Documentation Index

Fetch the complete documentation index at: https://docs.serversaustralia.com.au/llms.txt

Use this file to discover all available pages before exploring further.

What changes occur on my server due to an MMA?

Prev Next

Changes on servers with an MMA are outlined here. While there are some changes shared between Windows and Linux servers, server configuration changes largely differ by the kernel (A Linux or a Windows kernel) running on the server.

The following are the changes that take place on a server with an MMA broken down by kernel:

Windows Servers

The following changes occur on a Windows server with an MMA:

  • Install both a Salt Minion (Maintenance) and Zabbix Agent (Monitoring) on the host server.  These are the core agents used by our MMA.  Firewall ports required by these agents will be opened specifically to any management server requiring access to it.
  • Install and utilise disk health monitoring tools
  • Set up remote Event Log logging
  • Set up an alternate RDP port, and apply basic changes to the on server firewall to allow connections to this port.
    These connections can be configured to only allow from specific IP addresses.  Please contact our support team if you have specific IP addresses you would like to allow in this port.
    If you have a preferred alternative RDP port from the port that the MMA is intending to enforce, please let our support team know as we can accommodate for this as well.
  • Set and enforce the correct time and time zone on the server.
  • Install Webroot remote managed anti-malware software for Windows Servers.
  • Install all available updates.  Reboots are not forced when updates are installed, and they may need to be booked in with our support team.

Linux Servers

The following changes occur on a Linux server with an MMA:

  • Install both a Salt Minion (Maintenance) and Zabbix Agent (Monitoring) on the host server.  These are the core agents used by our MMA.
  • Install and utilise disk health monitoring tools
  • Set up remote Syslog logging
  • Install repositories required for management software
  • Set Time Zone and setup NTP
  • Install Configserver Security and Firewall (CSF).  This is a front end for iptables, and will replace UFW or firewalld on the server.  Please let out support team know of any requirements to the local firewall, and they can assist you in further locking down the server, and with managing what firewall ports are locked down.
  • Configure/Harden OpenSSH Server to prevent password login for root and alter the SSH port.
    The altered SSH port can be customised to suit your needs.  Please contact our support team if this is required.
    This will also apply our support teams SSH keys, and keep them up-to-date when ever these keys are rotated or require alteration.
  • On cPanel servers some cPanel specific changes occur.  This currently restricted to applying host identifying information (known to SaltStack as a grain), and setting up cpanel based MySQL backups, generally used by our R1soft backup servers.  Note:  If you do not have R1Soft backups, then the local MySQL backup will only be the last days data.
    Also, if the cPanel server has Imunify-360, then the version will be automatically updated by our management agent.

Need to prevent or modify some of these changes?

If you have the need to alter or prevent any of the changes outlined, please contact our support team.  Our management system is capable of altering or preventing any of the changes outlined above on a per-server basis.