Comodo Help
Find the desired product help
Comodo Endpoint Security Manager

Comodo Endpoint Security Manager

Administrator Guide v 2.1

English

Print Help Download Help
The Administrative Console > The Computers Area > Adding Endpoint Computers To ESM > Importing Computers By Automatic Installation Of Agent
  • Introduction To Endpoint Security Manager – SME
    • Software Components And System Requirements
    • Removing Incompatible Products
    • Installing And Configuring The Service
    • Key Concepts
    • Best Practices
    • Quick Start Guide
  • The Administrative Console
    • Logging-in To The Administrative Console
    • The Dashboard Area
      • Adding And Re-configuring Tiles
      • Quick Actions Tiles
      • Policy Status Tile
      • Endpoint Updates Tile
      • Endpoint Infections Tile
      • Connectivity Tile
      • Getting Started Tile
      • System Status Tile
      • License Status Tile
      • Software Tile
    • The Computers Area
      • Adding Endpoint Computers To ESM
        • Importing Computers By Automatic Installation Of Agent
        • Adding Computers By Manual Installation Of Agent And CIS
        • Updating Comodo Software On Managed Computers
      • Creating Endpoint Groups
      • Viewing Endpoints
      • Updating Endpoints
    • The Policies Area
      • Viewing Policies
      • Creating A New Policy
    • The Reports Area
      • Reports Gallery
        • Computer Details Report
        • CIS Configuration Report
        • Computer Infections Report
        • Quarantined Items Report
        • Antivirus Updates Report
        • CIS Log Report
        • Policy Compliance Report
        • Policy Delta Report
        • Malware Statistics Report
        • Top Ten Malware Report
      • Report Explorer
      • Report Settings
    • About
    • Logging Out Of ESM Console
  • How To... Tutorials
    • How To Connect CIS To CESM At The Local Endpoint
    • How To Configure CIS Policies - An Introduction
    • How To Set Up External Access From The Internet
    • How To Install CIS
  • Appendix 1 - The Service Configuration Tool
    • Start And Stop The ESM Service
    • Main Settings
    • Server Certificate
    • Internet And Mail Settings
    • Caching Proxy Settings
    • Viewing Database Event Log
  • About Comodo

Importing Computers by Automatic Installation of Agent

 

The 'Deploy' wizard will install the ESM agent software on network endpoints that can be reached from the ESM service computer. Computers can be imported from Active Directory, from a Workgroup or by specifying individual IP addresses or host names. The wizard also allows to update installed Comodo software in managed computers. See 'Updating Comodo Software on Managed Computers' for more details.

 

To import endpoints

  • Click the 'deploy' tile from the 'computers' area to start the wizard:



Step 1 - Select the Target Type

 

Computers can be imported into ESM in the following ways:

  • Active Directory - imports computers from an Active Directory Domain.

  • Workgroup - imports computers from a Workgroup.

  • Network Address – imports individual computers specified by their IP Addresses or Host Names.

  • Managed Computers - allows to update installed Comodo software in managed computers. See 'Updating Comodo Software on Managed Computers' for more details.

 

 

Note: Targets are contacted by the ESM service computer and its network connection, not the computer running the management console.

 

ESM SME can manage a large number of networked computers so, administrators should repeat this process until all computers for which management is required have been successfully imported.


Note: In most editions, licenses are required for each computer you wish to manage.


Explanations of importing using the sources can be found below in the sections that follow: Import from Active Directory, Import from Workgroup and Import Computers by Network Address.

  • Select the appropriate method to import the computers from Active Directory or Workgroup or select IP Addresses if you want to import computers by specifying their IP addresses or DNS names.



Importing from Active Directory

 

  • Choose 'Active Directory' and move to the next step by clicking the right arrow.

Step 2 - Domain Name

  • Select Current Domain or Custom Domain. Current Domain should be chosen if the ESM service computer is currently a member of the domain you wish to use to target for installation. If you select Custom Domain, you have to enter the details of domain controller, an administrator user name and password.



Domain Import Settings - Table of Parameters

Current Domain
(Selected by default)

Selecting this option will import any computers from the Active Directory domain that the CESM server is a member of. 

