Endpoint Protection

 View Only

Install Central Quarantine and Configure SEP Integrate with Central Quarantine 

Sep 27, 2015 09:46 AM

When a Symantec client finds an infected item that cannot be repaired with the current virus definitions, it blocks access to the item. The client then packages the item along with any affected system files and settings, and moves the package to the local Quarantine. The local Quarantine is a special location that is reserved for infected files and related system side effects. After viruses and other threats are isolated in a local Quarantine, they cannot damage or spread on the computer.

Symantec clients can automatically forward the packages that contain the infected files and related side effects from a local Quarantine to the Central Quarantine. The Central Quarantine is a central repository that is composed of two primary components, the Central Quarantine Server and the Quarantine Console. The Central Quarantine Server stores infected samples and communicates with Symantec Security Response. The Quarantine Console, which snaps into Microsoft Management Console (MMC), lets you manage the Central Quarantine Server.

You can collect forensic information more easily by using Central Quarantine. You can get a sample from an infected computer without having to physically go to that computer.

In addition to scanning files for viruses, the product scans files for security risks, which include spyware, adware, hacking tools, and joke programs. You can also forward these infected files to the Central Quarantine. Threats that are detected and quarantined with Proactive Threat Protection, however, are submitted by using a different mechanism.

Install Quarantine Server:

1. Launch 'Quarantine Server.msi':

Quarantine_Server_01.png

2. Accept the license:

Quarantine_Server_03.png

3. Click Next:

Quarantine_Server_04.png

4. Change the Maximum Disk Space accordingly:

Quarantine_Server_05.png

5. Input the Contact Information:

Quarantine_Server_06.png

6. Keep the gateway as default:

Quarantine_Server_07.png

7. Start the installation:

Quarantine_Server_08.png

8. You need to restart the system after the installation of Quarantine Server:

Quarantine_Server_09.png

Install Quarantine Console:

1. Launch 'Quarantine Console.msi':

Quarantine_Server_10.png

2. Accept the License:

Quarantine_Server_11.png

3. Choose Destination Folder:

Quarantine_Server_12.png

4. Finish the installation:

Quarantine_Server_13.png

Configure Central Quarantine:

1. Launch 'Symantec Quarantine Console' from Start menu:

Quarantine_Server_20.png

2. Right click 'Symantec Central Quarantine', select 'Attach to server':

Quarantine_Server_21.png

3. Input the information of the Quarantine Server:

Quarantine_Server_22.png

4. Edit the server properties, select 'General' tab, then click to enable 'Listen on IP', and input a port number:

Quarantine_Server_23.png

Configure SEP to integrate with Central Quarantine:

Log into SEPM admin console, click to edit the AntiVirus policy. Select 'Quarantine' configuration section, on the 'General' tab, click to enable the option 'Allow client computers to automatically submit quarantined items to a Quarantine Server', then input the information of the Quarantine Server:

Quarantine_Server_30_0.png

After a client computer be infected by a virus that need to be quarantined, the virus will be submitted to the Quarantine Server:

Quarantine_Server_31.png

 

 

 

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Related Entries and Links

No Related Resource entered.