course. Therefore I did some further investigation to find out which setting it was. (I cannot afford to switch off all securtiy settings of course). It turned out I had to change the following setting:<br />
<em>Client computers can trust the following certificate stores</em><br />
change from:<br />
<em>Enterprise Root Certification Authorities</em><br />
to:<br />
<em>Third-Party Root Certification Authorities and Enterprise Root Certification Authorities</em></p>
<p>With the first option, only a very small list of certificates is available in the &#8220;trusted root certification authorities&#8221; list of certificates. After I&#8217;ve changed the policy there are plenty certificates in the list.</p>
<p>McAfee has added new drivers (Device manager, show hidden Devices, Non-Plug and Play Drivers to show them). One of these, the McAfee Validation Trust  Protection Service (mfevtps), needs one of the root certificates in the extended list as shown above.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/09/infamous-mcafee-8-7-error-1920-service-mcshield-failed-to-start/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

