Endpoint Protection

 View Only
Expand all | Collapse all

Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

  • 1.  Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 30, 2013 11:08 PM

    Hi All,

    In order to reduce my confusion, can I actually create one single SYLINK.XML for all of my server with the below settings:

    Internal Servers SEP Client reporting and managed by Internal SEPM server
    DMZ Servers SEP Client reporting and managed by DMZ SEPM server

    so irrespective whichever the server is deployed and installed with the SEP client, it can automatically report to the correct DMZ or internal SEPM respecitvely. 



  • 2.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 30, 2013 11:22 PM
    Hi, As per my knowledge, Your Internal SEPM server and DMZ SEPM server has differnt IP,so you have to create two sylink because sylink contain IP address and client will communicate with that IP Address which is in sylink.XML Regards, Zafar


  • 3.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 30, 2013 11:26 PM

    HI,

    Are your SEPM AD integrate?

     

    if no may be you can create sylink.xml all sep client showing that particular group



  • 4.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Broadcom Employee
    Posted Jan 30, 2013 11:27 PM
    i do not think it can be done. the SEPM's have to be replicating. then ylink can be used. However again, the Management Server List needs to be set so that client report to the priorites defined in that. so it will be different sylink.


  • 5.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 31, 2013 12:19 AM

    Yes the SEPM in the internal is of course AD integrated as can be evidence from the account that I'm logged in to, it is using my AD account password.

     

    but the DMZ servers andthe SEPM in the DMZ is not AD integrated.



  • 6.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 31, 2013 12:21 AM

    Many thanks for the response Zafar,

    I don't know who set it up before me (my predecessors), I see that in one of the Sylink. XML it has multiple SEPM and has a priority 1 2 and 3 in the XML element ?

    are they rotated in round robin style ?



  • 7.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 31, 2013 12:22 AM

    Thank you for your clarification Pete, so in this case it is not possible to create one Sylink.XML which contains all SEPM servers in all different domain ?

     



  • 8.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Broadcom Employee
    Posted Jan 31, 2013 12:31 AM
    you have all the SEPM's certificate in one sylink file if they are replicating or in load balance.however as per your requirement you want to have client connects to respective location SEPM. if thats the case, the sylink has to be different withe the priorites defined. do you have SNAC?


  • 9.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 31, 2013 02:29 AM

    Hi Pete,

    Replication: Yes I have set both SEPM to replicate each other between Internal and DMZ

    SNAC: not yet implemented, but soon to be for the Internal only, not DMZ

    I've seen that the SYLINK.XML in my DMZ servers got

    Priority 1: connect to SEPM Internal FQDN

    Priority 2: connect to SEPM DMZ IP address

    Priority 3: connect to SEPM Internal IP address 

     



  • 10.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 31, 2013 02:36 AM

    Hello John,

    It may possible if failover/loadbalancing or replication is configured between SEPM's.

    Check the MSL configuration at both the SEPM's.

    Or else need to create two Sylink.xml files.

     



  • 11.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Broadcom Employee
    Posted Jan 31, 2013 02:39 AM
    you may need to edit/add MSL accordingly and appky to the clients so that they know which SEPM to communicate. Also when exporting new package you use the policy from the said group so that client know which group to communicate and policy to be taken. Hope this helps.


  • 12.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 31, 2013 02:44 AM

    Hi John,

    So irrespective whichever the server is deployed and installed with the SEP client, it can automatically report to the correct DMZ or internal SEPM respecitvely --> Yes it's correct with given info above.

    You can change the MSL if required.



  • 13.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Jan 31, 2013 04:06 AM
    Hi, Agreed with pete, could you please tell me architecture of ur environment? If you have installed SEPM with AD integration,the client will automatically move to respective OU.


  • 14.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Feb 03, 2013 07:45 PM

    Hi Zafar,

    Yes the AD integration is just for the Login authentication, once the SEP client reports in, I have to manually MOVE it by right clicking into the correct group.



  • 15.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Feb 03, 2013 07:45 PM

    Pete,

    May I know how and where can I edit the MSL list ?



  • 16.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Broadcom Employee
    Posted Feb 03, 2013 09:47 PM

    if the default MSL, you cannot edit it.

     

    check this link for configuring MSL

    http://www.symantec.com/docs/HOWTO81154

     



  • 17.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?

    Posted Feb 03, 2013 11:48 PM

    Many thanks for the clarification Pete,

    Now I know that MSL is the way to priorituze / load balance the SEP client connecting with the SEPM in the same subnet without any firewall in place.

    But in my case both SEPM servers are in the different subnet and there is a firewall in between the Intenral and the DMZ, so I guess creating one MSL to be used by the DMZ SEP client is impossible to do because the next available SEPM in the list is on different network zone protected with firewall.



  • 18.  RE: Creating Sylink.XML for multiple SEP talking to SEPM in different zones ?
    Best Answer

    Broadcom Employee
    Posted Feb 04, 2013 12:03 AM

    in that case you need to allow port(SEPM) on firewall,be default 8014.if you don't client won't connect to other location SEPM