Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Content:
Performing a New Installation
11
Agent configuration. 11
Add service account .. 24
Agent Deployment
27
30
30
31
35
41
LANDesk Queries
41
LANDesk Reporting . 42
Software Distribution ..
47
53
62
63
3. Read the Terms and Conditions, then if you agree check the box that says I accept the terms in this license
agreement then select continue.
2
9. Enter the server name of the database server in the Server field.
10. Enter the name of the database in the Database field.
11. Enter the username and password in the User name and Password field.
12. Once the data is entered, click Test Connection to test database connectivity or Select Continue.
13. Next, you are prompted for the location where you would like LANDESK Management Suite installe d.
14. Choose the default location or if desired, change it and select Continue and the Management Suite 9.6
software summary is shown.
5
16. When the installation finishes, you will be prompted to reboot. Select Reboot.
17. Activate your core once the core server has finished rebooting.
Now your LANDesk server is ready, run the console from program and login using your domain account.
After the installation and activation for the core server the first thing we will do is (Unmanaged devices
discovery).
As shown we configured scan for Bahri Domain and DMZ IP range to scan all the DMZ subnets .
5. After the configuration you just need to click (Scan now) and the result will appear as shown below.
Now we have list of our unmanaged machines and we are ready to configure and deploy the LANDesk Agent.
10
3. Click on (+) icon to create new configuration and choose (New Windows Agent configuration).
11
4. From the start page you will give a name for this agent and choose the feature you want to install with
agent.
12
13
14
Click new for new configuration and give a name for the settings and choose the feature to enable it
during the remote control session.
The indicator setting is related to agent and remote control and the recommended settings are:
15
The permission option is to give the support engineer the appropriate permission to access the
machines.
16
17
Then save the settings and use it with the agent settings.
7. For patch and compliance setting for windows patching and vulnerability scan here you only need to
choose the prober settings to be applied with the agent , for all clients we use the (Bahri Default
Distribution and Patch settings) and for the test group we will use (Bahri Workstation Disteibution and
Patch Testing ).
Now we will show how to create these settings:
18
19
Give a name for your setting and check the Network settings.
For scan option we will set the scan for our own definition group (Workstation Microsoft Patches)
and about autofix option you must uncheck for default setting but you need to check it for testing
group setting.
20
21
22
23
Now you need to add domain admin account to system to be able to deploy the agent on clients machines.
To add this account do the following:
1. Click configure tab from the head of window.
2. Choose services.
3. Click scheduler then click change login from the services window.
24
4. Click add to add new account then fill the info required.
25
26
B. Agent Deployment.
When the agent configuration is ready we need to distribute it for all clients because LANDesk Management
Suite is agent base system.
To deploy the agent follow these steps:
1. Open the agent configurations and right click the agent configuration you want to deploy to on clients
machines and choose (Schedule agent deployment).
That will create schedule task with the agent configuration name.
2. Now we need to add the desired machines from the unmanaged machines list to the task.
Open the unmanaged device discovery and select the desired machine.
27
3. Now drag and drop the selected machines to the task was created.
4. Now right click the task and start it to start the deployment.
When the agents installed successfully you can view all managed machines through you console as shown in below
example.
28
If you right click any managed machine you will find many features like Inventory and remote control.
29
30
2. In the OS Provisioning tool, click New Template then select Capture Template.
31
32
33
34
2. In the OS Provisioning tool, click New Template then select Capture Template.
35
4. Open the created template and validate the data and modify its actions if needed.
36
37
38
2. Press F8 when the option comes up when the computer is booted. The PROXY IP address should be the
IP address of the PXE Representative for the subnet.
4.
5. Enter your credential when prompted then Select the template which created previously and click OK.
39
6.
Wait for the image to be captured. When the capture is complete the computer will restart.
You can use the same previous steps for OS deployment by choosing the deployment template.
40
41
3. Choose the items you are building the query for and create the condition from them and choose the
information you need to know about the machines which comply with your condition and save the query
with meaningful name.
LANDesk Reporting.
The LANDesk reporting is very powerful and helpful tool, LANDesk already has predefined report can be used
and LANDesk give the ability to create your custom report based on your need.
You can find the predefined report from Report as the following:
1. After login to the LANDesk console click on Reporting/Monitoring then click on reports.
2. Expand the stander report from the report sup window.
42
43
From these report you can find many useful reports may help you in your work and they will help you to save
time and effort to collect any information related to your network.
If these reports did not meet your need you can build your own report based on your query which built before.
