Endpoint Protection

 View Only
  • 1.  Enabling LiveUpdate for Cisco ISE integration

    Posted Apr 12, 2015 01:15 AM

    Background:

    We currently have SEPM version 12.1.2015.2015, running on Windows server 2008 R2 standard.

    We have one management server installed in our environment (default mgmt. server; for policy mgmt. and updates), which suffice our requirements (as we don’t have more than 400 clients as yet). We have Live Update disabled on clients as we don’t have an internal LiveUpdate server, neither we want our internal clients to go to Symantec LiveUpdate servers (internet).

     

    Requirement & Issue:

    We are implementing Cisco ISE as NAC (Network Access Control) solution. As per our policy requirements, clients must not connect to internal network resources unless they are satisfactorily secured. One of similar requirements (through ISE posture) is to ensure Symantec Antivirus definitions are current/updated for workstations/laptops that connect to network.  (We have Symantec AV client and Cisco AnyConnect client software installed on our workstations/laptops.)

     

    The issue is…

    If a workstation which has outdated AV definitions connects to our network, Cisco ISE client (AnyConnect) tries to do auto-remediation by running Live Update. Cisco AnyConnect needs to run the “SepLiveUpdate.exe” on endpoint. However, as the update is disabled, client (Any Connect) gets error: “The remediation you are attempting is reporting an access denied error. This is usually due to privilege issues. Please contact your system administrator.”

    As informed by Cisco support, they need “SepLiveUpdate.exe” to run successfully in order to perform remediation of outdated AV definitions. (C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SepLiveUpdate.exe)

    If we manually try to run SepLiveUpdate.exe, that gives an error as well. (LiveUpdate has been disabled. Please contact your System Administrator for more information.). This is obvious, as update is disabled..

     

    Question

    How can we enable “SepLiveUpdate.exe”? (without having an internal LiveUpdate server or pointing updates to Symantec LiveUpdates)

     

    Regards,



  • 2.  RE: Enabling LiveUpdate for Cisco ISE integration

    Posted Apr 12, 2015 09:27 AM

    SepLiveUpdate.exe simply initiates an LU session to an external LU server so I doubt this is what you want:

    About SepLiveUpdate.exe

    If the HI check fails, you would need to remediate by downloading the Intelligent Updater to update, you could script this as well within the Cisco ISE I believe.

     



  • 3.  RE: Enabling LiveUpdate for Cisco ISE integration

    Posted Apr 13, 2015 02:08 AM

    As per my understading and observation from console..

    SepLiveUpdate.exe simply initiates an LU session to:

    1- Either an external LU server.

    OR

    2- An Internal LU server.

     

    As we dont have Internal LU server, we are looking forward to a workaround to direct SepLiveUpdate.exe to somehow take updates from SEPM server.. is this possible by any means?

     



  • 4.  RE: Enabling LiveUpdate for Cisco ISE integration

    Posted Apr 13, 2015 09:02 AM

    Not using SepLiveUpdate.exe.

    The internal process that talks to the SEPM from the client side is CcSvcHst.exe in 12.1.5