Total Defense Endpoint & Gateway
Description
Total Defense Endpoint &Gateway integrates comprehensive, multi-layered protection- so you are able to secure your business at every point. This seamless security suite safeguards your PC's, services and mobile devices from diversified threats.
Related Resources
Key Features
Stop SPAM and URL Filtering with CA Gateway Security - Learn more
- End to End Content Protection - provides integrated, multilayered policy-driven email (SMTP) and web (HTTP, FTP) traffic scanning that addresses content threats at the gateway
- Best of Breed Components - offers best of breed anti-virus, anti-spam, inbound and outbound email filtering and web URL filtering.
- Simplified Administration - enables a business to address and manage all email and web content threats remotely.
- Extensive Automated Actions and Alerts - automated, customizable actions, such as "block" and "quarantine," can be defined for each policy so that there is an immediate response when an object matches the policy criteria.
Shut Down Malware with CA Threat Manager - Learn more
- Single Integrated Management - the integrated management console reduces installation complexity, simplifies the system image, reduces support costs and raises efficiency through a common agent.
- Active Protection - harmful executables are stopped dead, spyware, root kits, keyloggers, and other malicious code cannot execute and are promptly removed.
- Bandwidth-saving Signature Updates - MicroDAT antivirus signature updates are less than 500KB in size. This is a more efficient way to distribute signature updates and ensures up-to-the-minute protection while saving valuable bandwidth.
- Flexible Reporting Capabilities - reports can be created based on workstation, date/time, security risk priority and virus/pest category. Automated email alerts of threats detected can be configured to meet specific business needs such as, defining "safe lists' or exclusion files of authorized applications to prevent false alarms.
- Expanded Reporting Capabilities - contains seventy five administrative reports. These reports are displayed in an easy-to-read, graphical format for improved administration and troubleshooting.
- Improved Agent Communications - communications between the CA Threat Manager agent and the web-based management console are initiated by the agent. This allows the agent to regularly "phone home" to the management console where it reports its status and obtains new policy configuration changes for proactive real-time management.
- Support For Microsoft Vista - CA Threat Manager is certified to support Microsoft Vista OS/desktop.
Protect Your Network Devices With CA Host-Based Intrusion Prevention System (HIPS) - Learn more
- Three Threat Protection Technologies in One - CA HIPS blends stand-alone firewall and intrusion detection and prevention capabilities to provide centralized proactive threat protection to counter online threats. This combination offers superior access control, policy enforcement, easy intrusion prevention management and deployment from a central location via a single interface.
- Behavior-based Real-time Protection - System administrators can use key functionality within CA HIPS to learn system behavior and prevent potentially malicious activity. This helps customize environments based on business requirements.
- Enterprise-focused Threat Management Solution - Environments can be protected against security breaches and ensure service continuity by determining what traffic is appropriate, what applications can communicate and even what behaviors and access rights on individual systems will be allowed or blocked. Centralized management functions allow for efficient and effective logging of all relevant events to help with compliance, reporting and investigations.
- USB Port Blocking - USB ports can be locked completely as well as locked out to certain types of USB plug-ins such as; specific make and model USB flash drives, iPod adaptors, NAS devices, etc.
- Centralized Policy Management - CA HIPS offers excellent centrally-managed policy creation, deployment and maintenance to make ongoing administration of security policy across the enterprise easy and flexible. Access and control levels can be determined and applied to the system, groups of users or to an individual user. Policies can also be set to specific users when they are in specific roles or locations.
Product Requirements
The following sections provide information about the system requirements for CA Total Defense.
Note: For the latest information about the release of this product, refer to the CA Support website at http://support.ca.com.
Server Requirements for Small to Medium Sites
The following sections provide requirements for environments with fewer than 1,000 endpoints.
Management Server, Event Server, Report Server
In environments with fewer than 1,000 endpoints, the system running the CA Total Defense server components (Management Server, Event Server, Report Server, and Content Update Redistribution Server) must satisfy the following requirements:
Minimum requirements:
- 3 GHz Pentium 4
- 2 GB RAM
- 40 GB hard drive
Recommended:
- 2.80 GHz Intel Core 2 Duo
- 4 GB RAM
-
100 GB hard drive
Groupware
In environments with fewer than 1,000 endpoints, the system running the Client to manage a Groupware application must satisfy the following requirements:
Minimum requirements:
-
3 GHz Pentium 4
-
3 GB RAM
-
40 GB hard drive
Recommended:
- 2.80 GHz Intel Core 2 Duo
- 4 GB RAM
-
100 GB hard drive
Microsoft SQL Server
If you use Microsoft SQL Server, rather than Microsoft SQL Express, the system hosting the database must satisfy the following requirements:
-
2.80 GHz Intel Core 2 Duo
-
4 GB RAM
- 100 GB hard drive
Server Requirements for Large Sites
In large environments with more than 1,000 endpoints, each of the CA Total Defense server components can be installed on a separate system, in what is known as a Distributed Installation. The following server components must be installed on a system that meets the minimum hardware requirements as described in the following sections. It is highly recommended you use 64 bit Server systems.
