Endpoint Protection

 View Only
  • 1.  12.x Find unmanaged computers without NTP

    Posted Dec 11, 2013 12:40 PM

    We don't use NTP, and we won't, ever(due to a long history of it causing major headaches). So unamanaged detectors will not work.

     

    So without NTP, how do I find unmanaged computers in 12.x? Please don't refer me to the "Client Deployment Wizard" it does no detection of any kind to see if a client is managed or not, I have thousands of clients and don't have time or patience to check each one manually.



  • 2.  RE: 12.x Find unmanaged computers without NTP

    Posted Dec 11, 2013 12:44 PM

    You can use SNAC to do it. There are policies that be configured to not allow clients on the network if they don't have AV installed. Of course this will require some extra hardware.

    Aside from that, there are other third party tools available.

    If your looking to do it with SEP/SEPM, your options are pretty limited. And yea, CDW doesn't tell you if a client is managed or not, it only tells you if you have SEP installed or something else.



  • 3.  RE: 12.x Find unmanaged computers without NTP

    Posted Dec 11, 2013 01:44 PM

    Hello, 

    Try to push clients from SEPM console if SEP is installed it will show(dont push the clients), copy the client compare it with the export list of SEPM and the difference will be your result.

    Regards

    Ajin

     



  • 4.  RE: 12.x Find unmanaged computers without NTP

    Broadcom Employee
    Posted Dec 12, 2013 05:40 AM

    Hi,

    Thank you for posting in Symantec community.

    To use a computer in the network as an unmanaged detector it must meet these requirements:

    -The Symantec Endpoint Protection (SEP) client on this machine must have Network Threat Protection and Firewall installed and enabled.

    -The computer must be in computer mode.

    -The machine must be on all the time.

    -Symantec Network Access Control cannot be enabled on this client.
    This can be determined by opening the SEP user interface. Network Access Control will be listed after Network Threat Protection.

    I will suggest to meet these system requirements, At least Install NTP on any single client machine like XP/Windows 7 & achieve your goal.



  • 5.  RE: 12.x Find unmanaged computers without NTP

    Posted Dec 12, 2013 10:17 AM

    Hello,

    As workaround, you can install NTP only on a client per each subnet but disable it via policy or assign to them a firewall policy to "allow all".

    if you can't use those features already offered by SEPM, you then need a dedicated client management software.