[KB8580] Deploy ESET Inspect Connector from ESET PROTECT On-Prem on WIndows/macOS/Linux

Issue

Solution

ESET Security Services for ESET Inspect On-Prem and ESET Inspect

ESET offers various security service packages and additional support for these products. Support for ESET Inspect On-Prem and ESET Inspect is limited and managing rules or exclusions are not included without an ESET Security Service package. Contact a sales representative for further assistance.

Prerequisites 


Deploy ESET Inspect Connector from ESET PROTECT On-Prem on Windows/macOS/Linux

  1. Log in to ESET PROTECT On-Prem with proper rights (ESET PROTECT On-Prem Admin rights or ask ESET PROTECT On-Prem Admin to create and deploy connectors for you if you do not have sufficient privileges).

  2. Click Computers and select the check box next to the computer or group.

  3. Click Computer TasksNew Task.

  4. Type a name for a new task in the Name field. The Description field is optional. Select Software Install from the Task drop-down menu and click Continue.

  5. In the Settings screen, choose whether you want to install ESET Inspect Connector from the repository or specify the URL path to the installer.

  6. Select the operating system you want to install ESET Inspect Connector on. For Linux or macOS, skip to step 13 below.

  7. Click Select below Choose package from repository.

  8. Select the radio button next to ESET Inspect Connector and click OK.

  9. Click Select below ESET license, select the check box next to your license and then click OK

    You must activate the ESET Inspect Connector with an ESET PROTECT Enterprise subscription. For more information, see the topic License Management

  10. Select the check box next to I accept the End User License Agreement and acknowledge the Privacy Policy.

  11. Add any custom parameters to the Installation parameters field. You can use the same parameters as in installation from a command line, or you can leave it blank (it will install without Certificate Authority, and the ESET Inspect Server address will be "localhost". You can change this by creating a policy with ESET Inspect Server address and Certificate Authority. To learn how to create a policy in the ESET PROTECT On-Prem, see the topic Policies or ask an ESET PROTECT On-Prem Administrator to create a policy for you).

  12. Click Finish.

  13. For Linux and macOS, you must create a policy to allow ESET Inspect Connector to communicate with ESET Inspect Server:

    1. In the Settings window, select ESET Inspect Connector.

    2. Type the Server Address with the ESET Inspect Server IP address.

    3. Click Edit → Add → Open Certificate Authority. Select the certificate that was used during ESET Inspect Server installation. Click Save.

    4. Click Continue.
       
    5. Click the Assign button and select the computer you want the policy to be applied to in the Assign window. Click Finish.

  14. Rerun the task for any other computers or groups that need to be connected.
Troubleshoot the ESET Inspect Connector installation

ESET Inspect Connector will be visible in the ESET Inspect Web Console immediately after activation and correct policy setting. After a few minutes, you should see the first events sent by connectors.

If you experience any issues, troubleshoot the ESET Inspect Connector


Grant full disk access for macOS deployment

For macOS Mojave (10.14) and later, you will receive the notification "Your computer is partially protected from ESET Endpoint Security for macOS. To access all ESET Endpoint Security for macOS functions, you need to allow Full disk access to ESET Endpoint Security for macOS".

  1. Open Preferences → Security & Privacy  Privacy.

  2. Click Privacy, navigate to Full Disk Access and click the Lock icon.

  3. Scroll the left side menu and click full disk access.

  4. Select the check boxes next to ESET Endpoint Security, ESET Endpoint Antivirus, ESET Management Agent, ESET Inspect Connector and ESET Real-time system protection.

  5. Lock your settings and close the window.

Allow full disk access remotely using MDM

Your computer needs to be enrolled in the MDM server to deploy configuration profiles to those computers.

  1. Download the .plist configuration file.

  2. Deploy the .plist configuration profile file using the MDM server.

  3. Activate ESET Inspect Connector with an "ESET Inspect" license. To do this, create a Product Activation task or contact your ESET PROTECT On-Prem Administrator.