Master Management Server
-
3 GHz Dual Quad Core Intel Xeon processors
-
8 GB RAM
-
500 GB hard drive
-
Dual Network Interface Cards (recommended)
Event Server
-
3 GHz Dual Quad Core Intel Xeon processors
-
8 GB RAM
-
500 GB hard drive
-
Dual Network Interface Cards (recommended)
Report Server
- 3 GHz Dual Quad Core Intel Xeon processors
- 8 GB RAM
- 500 GB hard drive
-
Dual Network Interface Cards (recommended)
Management Server Proxy
- 3 GHz Intel Xeon processor
- 4 GB RAM
-
100 GB hard drive
Event Proxy
- 3 GHz Intel Xeon processor
- 4 GB RAM
-
100 GB hard drive
GroupwareMinimum requirements:
-
3 GHz Pentium 4
-
3 GB RAM
-
40 GB hard drive
Recommended:
- 2.80 GHz Intel Core 2 Duo
- 4 GB RAM
-
100 GB hard drive
Microsoft SQL Server
- 3 GHz Intel Xeon processor
- 4 GB RAM
-
100 GB hard drive
Disk Space Requirements
A Standalone Installation of the Management Server, Event Server, Report Server, and Content Update Redistribution Server on the same host system uses 2 GB of disk space once all components are installed. This does not account for growth of the database based on policies, events, reports, and so on.
Client Requirements
Each system running the Client must satisfy the following requirements:
-
2.80 GHz Pentium 4 CPU
-
1 GB RAM
-
40 GB Hard Drive
Port Requirements for Microsoft SQL Server
If you are implementing a Distributed Installation, where CA Total Defense server components and the Microsoft SQL Server may all be installed on different systems, the following two ports should be open at the firewall on the system where the MS SQL Server resides:
- UDP 1434 for SQL Server Browser
-
TCP 1433 for the default SQL Server port or an alternative port set by the Database Administrator
Usually the firewall is configured at the program level (not the port level), however in a Distributed Installation scenario, "SQL Server Browser" and "SQL Server" services should be allowed on the firewall where the MS SQL Server resides.
Display Requirements
The minimum required resolution for a system running the Management Console or Client is 1024x768.
Additional Applications
This section describes additional applications required to run CA Total Defense.Note: For the latest information about the release of this product, refer to the CA Support website at http://support.ca.com.
Database Requirements
The Management Server and Event Server each use their own separate database and require the use of one of the following databases.
Small to Medium Sites
In environments with fewer than 1,000 endpoints:
-
Microsoft SQL Express 2005 Service Pack 2
-
Microsoft SQL Express 2008
-
Microsoft SQL Server 2005 Service Pack 2
-
Microsoft SQL Server 2008
Large Sites
In environments with more than 1,000 endpoints:
- Microsoft SQL Server 2005 Service Pack 2
-
Microsoft SQL Server 2008
Note: Since only a copy of policy and endpoint data is located on the Management Sever Proxy and disk utilization will be lighter, you may choose to install Microsoft SQL Express on systems hosting a Management Server Proxy.
Report Server Requirements
To print reports, a valid printer must be configured on the Report Server machine and you must have the following applications installed on that machine:
-
Adobe Acrobat Reader must be installed on the Report Server machine to print reports in PDF format.
- Microsoft Office Word 2003 (minimum) must be installed on the Report Server machine to print reports in Microsoft Word format.
Other Applications and Plug-ins
Systems running any of the CA Total Defense server or proxy components must have Internet Information Services (IIS) installed and enabled, as described in the following list:
- On Windows Server 2003, you must use IIS 6
- On Windows Server 2008, you must use IIS 7
- On Windows 2008 Server R2, you must use IIS 7.5
-
On Windows 7, you must use IIS 7.5
Systems running any of the CA Total Defense server components must also have the following applications:
-
ASP 2.0
- .NET 2.0 if the CA Total Defense Client is installed on Windows 2003
- .NET 3.5 Service Pack 1 on all other platforms
- Adobe Flash 9 or 10 (to use the Management Console UI)
Web Browsers
The Management Console supports the following web browsers:
-
Microsoft Internet Explorer 6 or higher
-
Mozilla Firefox 2.0 or higher
Operating System Support
The following sections provide information about the operating system requirements for CA Total Defense. Note: For the latest information about the release of this product, refer to the CA Support website at http://support.ca.com.
Server OS Support
The CA Total Defense server components (Management Server, Event Server, Report Server, and Redistribution Server) are supported on the following operating systems:
- Windows 2003 Server SP 2 (32/64-bit
-
Windows 2008 Server (32/64-bit)
-
Windows 2008 Server R2 (64-bit)
-
Windows 7 (32/64-bit)
Server Virtual Environment Support
The CA Total Defense server components (Management Server, Event Server, Report Server, and Redistribution Server) are supported in the following virtual environment:
-
VMware ESXi 4.0 (32/64 bit)
-
VMware Workstation 6.5.x (minimum) (32/64-bit)
- Citrix XenServer 5.0x (minimum) (32/64-bit)
Note: If you are installing a server component on a virtual machine (VM), ensure that the VM itself meets the minimum requirements documented in these release notes. If the VM does not meet the minimum requirements for the server component, you may experience performance problems. In addition, if a machine hosts multiple VMs, ensure that it has adequate system resources so that a VM hosting the Management Server is not competing with other VMs for those resources.
