not able to "ignore" Win 2008 sp2 (Full Version)

All Forums >> [Networking & Security] >> GFI LANguard



Message


tk -> not able to "ignore" Win 2008 sp2 (24.Jun.2009 1:15:57 PM)

...haven't had an issue with ignoring patches till I just tried ignoring Windows 2008 SP2. Keeps showing up after rescan. Any way I can check where the ignore list is stored?




DrewE -> RE: not able to "ignore" Win 2008 sp2 (24.Jun.2009 4:38:04 PM)

You can disable detection of this patch instead of using the Patch Ignore list as well. This can be done by configuring the "Scan Profile"




mblinde -> RE: not able to "ignore" Win 2008 sp2 (25.Jun.2009 9:52:49 AM)

tk,

If that doesn't work you can do what we did. After every GFI console update we noticed our ignore list got reset so we resorted to modifying the toolcfg_bulletinignore.xml file with notepad or Microsoft's XML Notepad 2007. This actually turned out to be a good thing because in the process I discovered that our scans we were doing were not reporting correctly on certain patches because they were still set inside of this file to ignore the patches but when you looked at it through the console it did not show we were ignoring these patches. You have to match up the GFI number to the patch you are wanting to ignore but this is one way of globally ignoring patches. This is especially good if you have customers or other people using multiple consoles and you want to make sure you are all ignoring the same things.

If I'm wrong on this I'm sure a GFI forum monitor "DrewE" will correct me. :-) Hopefully I'm right on this and also after mentioning this the GFI devs won't change this because a central point of management for exclusion lists for multiple scanning consoles is lacking from LANGuard currently so we manage it from this one file and push modifications to that file to the mutiple consoles we use.




Page: [1]