Process list information – H3C Technologies H3C Intelligent Management Center User Manual

Page 95

Advertising
background image

79

Type—Type of the PC software control group, Process.

Description—Description of the PC software control group.

Default Action for Check Failure—Default action for the PC software control group when the check
fails, which can be:

{

Monitor—The user is not informed of security problems after going online, and can access the
network. Security check results are recorded in security logs.

{

Inform—The user is informed of security problems after going online. The system prompts the
user to solve problems, and the user can access the network. Security check results are recorded

in security logs.

{

Isolate—The user is informed of security problems after going online. The system prompts the
user to solve problems, and the user can access resources in the isolation area according to the

configured ACL. Security check results are recorded in security logs.

{

Kick out—The user is informed of security problems after going online, fails the authentication,
and is forced to log off. Security check results are recorded in security logs.

A new PC software control group uses the default action you configured for PC software control

group check failure. When you select Global Security Mode in Security Level configuration, the
default action of the PC software control group failure is invalid. You can specify whether Global

Security Mode is used and the default action for PC software control group failure for each PC

software control group.

Service Group—Service group to which the PC software control group belongs.

Process list information

Process Name—Name of the process.

{

For the Windows operating system, the process name must be the same as that in Windows
Task Manager > Processes.

{

For the Linux operating system, the process name must be the same as that after the ps -ef
command is executed.

{

For the Mac OS operating system, the process name must be the same as that after the ps

-awwx -o command is executed.

Alias—Alias of the process. When an access user fails the access control check, the iNode client
uses the alias as the name of the process on the Security Check Result page.

Operating System—Operating system of a process: Windows, Linux, or Mac OS.

Check Type—Select a process check method: Simple, Complex, and MD5. You can configure all of
them on a Windows operating system, but you can configure only Simple on a Linux or Mac OS

operating system.

{

Simple—Used where the process name is the same as the source file name of a program.

{

Complex—Used where the process name is different from the source file name of a program. A
process is generated for each program and typically, the process name is the same as the

source file name of the program. In some cases (for example, if the program name was

changed manually), the process name is different from the source file name.

{

MD5—Used where a process name has no corresponding source file name, or one process
name corresponds to multiple programs. The iNode client determines whether the software

corresponding to the MD5 digest is running on the user endpoint according to the process

name and MD5 digest sent by the EAD server.

Advertising