Client Operating System Support
The CA Total Defense Client (Client) is supported on the following operating systems:
-
Windows XP Professional SP 2 and SP 3 (32-bit)
-
Windows XP Professional SP 2 (64-bit)
-
Windows 2003 Server SP 2 (32/64-bit)
-
Windows Vista with SP 1 (32/64-bit)
-
Windows 2008 Server with SP 2 (32/64-bit)
-
Windows 2008 Server R2 (32/64-bit)
-
Windows 7 (32/64-bit)
Client Virtual Environment Support
The Client is supported in the following virtual environments:
-
VMware Workstation 6.5.x (minimum) (32/64-bit)
-
VMware ESXi 4.0 (32/64 bit)
-
Citrix XenServer 5.0x (minimum) (32/64-bit)
Client Groupware Support
The Client is supported in the following Groupware environments:
-
IBM Lotus Notes/Domino 8 and 8.5 for Windows (32/64-bit)
-
Microsoft Office SharePoint Server 2007 (32/64-bit)
-
Microsoft Office SharePoint Portal Server 2003 (32 bit)
-
Microsoft Exchange 2003 and all service packs (32/64 bit)
-
Microsoft Exchange 2007 and 2010 and all service packs (64-bit)
-
NetApp Filer 7.2.5 (supports only Windows XP Professional SP3 32-bit)
CA Gateway Security:
CA Gateway Security r8.1 supports the following operating systems:
- Windows Vista - supported under the following conditions; if CleverPath Reporter and Ingres are not selected during the CA Gateway Security r8.1 installation for use with the CA Gateway Security r8.1 Outlook Plug-in Desktop Option.
Not supported under the following conditions; for use with ADCP or for use with the Role Based package - Windows 2008 - supported under the following conitions; if CleverPath and Ingres are not selected during the CA Gateway Security r8.1 installation for use with the CA Gateway Security r8.1 Plug-in Desktop Option
Not supported under the following conditions; for use with ADCP or for use with the Role Based package - Windows 2003 Server (Standard or Enterprise Edition), SP1, SP2
- Windows XP Professional SP1, SP2
- Windows 2000 SP4
CA Gateway Security r8.1 supports the following databases:
- Microsoft SQL Server 2000
- Microsoft SQL Server 2005
-
Microsoft SQL Server 2005 Express Edition
Recommended Hardware, One Computer
The following are the recommended hardware requirements to install all CA Gateway Security 8.1 components on a dedicated computer:
- Platform: 2.8 GHz Dual Processor Intal Xeon Server
- Memory: 2 GB RAM
- Disk Szie: 73 GB ULTRA Wide SCSI hard drive
- Media: CD-ROM
- Network Interface: One standard network interface card (NIC)
Minimum Hardware, Multiple Computers
If you choose a distributed installation, install the following components on individual computers:
- SMTP Content Manager
- HTTP/FTP Content Manager
- Central Reporter, Quarantine Manager and Manager Console (install on same computer)
- ADCP Agent
- ADCP Agent Distrubuted Source Client (Server Side)
- ADCP Agent Distributed Source Client (Client Side)
The following are minimum hardware requirements for each component installed on individual computers:
SMTP Content Manager Computer
- Platform: Pentium IV, 1.3 GHz CPU
- Memory: Minimum of 1 GB RAM
- Disk Size: 5.0 GB free disk space
- Media: CD-ROM
- Domain Name services: Domain Name services
- Network Interface: one standard network interface card (NIC)
HTTP/FTP Content Manager Computer
- Platform: Pentium IV, 1.3 GHz CPU
- Memory: Minimum of 1 GB RAM
- Disk Size: 5.0 GB free disk space
- Media: CD-ROM
- Network Interface: One standard NIC
Central Reporter, Quarantine Manager, Manager Console Computer
- Platform: Pentium IV, 1.3 GHz CPU
- Memory: Minimum of 1 GB RAM
- Disk Size: 5.0 GB free disk space
- Media: CD-ROM
- Domain Name services: Domain Name services (used by the Quarantine Manager)
- Network Interface: One standard NIC
ADCP Agent
- Platform: Pentium III, 1.0 GHz CPU
- Memory: Minimum of 1.0 GB RAM
- Disk Size: 10.0 GB IDE hard drive, with at least 2 GB free disk space
- Network Interface: One standard NIC
ADCP Agent Distributed Source Client (Server Side)
- Platform: Pentium III, 1.0 GHz CPU
- Memory: Minimum of 1.0 GB RAM
- Disk Size: 10.0 GB IDE hard drive, with at least 2 GB free disk space
- Network: One standard NIC
ADCP Agent Distributed Source Client (Client Side)
- Platform: Pentium III, 500 MHz CPU
- Memory: Minimum of 256 MB RAM
- Disk Size: 500 MB free disk space
- Network Interface: One standard NIC


