Creating and managing client groups in Symantec Client Security 3.x and Symantec AntiVirus Corporate Edition 10.x
| Article:TECH101220 | | | Created: 2005-01-16 | | | Updated: 2010-08-16 | | | Article URL http://www.symantec.com/docs/TECH101220 |
Problem
This document provides additional information about creating and managing Symantec Client Security client groups in Symantec System Center 10.
Solution
Introduction
Symantec System Center 10 allows you to create groupings of Symantec AntiVirus and Symantec Client Security clients in a server group. This is an enhancement over previous releases of Norton AntiVirus Corporate Edition, in which all clients under a single parent server shared an identical configuration set.
Client groups share configuration, and these settings take precedence over configurations made at the parent server level. However, by default, after you have configured a client group, any settings configured at the server group level will replace any client group configuration. This behavior can be changed by right-clicking the client group name and unchecking the option to inherit settings from the server group.
Client groups can belong to only one server group. In other words, computers from different server groups cannot be members of the same client group. You can create as many server groups as you need to manage your clients efficiently.
Creating new client groups
All server groups contain a single Groups folder, which contains all of its client groups. When you create a new client group, that client group appears inside the Groups folder.
To create a new client group
- In the Symantec System Center console, in the left pane, right-click the server group to which you want to add the client group, and then click Unlock Server Group.
- Right-click Groups, and then click New Group.
- In the New Client Group dialog box, in the "Enter name of the new client group" box, type the name for the new client group.
The name cannot contain more than 15 characters. - If you want to apply the settings from an existing client group to the new client group, then select the name of the existing client group from the Client Group Template drop-down list.
- Click Create.
Adding clients to or removing clients from a client group
Computers that are running Symantec AntiVirus Corporate Edition client and legacy versions can be added to client groups. Both clients are treated identically. If a Norton AntiVirus legacy client does not have the feature for which a configuration option setting is set, the setting is ignored.
Note:
- Only Symantec AntiVirus Corporate Edition servers support client groups; legacy Norton AntiVirus Corporate Edition servers do not.
- A client can belong to only one client group.
To add an existing client to a client group
- In the left pane of the Symantec System Center console, click the server that contains the client.
- In the right pane, move the client to the client group by dragging and dropping it.
By default, you will not see a list of clients under a client group. The next procedure shows you how to make the clients visible.
To make the clients visible
- On the Tools menu, click Symantec System Center Console Options.
- On the Client Filter tab, check Show client machines when viewing Groups.
To remove a client from a client group
- In the left pane of the Symantec System Center console, click the server that contains the client.
- Expand any client group to show the list of clients.
- Right-click the client that you want to remove, and then click Remove from client group.
You can also drag and drop the client into another client group.
Configuring settings and running tasks at the client group level
You can set configuration options and run tasks at the client group level. The settings will be applied to, or the task run on, all clients in the client group.
To configure settings and run tasks at the client group level
- In the left pane of the Symantec System Center console, right-click the client group, and click All Tasks.
- Click the product for which you want to set options.
- Click the type of settings that you want to configure or the task that you want to run.
Finding client group settings
Client group settings are stored in the primary server's registry, under the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\Groups
Settings are rolled out to each server in a client group configurations file (Grcgrp.dat). The primary server packages all client group settings into the client group configuration file and then copies it to each secondary server in the server group. The secondary server rolls out the settings to the clients that it manages.
On each server in the group, the settings file (Grc.dat) that matches the specific client group can be located in the \\<server name>
Combining ClientRemote Install with client groups
In version 6 of the Symantec System Center, you can specify the location of the client deployment files.
To specify the location of client deployment files
- In the Symantec System Center console, on the Tools menu, click ClientRemote Install.
- Click Next.
In the Select Install Source Location dialog window, the Default Location is the
Program Files\Symantec\Symantec System Center\Deployment\Server Rollout\Clients\Win32 folder.
This deploys the Symantec AntiVirus 9 client. - If you want to deploy the client with the client firewall or deploy the client directly into a client group, create a folder on the computer on which the Symantec System Center is installed.
- For the Symantec Client Firewall/Symantec AntiVirus deployment, copy the contents of the \SCSClnt\ folder on the CD.
- To place the client directly into a client group, copy the Grc.dat file from the Groups\<client group name>
\ folder on the VPHome share of the appropriate antivirus server.
- When deploying to the clients, simply select the appropriate deployment folder to preconfigure the clients correctly.
Moving clients in client groups
You can move clients from one client group to another by dragging them. After you move the client, it receives the new client group's configuration settings.
Viewing client groups
When you view client groups, you can do the following:
- View a single client group
- View information about client groups
- View the contents of client groups one group at a time
- Filter the client group view to show only the information that interests you
To view a single client group
- In the left pane of the Symantec System Center console, right-click the server group that contains the client group.
- Click Unlock Server Group.
- Double-click the server group.
- Double-click the Groups folder.
The client groups appear nested beneath the Groups folder.
Viewing information about client groups
When the Groups folder is selected in the left pane and Default Console View or a Symantec product view is selected from the View menu, the client groups appear in the right pane along with information specific to the view. For example, when the Default Console View is active, the number of clients in each client group appears.
Client group filtering must be enabled for the clients to be enumerated. When you select the Groups folder, the number of clients reported for each client group may not be accurate until a client group is selected.
Filtering the client group view
Filtering improves client viewing performance in the Symantec System Center console. However, if there are many clients in the server group, filtering may affect performance. The clients must be enumerated to display the client groups accurately.
To filter the client group view
- On the Tools menu of the Symantec System Center console, click Symantec System Center Console Options.
- In the Symantec System Center Console Options Properties dialog box, on the Client Filter tab under Group Options, click Show client machines when viewing groups.
- Under Server Options, check any of the following options:
- Build client lists when the Server Group is unlocked
This enumerates all clients in the server group when it is unlocked. When this option is unchecked, clients are not added to their client groups until the server is selected. The number of clients in a client group is not accurate until all the servers in the server group have been selected. - Cache all client info (including clients in locked Server Groups)
This enumerates clients in both unlocked and locked server groups that are discovered by the Topology Service. These options may negatively affect performance if there are many clients and servers in the server group.
- Build client lists when the Server Group is unlocked
- Click OK.
- On the Action menu, click Refresh.
Renaming client groups
Symantec System Center does not support the renaming of client groups directly.
To change the client group name
- Create a new client group, importing settings from another client group, if desired.
- Drag clients from the old client group to the new client group.
- Delete the old client group.
Deleting client groups
Before you delete a client group, you may want to reassign the clients to another client group. When a client group is deleted, the clients that are assigned to it retain the settings of the deleted client group. The clients are not assigned new settings until one of the following actions occurs:
- The client checks in with its parent server.
The client is then assigned the server's default settings for unassigned clients. - The client is assigned to another client group.
The client is then assigned the settings of the new client group.
If you delete a client group and then recreate it before the clients check in with their parent servers or are reassigned, the clients resume membership in the group automatically. They continue to assume the settings of that group.
To delete a client group
- In the left pane of the Symantec System Center console, unlock the server group from which you want to delete the client group.
- Double-click the server group.
- Double-click the Groups folder.
- Right-click the target group, and then click Delete Group.
- Click Yes.
- Click Delete.
|
|
Legacy ID
2005041618530548
Article URL http://www.symantec.com/docs/TECH101220
Terms of use for this information are found in Legal Notices









Thank you.