Custom Domain

Selecting this option allows the administrator to specify an alternative Active Directory domain from which computers will be imported. Choosing this option requires administrators to specify the following details:

Domain Controller:

Enter the IP address or host name of the Active Directory domain controller from which they wish to import.

User Name:

Enter the user-name of a user with administrative rights to the domain controller.

Password:

Enter the password of the user specified in the 'User Name' field.

  • Swipe to the left or click the right arrow. The wizard moves to next step to select the target endpoints.

 Select Targets

 

The  Active Directory structure for the selected domain will be listed.

 

  • Click the icon to expand or collapse the tree structure

  • Select the target endpoints onto which you wish to install the agent and import into ESM

  • Click the right arrow or swipe left to move to step 3 to select the endpoints

Importing Computers from Workgroup

  • Choose 'Workgroup' and move to the next step by swiping to left or clicking the right arrow.

Step 2 - Workgroup Name

 

The next step is to select the workgroup(s) from which the endpoints are to be imported.

 

 

ESM enables the administrator to specify the workgroup name in two ways:

  •  Find workgroups – Makes ESM to search for the workgroups associated with the network and enables administrator to select the workgroup(s) from which the endpoints are to be imported in the next step.

 

 

Note: The Workgroup is discovered from the local area network attached to the ESM service computer.


    • Select the workgroup(s) and swipe to the left or click the right arrow to move to step 3 to select the endpoints.

  • Specify workgroup manually – allows the administrator to enter the name of the workgroup from which the endpoints are to be imported in the 'Workgroup:' text box.



  • Enter the name of a network workgroup and click the right arrow. The wizard moves to step 3 , to select the target endpoints.

Importing Computers by Specifying Network Addresses

  • Choose 'Network Addresses' and move to the next step by swiping to the left or clicking the right arrow.

Step 2 - Adding IP Addresses

 

The next step is to add the target computers by specifying their IP address(es) or the host names.

 



 

Computers can be added in four ways:

  • Import individual computers by specifying their IP addresses one-by-one - Enter the IP address of the computer and click 'add'. The IP address will be added and displayed below the text box. To add more computers, repeat the process.

  • Import individual computers by specifying their names one-by-one - Enter the name of the target computer as identified in the network and click 'add'. The computer name will be added and displayed below the text box. To add more computers, repeat the process.

  • Import a group of computers by specifying their IP Address range - Enter the IP Address range of the target computers with the Start address and End address separated by a hyphen (e.g. 192.168.111.111-192.168.111.150) and click 'add'. The entered IP address range will be added and displayed below the text box. To add more IP address ranges, repeat the process.

  • Import a group of computers by specifying IP Addresses and Subnet mask – Enter the IP Address and Subnet mask (e.g. 192.168.111.111/24 or 192.168.111.111/255.255.255.0) in the text field and click 'add'. The entered IP address/subnet mask will be added and displayed below the text box. To add more IP address/subnet mask, repeat the process.

    • To remove a computer/computer group added by mistake, select computer(s)/computer group(s) from the text box and click 'remove'.

    • Swipe to the left or click the right arrow to move to the step 3 to select the endpoints.

 

 

Note: IP addresses are specified relative to the ESM service computer.



Step 3 - Targets Summary

 

In this step, all the endpoints included in the previous Step 2 will be displayed.

 


Select the endpoint(s) that you want to deploy the agent and CIS to. You can use the filter option to select the endpoints from the list displayed.

  • Click the filter icon in the 'Target Computer' column header to search for a particular endpoint and click 'Apply'

  • Click the filter icon in the 'IP Address' column header to search for endpoints with particular IP(s) and click 'Apply'

  • Click the filter icon in the 'Status' column header to search for endpoints that are 'Ready' or 'Unavailable' and click 'Apply'

  • Click the filter icon in the 'Is Managed' column header to search for endpoints that are 'Managed' or 'Not Managed' and click 'Apply'

  • Click the right arrow or swipe left to move to the next step

 Step 4 - Credentials

 

The next step is to select the administrative account (login) credentials that will be used to remotely upload the installation package using the administrative share on all target computer(s).

