Linux Patch Scanning and Deployment Settings


 

Linux Patch Management module scans and assesses the patches that are deployed or missing in the Linux systems in the network. This helps make sure that all the Linux systems on the network are up to date with the critical or recent patches that are released for the Linux version and there are no security vulnerabilities in the network. The following sections provide details on configuring settings for scanning the network for missing patches and deploying the same.

 

Defining Parameters for Patch Scanning and Deployment

Settings-SWMgmt-PatchWzrdLin.jpg

 

linux_include_systems.gif

 

linux_exclude_systems.gif

 

linux_critical_systems.gif

 

linux_patch_scan_settings.gif

 

Sr. No

Field Name

Description

     1

Scan Retry  Count

Number of attempts to retry if a scan fails on the target system. Default scan retry count is 1 which can be changed.

     2

Scan Retry Interval

The duration after which a retry has to be attempted. Default scan retry interval is 1 hour which can be changed.

     3

Deploy Retry Count

The duration after which a retry has to be attempted. Default deploy retry count is 3 which can be changed.

     4

Deploy Retry Interval

Number of attempts to retry if a patch deploy fails on the target system. Default deploy retry interval is 3 which can be changed.

 

linux_patch_scan_schedule.gif

 

 

linux_patch_deploy_schedule.gif

 

Note.gifNotes: 1. Patch deployment will be performed only when the ‘Deploy Scheduler’ is enabled. Patch deployment will not be performed automatically or on demand.

2. Even if an automatic patch deployment is enabled, for devices listed in the critical system profile, the deployment will only happen for manually approved patches.