Security and software updates
To ensure maximum protection you must keep your Software and Security Rules and Patterns up to date. The Updates tab on the Administration > System Settings page allows you to set the location where Deep Security Manager checks for updates. To see the status of current updates, go to the Administration > Updates page.
Primary Security Update Source
- Trend Micro Update Server: Connect to the default Trend Micro Update Server.
- Other Update Source: If you were given an alternative source for updates, enter the URL here including "http://" or "https://". (SSL connections are supported.)
- Allow Agents/Appliances to download Pattern Updates from Primary Update Source if Relays are not available: If an agent or applianceThe Deep Securty Agent and Deep Security Virtual Appliance are the components that enforce the Deep Security policies that you have defined. Agents are deployed directly on a computer. Appliances are used in VMware vSphere environments to provide agentless protection. They are not available with Deep Security as a Service. cannot communicate with the Relay, it will download pattern files directly from the Trend Micro Update Server (or other update source).
- Allow Agents/Appliances to download Pattern Updates when Deep Security Manager is not accessible: Normally, the Deep Security Manager instructs Agents or Appliances to download Pattern Updates. When this option is selected, even though an Agent cannot communicate with the Deep Security Manager, it will continue to download updates from its configured source.
- Automatically Apply Rule Updates to Policies: With this option selected, newly downloaded Security Rule Updates will automatically be applied to Deep Security Policies. If this option is not selected, you will have to manually apply downloaded Rule Updates to Policies from the Administration > Updates > Security page by clicking on the Apply Rules to Policies button.
By default, changes to Policies are automatically applied to computers. You can change this behavior by opening a Computer or Policy editorYou can change these settings for a policy or for a specific computer. To change the settings for a policy, go to the Polices page and double-click the policy that you want to edit (or select the policy and click Details). To change the settings for a computer, go to the Computers page and double-click the computer that you want to edit (or select the computer and click Details). > Settings > General window and changing the Automatically send Policy changes to computers setting in the Send Policy Changes Immediately area.
- Allow supported 8.0 and 9.0 Agents to be updated: Select this option if you require support for agents on Windows 2000, AIX, HP-UX, or Solaris. By default, Deep Security Manager does not download updates for Deep Security Agent 9.0 and earlier, because for most platforms, Deep Security Manager 10.2 does not support them (see System requirements). This reduces disk usage because older agents and appliances have a different update package format. However, those platforms do not have newer agent versions, and therefore require the older package format.
- Download Patterns for all Regions: If you are operating in multi-tenancy mode and any of your tenants are in other regions, select this option. If this option is deselected, a relay will only download and distribute patterns for the region (locale) that Deep Security Manager was installed in.
- Use the Primary Tenant Relay Group as my Default Relay Group (for unassigned Relays): By default, the primary tenant gives other tenants access to the its relays. This way, tenants don't need to set up their own relays. If you don't want other tenants to share the primary tenant's relays, deselect this option and create separate relays for other tenants.
If this option is deselected, when you click Administration > Updates > Relay Groups, the relay group name will be "Default Relay Group" rather than "Primary Tenant Relay Group".This setting appears only if you have enabled multi-tenant mode.
Alternate software update distribution server(s) to replace Deep Security Relays:
Deep Security Relays are usually used to host Agent Software Updates. However, you can optionally use your own web servers to distribute Agent software packages. To use your own web servers for software distribution, enter the URL to the directory hosting the software.