 



Credentials - Table of Parameters

Current User Credentials
(Selected by default)

Selecting this option will install the agent using the credentials of the currently logged -in ESM administrator account in each endpoint

Custom Credentials

Selecting this option allows the administrator to specify an administrative account for installation of the agent. Choosing this option requires administrators to specify the following details: 

User Name:

Enter the user-name of the dedicated network administrator.

Password:

Enter the password of the dedicated network administrator.

  • Click the right arrow or swipe left after entering the credentials to move to the next step

 Step 5 - Checking for Updated Software

 

The next stage 'Packages' displays the version details of ESM Agent and CIS. You can also check for updates of these applications and download it in your server for deployment on to the end-points.

 


 

 



  • Click 'Check for Updates' to find out if any newer version of ESM Agent and CIS are available

  • If any newer versions are available, you can choose to download them to the ESM server by clicking 'Download'

  • Swipe to the left or click the right arrow to move to the next step

 Step 6 - Internet Security


The next step is to choose installation options for Comodo Internet Security (CIS):

 

 

  • Select 'Install Comodo Internet Security' check box if you wish CIS to be installed along with the agent.

 

 

Note: If the option to install CIS is not be selectable, your license for Comodo Endpoint Security Manager did not include CIS software.

  • Select the version of CIS you wish to install on the selected endpoints from the drop-down. Note - the drop-down will be empty the first time ESM is run. You must first click 'Check For Updates' then 'Update' to populate the drop-down as explained the previous Step - Checking for Updated Software.

  • Select whether you want to include all the components (Firewall and Antivirus), Antivirus only or Firewall only from the Components drop-down.

  • Suppress reboot after installation - CIS installation will restart of the endpoints for the installation to take effect. If you do not want the endpoints to be restarted on completion of installation, select this check box. CIS installation will complete but will take effect only on the next restart of the endpoint.

  • Uninstall all incompatible products - Selecting this option uninstalls select third party antivirus, firewall and other desktop security software from the endpoints, prior to the installation of CIS. Performing this step will remove potentially incompatible products and thus enable CIS to operate correctly. Some incompatible products can be detected, but not automatically uninstalled and must be removed manually. If your product is detected but not uninstalled, please consult your vendor’s documentation for precise uninstallation guidelines.

However the following steps will help most Windows users:

    • Click the Start button to open the Windows Start menu

    • Select Control Panel > Programs and Features (Win 7, Vista); Control Panel > Add or Remove Programs (XP)

    • Select your current antivirus or firewall program(s) from the list

    • Click Remove/Uninstall button

    • Repeat process until all required programs have been removed

Click Here to see the full list of incompatible products.

  • Click the right arrow to move to the next step.

Tip:

 

You can also:

  • Install CIS manually onto endpoint computers. Refer to How to Install CIS; and

  • Import stand-alone CIS application pre-installed at the endpoints under the management of ESM. Refer to How to connect CIS to CESM at local endpoint.


 Step 7 – Deployment Progress

  • Click 'Start Deployment'

 

ESM will start installing the agent/CIS on to the selected endpoints and the progress will be displayed.




If any of the selected endpoints have older versions of CIS than the one selected in the previous Step 6, they will be automatically uninstalled and the selected version will be installed.

 

Step 8 – Deployment Complete

 

On completion of installation, the results screen will appear.

 



  • If deployment fails, click on the words 'Deployment Failed' to discover the reason. The info box also contains advice that may remediate the issue.

  • Click Finish icon  or swipe the screen to the left to exit the wizard.

The endpoints selected in Step 3 are now added to ESM and are ready for management through ESM. Refer to the section 'Viewing Endpoints' for more details on how to view the list of imported endpoints.

 

The newly added computers will be added to the default group 'Unassigned'. If this group has been changed to use a specific policy, that policy will be applied after the agent installation is completed. The administrator can create and name new groups according to the structure of the organization and move the added computers into them from 'Unassigned' group. Once created, admins can run tasks on entire groups of computers (such as applying security policy to CIS, running AV scans, deploying agents, updating AV databases and more). Refer to Creating Endpoint Groups for more details.

Terms and Conditions Privacy Policy

© Comodo Group, Inc. 2013. All rights reserved.