To create custom reports do the following:
1. Open the reports widows as explain before.
2. Right click My reports.
3. Select new report.
44
4. Give a name for the report and click on Load from LDMS query.
45
46
Software Distribution
One of the very helpful tool or feature comes with LANDesk Management Suite is software distribution
which will help the support team to handle all request for new software and application installation or
upgrade.
LANDesk support many methods of packages (MSI packages, Executable packages and batch file).
Each package need to be handled separately and tested many times and on different platform to make sure
this package will work fine with LANDesk systems.
For example we will show how create the following package.
A. Package preparation
1. Firstly we need to copy the original package.
2. Click Distribution tab and select Distribution packages from distribution menu and finally select
Public packages to create a new package and make it available for all support team and all LANDesk
users.
NOTE: In this example we will work on Adobe reader executable file and show how to create installation
package with silent installation feature.
47
3. Click the (+) icon to create new package then select the type of package you want to create, in our
example we will use new executable package.
48
5. Click on install/uninstall options and enter the required command parameters for the installation.
49
NOTE: The commands parameters are different from package to another and some packages have
complex commands you can review these parameters by using the (/Help or /?) parameters.
6. From Additional files we will add all related file needed to complete the installation successfully.
50
NOTE: Not all packages have additional files so we need to use this only with the packages have multiple
files for installation.
7. Finally we need to give a domain admin account to be used for installation as shown.
8. Click Save to save the package and now the package is ready to be distributed.
51
B. Package Deployment.
To deploy any saved package you only need to follow these steps.
1. Right click the saved package you want to deploy.
2. Select Create schedule task.
That will create schedule task for package deployment with the same name of the package.
52
3. Form the managed devices list select the machine you want to deploy the package on it then drag
and drop it to the task.
53
From the download window we will chose the patches we want to download and select the language then
specify where to save the downloaded definitions and create schedule task for patches and definitions
download.
54
Select the required Definition types and Languages for the environment. Microsoft Windows Vulnerabilities are
the most commonly downloaded vulnerability type. Microsoft Windows Vulnerabilities contain the patches for
the Windows Operating Systems as well as the patches for common applications for the Windows Operating
System such as Adobe Reader and Microsoft Office. Check the box for Put new definitions in Unassigned
group so that all of the definitions are downloaded to the (Unassigned) folder.
When you set the settings click apply to save them then click (Schedule download) to create download task.
55
Enter the time and the repeating period and click save when you finish.
56
6. Copy the content of Scan group to (Patch Deployment (All Patches)) group.
57
58
Drag computers from All Devices in the Console and drop them on the Security Scan task (Patch and
Compliance Scan) in the Scheduled tasks window. Drag all computers that the Security scan needs to be
run on to the task.
Right-click the Security Scan task (Patch and Compliance Scan) in the Scheduled tasks window and click
Start now to immediately run the Security Scan task. Or, select Properties to schedule a time for the
Security Scan to run. It is recommended to run the Security Scan task during non-business hours because
the Security Scan will impact the performance of the computer.
59
When the task finish the LANDesk Patch manager will have full info about the needed patches for all machines
and not all machines have autofix option the patches will be installed on test machines only. You need to
monitor these machines foe two weeks then create repair settings for all machines if all patches are approved.
8. Crate repair task for Patch Deployment (All Patches) group.
Right-click Patch Deployment (All Patches) group and select the Repair option.
Verify that the correct scan and repair setting is shown in the Scan and repair settings box.
Click OK to create the repair task.
Drag and drop the desired machines you want to patch.
Start the task.
That will repair all machines and make your environment without vulnerability.
You can use the following diagram as quick reference for patching process.
60
None Approved
Patches
Approved Patches
61
Appendix A:
System requirements.
Software Requirements:
The install language of the Microsoft Windows Server 2008 R2 should match the language LANDesk install
language and the language of all Remote Consoles.
Hardware recommendations:
62
Appendix B:
LDMS Database creation
Open SQL Server Management Studio. Start | All Programs | Microsoft SQL Server 2008 | SQL Server
Management Studio.
Create a new database by right clicking on the Database folder choosing New Database
63
64
Change Authentication to SQL Server then enter the login name and password.
Uncheck Enforce password policy.
The Login Password to be used by the LANDesk Database install must be 8 characters minimum with
numbers and letters.
Click on the Server Roles page.
65
Check sysadmin if doing an LDMS database upgrade. Leave public checked for both upgrades or new
database installs. In the event of an upgrade, the sysadmin role can be removed from the login once the
upgrade succeeds.
Click on the User Mapping page.
66