Release Notes
McAfee Firewall for Linux 8.0.0
Contents
About this release Features
Installation Known issues
Find product documentation
About this release
This document contains important information about the current release. We strongly recommend that you read the entire document.
We do not support the automatic upgrade of a pre-release software version. To upgrade to a production release of the software, you must first uninstall the existing version.
Features
This release of the product includes these new features.
Stateful firewall
Keeps track of the network connections. A stateful firewall includes a state table that dynamically stores information about active connections created by allow rules.
Regular mode
Adaptive mode
When the network packet matches a rule’s conditions, the associated action defined in the rule is executed. If no matching rule is found, the network packet is allowed, and a rule is created to allow similar packets later.
Trusted networks
Define networks that can include subnets, ranges, or a single IP address that can be used while creating firewall rules.
FTP inspection
Creates dynamic rules for FTP data connections automatically, by actively monitoring the FTP commands on the control channel.
Common manageability for Linux, Windows, and Mac
McAfee ePO-based policies can be enforced on Windows, Linux, and Mac systems.
FQDN support
Supports FQDN-based rule creation.
CLI support
Supports Command Line Interface for managing the firewall.
Dev Ops tools support
Supports silent installation and command-line configuration that can be used for automation through scripts and Dev Ops tools.
Firewall groups
Organize firewall rules of similar criteria under rule groups, and provide better rule management capabilities.
Time-based firewall
Configure firewall rules that are enforced only for a specific time period during the week.
Supported protocols
TCP, UDP, and ICMP.
Product management
Complete management of the product through McAfee ePO including deployment and policy enforcement.
Installation
For information about installing Firewall for Linux, see McAfee Firewall for Linux Product Guide .
System requirements
Make sure that your system meets these requirements, and that you have administrator rights.
Component Requirement
Operating system • Red Hat 6, 7 • Amazon Linux 2014.x • SUSE 11, 12 • CentOS 6, 7
• Ubuntu 12.04, 14.04, 14.10
• Oracle Linux - Red Hat, UEK 6, 7
Hardware • Processor - 64-bit
• RAM - 2GB (minimum), 4GB (recommended) • Hard disk space - 100MB (minimum)
McAfee®
Firewall for Linux 8.0.0 McAfee®
Host Intrusion
Prevention extension 8.0 patch 5 McAfee®
Agent 4.8 patch 2 and later McAfee ePO 4.6.8, 5.1.1
Installation from the CLI (Unmanaged mode)
This procedure involves installing McAfee Runtime and McAfee Agent for RPM-based Linux systems and Ubuntu systems.
The McAfee Agent and the McAfee Runtime package are available inside the McAfeeAgent folder when you extract the McAfeeFirewall.zip package.
You can use the command line to install Firewall for Linux with user intervention (prompt mode) or without (silent mode).
Download the software package
Download the Firewall for Linux software package to a Linux-based standalone system.
Task
1 Download McAfeeFirewall.zip to a temporary directory.
2 Extract the .zip file.
\unzip McAfee Firewall.zip
Install McAfee Runtime and McAfee Agent on an RPM-based system
Install McAfee Runtime and the McAfee Agent on an RPM-based system.
Task
1 Change directory. cd McAfeeAgent
2 Install McAfee Runtime. rpm -ivh MFErt.i686.rpm
3 Install McAfee Agent. rpm -ivh MFEcma.i686.rpm
4 View the status of the McAfee Agent. /etc/init.d/cma status
Install McAfee Runtime and McAfee Agent on an Ubuntu system
Install McAfee Runtime and the McAfee Agent on an Ubuntu system.
Task
1 Change directory. cd McAfeeAgent
2 Install McAfee Runtime.
sudo dpkg -i MFErt.i686.deb
3 Install McAfee Agent.
sudo dpkg -i MFEcma.i686.deb
4 View the status of the McAfee Agent. /etc/init.d/cma status
Install Firewall for Linux in silent mode
Silent mode installation is a non-interactive process, where the End-User License Agreement is not displayed and the firewall is enabled automatically.
Task
1 Change directory. cd ..
2 Install the software. ./install-mfw.sh silent
Install Firewall for Linux in prompt mode
Prompt mode installation is an interactive process, where you accept the End-User License Agreement and enable the firewall.
Task
1 Change directory. cd ..
2 Install the software. ./install-mfw.sh prompt
3 When the End-User License Agreement appears, type accept, and press Enter.
4 When prompted to enable the firewall, enter y or Y, or skip this step by pressing any other key.
When you run the install command ./install-mfw.sh, by default the installation happens in prompt mode.
When the installation is complete, the software starts protecting your Linux system immediately. Any existing network connections that are running on your system are disconnected. You must re-establish those connections.
Uninstall the software from a standalone system
You can uninstall Firewall for Linux from a standalone Linux system using a command-based script.
Task
1 Open the terminal window.
2 Type the following command, then press Enter. /opt/McAfee/mfw/bin/uninstallmfw.sh
3 Confirm the uninstall activity.
The software is removed from a standalone system.
Known issues
Find product documentation
After a product is released, information about the product is entered into the McAfee online Knowledge Center.
Task
1 Go to the Knowledge Center tab of the McAfee ServicePortal at http://support.mcafee.com.
2 In the Knowledge Base pane, click a content source: • Product Documentation to find user documentation • Technical Articles to find KnowledgeBase articles
3 Select Do not clear my filters.