Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Configuring SEP v11

Created: 07 Dec 2010 | 5 comments
cdubya's picture
0 0 Votes
Login to vote

We run SEP v11 on our network and I'm finding the default level of protection seems to be allowing a good deal of malware on our systems.

I read a few other threads about people having the same issue with SEP and the suggestion was to lock down SEP tighter.

I'm a noob to SEP, but as far as I can tell I guess the setup is considered "managed". That being said, what do I need to do to tighten down the security on the clients?

I read about there being higher degrees of false positives, but being able to add exceptions (if your security policy allows it).

I want to get these machines setup so we don't have so many issues with malware, so would appreciate any feedback.

Thanks,

C.

Comments

Brian81's picture
07
Dec
2010
1 Vote +1
Login to vote

This should get you

This should get you started

Security Response recommendations for Symantec Endpoint Protection settings

http://www.symantec.com/business/support/index?pag...

Thomas K's picture
07
Dec
2010
1 Vote +1
Login to vote

See the Security Response

See the Security Response recommendations.

 

Security Response recommends the following Scan Settings

 

Antivirus Security Setting Default Setting High Security Policy Security Response Recommendation
Lock settings Some Some All
Remediation: terminate processes No No Yes
Remediation: terminate services No No Yes
Auto-Protect action taken for security risks Quarantine/Log Quarantine/Log Quarantine/Delete
Network Auto-Protect Disabled Enabled Enabled
Bloodhound Level Default (2) Default (2) Default (3)
SEP Startup System Start System Start System Start
Auto-Protect Scan Modify and access Modify and access Modify and access

Security Response recommends the following setting changes to Truscan for best protection

 

Truscan Default Setting Security Response Recommendation
Scan Sensitivity 9/Low 100
Action on Detection Log Terminate
Scan Frequency 1:00 00:15

http://www.symantec.com/business/support/index?pag...

khaskins82's picture
07
Dec
2010
0 Votes 0
Login to vote

You can do alot to protect

You can do alot to protect the computers by making sure the patching is up to date. I got more from patching than with SEP by itself.

zer0's picture
07
Dec
2010
0 Votes 0
Login to vote

Also check out this

Also check out this pre-written policy for protecting SEP - http://www.symantec.com/business/support/index?pag...

 

And make sure you have password protection enabled for stopping or removing SEP