F-Secure Email and Server Security Upgrade Best Practices You Should Know - F-Secure Community
<main> <article class="userContent"> <h3 data-version="11" data-article="000029421" data-id="issue">Issue:</h3> <p>How to install F-Secure Email and Server Security 15.00?<br>Why I cant push install F-Secure Email and Server Security 15.00 using Policy Manager Console?</p> <h3 data-id="resolution">Resolution:</h3> <p>Before planning any upgrade, it is highly recommended to check release version and make sure your Exchange server meets the criteria. Release notes can be found under our official web page: <a rel="nofollow" href="https://help.f-secure.com/product.html#business/releasenotes-business/latest/en/fsess-latest-en ">https://help.f-secure.com/product.html#business/releasenotes-business/latest/en/fsess-latest-en </a><br><br>If you are using Business Suite, make sure that your F-Secure Policy Manager Server version is the latest. More about version release please refer here: <a rel="nofollow" href="https://www.f-secure.com/fi/business/downloads/policy-manager ">https://www.f-secure.com/fi/business/downloads/policy-manager </a><br><br><b>Note:</b> F-Secure Policy Manager Server needs to be the latest version before you can upgrade the clients to the latest versions.<br><br><br><u>Licensing: </u><br></p><ul><li>If you are upgrading from version 12. xx to 15.xx and you do not have product activation key, please contact your F-Secure reseller or Partner to obtain the latest keycodes for Business Suite products.</li><li>If you are upgrading from version 14. xx to 15.xx no additional keys are needed.</li><li>If you have F-Secure Email and Server Security standalone version and do not have the key or installer, please contact your F-Secure reseller or Partner to obtain the latest keycodes for Business Suite products and the </li></ul><u><b>Conditions that should be met for installation to be successful (these are applied to user that will run MSI):</b></u><br><br>F-Secure Email and Server Security for Microsoft Exchange: <ul><li>User must be in local "Administrators" group</li><li>User must have access rights to create/configure application in the "Program Files" folder</li><li>User must be able install/configure local services</li><li>User must have rights to run PowerShell scripts</li><li>User must be a member of "organization management" (could be added in MS Exchange Security group or via Exchange admin center>permissions)</li><li>User must be in "Local Administrator" group</li></ul> F-Secure Email and Server Security for Microsoft SharePoint: <ul><li>User must be in "Local Administrator" group</li><li>Note: User for scan and service (credentials entered at the installation in UI or config tool after installation):</li><li>User must be in "Farm Administrators" in SharePoint Group</li><li>User should have "Logon as a service" privilege enabled</li></ul><b><u>Supported scenarios for the upgrade:</u></b><br><br><b>IMPORTANT:</b> Push operations using F-Secure Policy Manager Console for F-Secure Email and Server Security respectively Exchange and SharePoint components have never been supported and will continue to be unsupported. This means that no push installation is possible for F-Secure Email and Server Security via the F-Secure Policy Manager console. It would be a security risk to share DB passwords / SHP admin credentials over the network and no changes in the installation process.<br><br>Currently we support only the two upgrade scenarios: <ul><li>Local upgrade using MSI </li><li>Policy-based upgrade from Policy Manager</li></ul> If you are upgrading from Version 12.xx:<br><br><b>Note:</b> Microsoft® SQL Server must be installed before upgrading your Email and Server Security. SQL Express is no longer included in the installer as it used to be with version 12.xx.<br><br>Please refer to the deployment guide how to install SQL. Installing Microsoft SQL Server instructions can be found here: 50 | Installing Microsoft SQL Server | F-Secure Email and Server Security <a rel="nofollow" href="https://help.f-secure.com/data/pdf/fsess15.00-deployment-eng.pdf">https://help.f-secure.com/data/pdf/fsess15.00-deployment-eng.pdf</a>.<br><br>If you upgrade using Policy Manager ‘policy-based upgrade option, you still need to setup the SQL Database locally on your Exchange server by running setup F-Secure.Ess.Config.exe as administrator. Tool can be found here: C:\Program Files (x86)\F-Secure\Email and Server Security\ui\F-Secure.Ess.Config.exe <br><br>For more help, please refer to 4.1 Installing the product locally page 25: <a rel="nofollow" href="https://help.f-secure.com/data/pdf/fsess15.00-deployment-eng.pd">https://help.f-secure.com/data/pdf/fsess15.00-deployment-eng.pd</a>f<br><br>Additionally, check the articles below to make sure you have all prerequisites for the F-Secure Email and Server Security Web Console.<br><br>You might want to verify if TLS 1.0, 1.1 and 1.2 are enabled. Our advise is to use 1.2<br><br><u><b>Upgrading standalone:</b></u><br><br>If you don't have the MSI installer, please contact your reseller or customer support to provide you with the installer.<br><br><b>Note:</b> After installing this standalone version of Email and Server Security it will take some time for it to recognise that it is a standalone installation. Customers are advised that they should not restart the server EVEN if prompted until "Update Server" in the Updates section of the settings user interface shows "guts2.sp.f-secure.com". If the customer restarts the computer before this time, the process will start over. In some cases this may take up to three hours, we will improve this in the next version.<br><br>FAQs:<br><br>Do I need to run maintenance mode and take servers offline from the DAG cluster when upgrading F Secure Email and server security?<br><br>More about the maintenance mode and DAG: <a rel="nofollow" href="https://docs.microsoft.com/en-us/exchange/database-availability-groups-dags-exchange-2013-help">https://docs.microsoft.com/en-us/exchange/database-availability-groups-dags-exchange-2013-help</a><br><br>The upgrade process does not require servers to be offline. However, to avoid any compatibility issues that might come up during the upgrade, you advise you to run the upgrade on one server first using the local installation option.<br><br>To install the product on a server with MSI you created with Policy Manager: <ol><li>Log in to the F-Secure Policy Manager Console</li><li>Go to the Installation tab</li><li>Click Installation packages </li><li>Click Import </li><li>Import the F-Secure Email and Server Security 15.00 Jar file</li><li>Select the imported Jar file from the Installation packages list and click Export as MSI</li><li>Run the MSI locally on your Exchange server with the domain admin or the local admin rights</li><li>Complete the setup by following the on-screen instructions </li></ol> If you have any questions about the specific configuration, please refer to the Administrator or Deployment guides: <ul><li><a rel="nofollow" href="https://help.f-secure.com/data/pdf/fsess15.00-adminguide-eng.pdf">Administrator's guide</a></li><li><a rel="nofollow" href="https://help.f-secure.com/data/pdf/fsess15.00-deployment-eng.pdf">Deployment guide</a></li></ul><p>Article no: 000029421</p> </article> </main>