Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Distributing RU6.1 via GUP

Updated: 16 Nov 2010 | 17 comments
Jose Lopez FJS's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hi all,

Our organisation currently distributes AV updates to the estate via a distributed GUP architecture.  We have to upgrade every end point to RU6.1 and will be using auto upgrade to achieve this.

My question is;

Can the GUP's be used to distribute and auto upgrade the RU6.1 update to all end points on their local network?  If so, what needs to be configured/considered?

With over 25,000 end points, we don't want to have the central SEPM servers having to service everybody for obvious bandwidth issues deploying a 120MB file across many WAN-linked sites (some have very slow connections to the SEPM Servers Data Centre).

Thank you all for your assistance.

Jose

Comments

AravindKM's picture
03
Nov
2010
0 Votes 0
Login to vote

Can the GUP's be used to

Can the GUP's be used to distribute and auto upgrade the RU6.1 update to all end points on their local network?--- 

It is not possible as of now.There is some product enhancement requests  in the idea section of this form.You can also vote for it..

Ref:IF GUP could Handle Product Updates aswell

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Rafeeq's picture
03
Nov
2010
0 Votes 0
Login to vote

hi

No ; GUP can only be used for AV defs nothing else as of now :(

However there is a idea for including this feature in Future

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Prachand's picture
03
Nov
2010
1 Vote +1
Login to vote

Hi Rafeeq, GUP can update

Hi Rafeeq, GUP can update every thing in terms of defintion( AV &AVS , PTP and PTP )an intelligent updater can only update AV and AVS

GUP cannot update the version or push the version update

Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)

Rafeeq's picture
03
Nov
2010
0 Votes 0
Login to vote

Hi

thank you :) I actually ment only virus definitions; 

Yes it will update AV/AS , PTP, NTP

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

AravindKM's picture
03
Nov
2010
0 Votes 0
Login to vote

You may try this How to

You may try this

How to Auto-Upgrade Remote Site Clients using IIS

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Jose Lopez FJS's picture
03
Nov
2010
0 Votes 0
Login to vote

Wow, I am impressed with the

Wow, I am impressed with the response times here!

Thank you all for answering my query so quickly and pointing me to possible walk arounds.  I will run them by our SEP expert here and see if they are viable.

This seems to be a feature which others have raised as desibale/essential as far back as May 2009.  This should really form part of a near future release update.

Thanks,

Jose

pete_4u2002's picture
03
Nov
2010
0 Votes 0
Login to vote

could be added under ideas

could be added under ideas section.

Vikram Kumar-SAV to SEP's picture
03
Nov
2010
0 Votes 0
Login to vote

GUP cannot host product

GUP cannot host product (package) updates I have already added an IDea more than a year back.

https://www-secure.symantec.com/connect/idea/if-gup-could-handle-product-updates-aswell

However it is possible to specify a remote HTTP server location to host client update packages.

postechgeek's picture
03
Nov
2010
1 Vote +1
Login to vote

Jose, I feel your pain on

Jose,

I feel your pain on this one. I so wish that GUPs could distribute client updates. That would be fantastic. To work around this, I copy the client install packages to each of the DCs in our locations and use clientremote.exe (push deployment wizard) to push out the updates. That way, the install files stay on the local subnet and don't crush our bandwidth. It's kind of hassle, but it saves bandwidth in the end. This keeps the operations folks happy, and we as IT can still get work done.

 

Mike

Jose Lopez FJS's picture
03
Nov
2010
0 Votes 0
Login to vote

Thanks all

Thanks all again!

Unfortunately Mike, we don't have DC's at each of our locations, but I like that work around.  Certainly something to consider for those locations that do.

Symantec need to address this issue as people like Vikram identified it as a concern as far back as May 2009, and it's not just a desirable cosmetic change, but a genuine Enterprise-wide concern which impacts other areas of a large estate.

Jose

postechgeek's picture
03
Nov
2010
0 Votes 0
Login to vote

Yeah, the machines do not

Yeah, the machines do not need to be DCs directly. If the locations have a PC with a server OS say Windows Server 2003, that would work too. Mainly, it's the connection limit that is the issue. Any PC can be used to push out the install packages. If you are using a Windows XP/Vista/7 based client, you only get 10 concurrent connections.

So, copy the Push Deployment Wizard files found here on the SEP (Symantec_Endpoint_Protection_11.0.6_MP1_Xplat_en.dvd.zip) install zip file:

Tools>Push Deployment Wizard

From there copy the install packages over to the PC at the location, and run clientremote.exe.

Also, I have heard some (maybe next release) rumblings around the forum that Symantec is going to include the ability to update client packages from the GUPs. This would greatly help. I thought it was supposed to be included in RU6, but it wasn't. Disappointment. :)

Mike

 

VeeKee's picture
03
Nov
2010
1 Vote +1
Login to vote

Use IIS to auto upgrade remote site clients.

You may also refer the below article.

 

https://www-secure.symantec.com/connect/articles/h...

 

One benifit of using this method is that, mobile users with laptops who miss the upgrade will get the package once they connect to the network. A true auto upgrade.

 

Cheers!!

---------------------------------
Vikas
--
Don't forget to mark your thread as 'solved' with the answer that best helped you!

Jose Lopez FJS's picture
09
Nov
2010
0 Votes 0
Login to vote

Mike, If the GUP's are W2K3

Mike,

If the GUP's are W2K3 servers, could we use them to deploy to their local clients using your method above

"So, copy the Push Deployment Wizard files found here on the SEP (Symantec_Endpoint_Protection_11.0.6_MP1_Xplat_en.dvd.zip) install zip file:

Tools>Push Deployment Wizard

From there copy the install packages over to the PC at the location, and run clientremote.exe"

and NOT be limited to the 10 concurrent connection limits?

Thanks,

Jose

postechgeek's picture
09
Nov
2010
0 Votes 0
Login to vote

Jose, You are correct. Win2K3

Jose,

You are correct. Win2K3 has unlimited concurrent connections.

 

Thanks,

Mike

Vikram Kumar-SAV to SEP's picture
09
Nov
2010
0 Votes 0
Login to vote

GUPs cannot distribute

GUPs cannot distribute packages/upgrades..

Clientremote.exe is a manual process.

postechgeek's picture
09
Nov
2010
0 Votes 0
Login to vote

Vikram is correct about

Vikram is correct about clientremote.exe,  with one exception. Clientremote.exe can push out the install package to multiple computers at a time. You have to manually add the clients. The best bet is to take a quick look at the tool, and see if it has the options you are looking for.

 

Thanks,

Mike

Jose Lopez FJS's picture
09
Nov
2010
0 Votes 0
Login to vote

Thanks Vikram.  I think we're

Thanks Vikram.  I think we're shutting the issue down here and accepting we are forced to auto upgrade centrally until such time as GUP re-distribution is introduced.

Thank you all for your contributions.