Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Unmanaged Detector in SEP 12.1

Updated: 08 Feb 2012 | 13 comments
pete_4u2002's picture
+7 7 Votes
Login to vote

To configure the client as an unmanaged detector, you must do the following actions:

  •  Enable Network Threat Protection.
  •  Switch the client to computer mode.
  •  Install the client on a computer that runs all the time.
  •  Enable only Symantec Endpoint Protection clients as unmanaged detectors.
  • A Symantec Network Access Control client cannot be an unmanaged detector.

 

To configure a client to detect unauthorized devices

1 In the console, click Clients.

2 Under View Clients, select the group that contains the client that you want to enable as an unmanaged detector.

3 On the Clients tab, right-click the client that you want to enable as an unmanaged detector, and then click Enable as Unmanaged Detector.

4 To specify one or more devices to exclude from detection by the unmanaged detector, click Configure Unmanaged Detector.

5 In the Unmanaged Detector Exceptions for client name dialog box, click Add.

6 In the Add Unmanaged Detector Exception dialog box, click one of the following options:

Exclude detection of an IP address range, and then enter the IP address range for several devices.

Exclude detection of aMACaddress, and then enter the device's MAC address.

7 Click OK.

8 Click OK.

 

To display the list of unauthorized devices that the client detects

1 In the console, click Home.

2 On the Home page, in the Security Status section, click More Details.

3 In the Security Status Details dialog box, scroll to the Unknown Device Failures table.

4 Close the dialog box.

Comments

Swapnil's picture
20
Feb
2012
1 Vote +1
Login to vote

Nice one

Nice one

Swapnil

SOC Team .

Please don't forget to mark your thread solved with whatever answer helped you.

pete_4u2002's picture
20
Feb
2012
0 Votes 0
Login to vote
Jakesty's picture
23
Apr
2012
0 Votes 0
Login to vote

Exclusion Issues

I have added exlusions, but they still show up in the list.  I'm using the IP address range to block monitoring things like network printers, etc.

What else is missing?

 

thanks, Jake

sadelphin's picture
18
May
2012
0 Votes 0
Login to vote

Is there a way to add

Is there a way to add multiple mac address to exclude ? like importing from a file

pete_4u2002's picture
18
May
2012
0 Votes 0
Login to vote

you can multiple MAC address

you can multiple MAC address one by one. we cannot import a file to exclude.

sadelphin's picture
18
May
2012
0 Votes 0
Login to vote

What if i have 400 mac id's

What if i have 400 mac id's to exlude?..

pete_4u2002's picture
18
May
2012
0 Votes 0
Login to vote

may be we can add it as an

may be we can add it as an IDEA, going to add it in sometime.

sadelphin's picture
18
May
2012
0 Votes 0
Login to vote

say if i add some mac address

say if i add some mac address in exclusion list.. Where it will be saved?. in sepm or client. If it's saved in a file somewhere can we edith that ?

pete_4u2002's picture
18
May
2012
0 Votes 0
Login to vote
sadelphin's picture
19
May
2012
0 Votes 0
Login to vote

Confused

Thanks pete for directing me in the right direction.

But it seems in the database the ip address range is hashed somehow.

I've excluded some ip address range in console by configure unmanaged detector. when i query in database i dont see the actual ip address mentioned, only some random number is there... attached screen shot for your reference

Exclude ip range.PNG
pete_4u2002's picture
19
May
2012
0 Votes 0
Login to vote

can you check this Monitors >

can you check this

Monitors > Notification > View Notifications from Symantec Endpoint Protection Manager you see IP addresses in the report that were excluded.does that help?

 

 

sadelphin's picture
19
May
2012
0 Votes 0
Login to vote

My point is different..

Instaed of adding the mac address/ip address one by one i'm thinking of adding those directly  to the database.

 

pete_4u2002's picture
19
May
2012
0 Votes 0
Login to vote

its not recommended to

its not recommended to directly insert into DB without DB schema information. however if it is must you can take a backup of db and then insert the query.