The following are the requirements for TMCM Policy Management.
The products that currently support the Policy Management feature are listed inside the TMCM console.
To view the list of products:
- Open the TMCM console.
- Go to Policies > Policy Resources > Policy Template Settings. In the Product Support section, you will see the list of supported products.
- Point the mouse to the "i" icon to show the product versions.
Products not listed here will not be able to support Policy Management.
For most products, once they are registered to TMCM, they are automatically listed into the Managed Servers list. However, some products have to be manually entered in the Managed Servers list.
Verifying if servers are included in the Managed Servers list:
- Open the TMCM console.
- Go to Administration > Managed Servers.
- On the Server Type dropdown, select the product you want to manage. As of TMCM 6.0 Patch 4, the list of Managed Servers are as follows:
Some products are automatically added as long as they appear in the TMCM console product tree.
Examples of these products are:
- Officescan Client
- Officescan Data Loss Prevention
- Interscan Messaging Security Virtual Appliance (DLP only)
- Interscan Web Security Virtual Appliance (DLP only)
- ScanMail for Exchange (DLP only)
- Deep Discovery Inspector
For other products, the Administrators have to manually add them. If they have been added, they will appear in the list.
Adding servers to the Managed Servers list
- Open the TMCM console.
- Go to Administration > Managed Servers.
- On the Server Type dropdown, select the product you want to add. In the example below, we chose Mobile Security for Enterprise.
- Click the Add button.
- Enter the necessary details:
- Server: product console web link
- Display Name: display name of the server
- User name: username to access the product console
- Password: password to access the console
- Click Save. You will see the details listed in the Managed Servers list.
For Trend Micro Security for Mac, the web link should be:
https:<IP address or fully-qualified domain name (FQDN) of the OSCE server>:<OSCE https port>/
The username and password should be the account used to log in to the OSCE server console.
If the product appears in the product tree, then the product must not be in the New Entity folder. Entities under the New Entity folder will not be deployed a policy.
To confirm if the product is in the New Entity folder:
- Open the TMCM console.
- Click Directories > Products.
- Click the Directory Management button.
- Verify that the product does not appear in the New Entity folder.
Policy Management will not take effect for products that are in the New Entity folder. Drag the products to a new folder for Policy Management to take effect.
For products that appear in the product tree, two-way communication must be working.
For the following products using Web Service API to communicate with the Control Manager, skip this requirement.:
- Trend Micro Endpoint Encryption
- Trend Micro Mobile Security
- Trend Micro Security for Mac
- Intrusion Defense Firewall
For two-way communication to work:
- The TMCM server must be able to connect to the product console using the IP address, hostname, or FQDN specified during product installation.
- When there is a firewall in between, TMCM must be able to connect to the port of the product console.
- For products reachable only via a Network address translation (NAT) IP, the NAT IP must be configured in the product console settings as illustrated below:
Click image to enlarge.
The NAT IP address and port must be specified in the Two-way Communication Port Forwarding section.
For the following products using Web Service API to communicate with the Control Manager, skip this requirement:
- Trend Micro Endpoint Encryption
- Trend Micro Mobile Security
- Trend Micro Security for Mac
To check if SSO is enabled:
- Open the TMCM console.
- Go to the Products tab.
- On the left panel, select the product.
- Click Configuration > Single Sign-on.