BigFix Enterprise console

Suite brings OS defences under control

BEC 5.1 can manage the security of a variety of operating systems from a single console

Written by Roger Howorth

Larger Image

The BigFix Enterprise Console (BEC) 5.1 is a configuration and patch management system for desktops and servers running Windows, Linux, Mac OS X and a variety of proprietary Unix operating systems. A wide range of client and server systems are supported, but they each need to run a BigFix agent in order to be fully managed by the suite.

BEC requires one Windows Server and uses a Microsoft SQL database to store its data. BigFix says one server can handle 150,000 devices, and there is an automatic system of relays that can balance the load and reduce delays for devices connected by slow network links. Relays must run the Windows BigFix agent.

BEC receives a collection of messages from BigFix’s datacentre every few minutes. These messages are called fixlets, and each contains details of a vulnerability affecting a certain type of computer, such as one running Microsoft Windows Server 2000. Once a BigFix agent is installed it goes to the server and downloads all its fixlets, determines which ones are relevant, and reports back to BEC.

Thus, the BEC console displays a list of fixlets and a tally of how many systems each is relevant to. Some fixlets are informational. For example, one checks Windows 2000, 2003 and XP systems to see whether they have antivirus tools installed. Others are more proactive – for example, the Null Session’s fixlet has options to change registry values to disable Null Sessions.

Clicking on a fixlet causes BEC to display its properties, which include details about the vulnerability, a place for comments, a list of relevant computers and an action history.

With BEC, nothing is changed on managed systems until an administrator clicks on a fixlet link. Once actioned, the fixlet could automatically be applied to all relevant computers that are running the BigFix agent, even new ones added after the fixlet was actioned. BEC provides options to action fixlets at a particular time, and to continually broadcast fixlets so their actions are always checked and applied if necessary.

BEC gathers information about most network devices from its agents, but the agents are not available for some types of network kit, including some printers, routers and firewalls. However, BEC can discover most other devices because it integrates with Nessus and Nmap – both open-source security scanning tools. We tested the Nmap integration using a fixlet called “Run Nmap with Custom Scan Options and Scheduling”.

All BEC actions are audited, which means whenever someone takes an action they must authenticate to the system. Thus we needed to give our BEC password to deploy the scanner. We then chose an XP desktop from the fixlet list of relevant computers. BEC then downloaded the Nmap software from a BigFix site, checked its digital signature and installed it on our workstation. A few minutes later and the Nmap results were added to our BigFix console under a new tab called Unmanaged Assets. It discovered our lab firewalls and routers, and for each device reported its MAC address and IP address plus some other IP related parameters.

Tags:

Product overview

  • Price: ££14
  • Web site: BigFix

Ratings

  • Our rating: n/a
  • Average user rating:

Verdict

BigFix Enterprise Console 5.1 provides a single console from which to manage the security settings and patching or a wide range of operating systems.

Best prices

reader comments

related articles

 

Debian flaw exposes communications breakdown

A wake up call for open source developers, Gartner warns 28 May 2008

IronKey unveils 8GB secure USB drive

Device touted as offering 'ultimate security' 06 May 2008

Experts warn of security-dodging Trojans

New malware on the rampage 06 Jun 2008

today's top stories

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Rules of convergence

While moving to a converged communications platform can bring greater efficiency and flexibility to business dealings, there are also potential legal complications related such matters as data retention and disclosure, as Jon Fell explains 18 Nov 2008

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Has the state of the economy forced to re-evaluate your IT purchasing options?

Has the state of the economy forced to re-evaluate your IT purchasing options?

Are you re-thinking your IT spending?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

Soca unitAnalysis

EU police in the dock over data sharing

Poor integration and lax practices are jeopardising EU efforts to fight international crime 20 Nov 2008

Nigel JonesComment

Have lessons of last year's HMRC fiasco sunk in?

Safeguarding privacy requires a good understanding of both technology and human psychology, says Nigel Jones 20 Nov 2008

Advertisement

Primary Navigation