Updated on 2024-01-16 GMT+08:00

Installing the Agent on a Windows Server

You can enable HSS for ECSs only after installing the agent. This section describes how to install the agent on a Windows server.


  • The ECS is in the Running state and can access the Internet.
  • Ensure the outbound rule of your security group allows access to the port 10180 on the network segment. (This is the default setting.)
  • The DNS server address of the cloud server has been set to the private DNS server address. For details, see Changing the DNS Server Address of an ECS and Private DNS Server Addresses.
  • The available capacity of the disk where the agent is installed must be greater than 300 MB. Otherwise, the agent installation may fail.
  • The Security-Enhanced Linux (SELinux) firewall has been disabled. The firewall affects agent installation and should remain disabled until the agent is installed.
  • If any third-party security software has been installed on your server, the HSS agent may fail to be installed. In this case, disable or uninstall the software before installing the agent.


  • 64-bit Huawei Cloud servers and non-Huawei Cloud servers can be protected. 32-bit servers are no longer supported.
  • Mainstream OSs are supported. For details, see Supported OSs.
  • The HSS agent will be automatically installed on Workspace 23.6.0 or later. If your Workspace version is earlier than 23.6.0, you can manually install the agent by referring to this section.

Installation Path

The agent installation path on servers running on Windows cannot be customized. The default path is: C:\Program Files\HostGuard.

Installation Operations

  1. Log in to the management console.
  2. Click in the upper left corner of the page, select a region, and choose Security & Compliance > HSS to go to the HSS management console.
  3. In the navigation pane, choose Installation & Configuration.

    If your servers are managed by enterprise projects, you can select an enterprise project to view or operate the asset and scan information.

  4. Click the Agent Management tab.
  5. Copy the address for downloading the agent installation package.

    • Huawei Cloud server
      1. Click the value in the Servers Without Agents area to filter the servers where the agent is not installed.
      2. In the Operation column of a server, click Install Agent.
        Figure 1 Installing an agent
      3. In the displayed dialog box, click Copy to copy the address for downloading the agent installation package.
    • Non-Huawei Cloud server
      1. Click Add Asset from Other Cloud.
        Figure 2 Adding asset from other cloud
      2. In the displayed slide-out panel, copy the address for downloading the agent installation package suitable for your system OS.

  6. Remotely log in to the server where the agent is to be installed.
  7. On the server where the agent is to be installed, use Internet Explorer to download the agent installation package from the copied agent download address and decompress it.
  8. Run the agent installation program as an administrator.
  9. Select a host type on the Select host type page.

    • Huawei Cloud server: Select Huawei Cloud Host.
    • Non-Huawei Cloud server: Select Other Cloud Host.
      Copy Org ID from the agent installation page, as shown in Obtaining the Org ID (for a non-Huawei Cloud server). Enter the Org ID and install the agent as prompted.

      Ensure Org ID is correct. Otherwise, the agent status may be displayed as Not installed even if the installation succeeded.

      Figure 3 Obtaining the Org ID (for a non-Huawei Cloud server)

  10. Check the HostGuard.exe and HostWatch.exe processes in the Windows Task Manager.

    If the processes do not exist, the agent installation fails. In this case, reinstall the agent. It takes 3 to 5 minutes for the console to update the agent status after agent installation.

Follow-up Procedure

After the agent is installed, enable security protection for your server. For details, see Enabling Protection.