How do I disable the Audit Portmapper on Windows?
search cancel

How do I disable the Audit Portmapper on Windows?

book

Article ID: 54715

calendar_today

Updated On:

Products

CA Security Command Center CA Data Protection (DataMinder) CA User Activity Reporting

Issue/Introduction

Description:

This document shows how to disable the Audit Portmapper. Please Note: You must configure Audit to use fixed ports in order for Audit to operate without a portmapper.

Solution:

IMPORTANT: This article contains information about modifying the registry.
Before you modify the registry, make sure to create a back up of the registry and ensure that you understand how to restore the registry if a problem may occur.
For more information on how to back up, restore, and edit the registry, please review the relevant Microsoft Knowledge Base articles on support.microsoft.com.

  1. Stop the Audit Log Router service.

    1. Open regedit and drill down to: HKLM\System\CurrentControlSet\Services\eTrust Audit Log Router.
    2. Open DependOnService and remove the entry value for portmapper.
    3. Click OK.

    <Please see attached file for image>

    Figure 1

    1. Open HKLM\Software\ComputerAssociates\eTrustAudit\RPC
    2. Replace the data for PortmapName with an empty string value
    3. Add a DWORD entry named RegisterPort with a Data value of 0.

    <Please see attached file for image>

    Figure 2

    1. Stop the portmapper service.
    2. In the Portmap service properties change the "Startup Type" to "Disabled".

    <Please see attached file for image>

    Figure 3

  2. Start the Audit Log Router service.

Environment

Release:
Component: ADTCTL

Attachments

1558711782145000054715_sktwi1f5rjvs16sdf.gif get_app
1558711780295000054715_sktwi1f5rjvs16sde.gif get_app
1558711778246000054715_sktwi1f5rjvs16sdd.gif get_app