Trusted Vendors Configuration
Does anyone agree that sometimes Symantec may be pushing out features which aren't fully supported when they aren't 100% complete?
Don't get me wrong I am impressed with the quality of the products we use (SEPM MR4, Endpoint Protection, DHCP Enforcer) but i have started to get frustrated about using features which aren't fully working but I can't seem to find any documentation to detail which functionality is missing.
For example, with the Symantec DHCP enforcer, there is the function for DHCP Trusted Vendors Configuration. The setup guide for the DHCP Enforcer shows a complete list of all kinds of vendors which magically appear when the check box is enabled, but from 2 hours to support and a con call to the developers it turns out this feature only works if the Enforcer is placed in Allow All mode, the devices entry deleted from the DHCP and the device re-attached effectively picking it up as it's IP is assigned.
Am i missing something or has this been ommited from the documenatation? At no point did i notice this in the configuration documentation;
Configuring a trusted vendor list
Agents cannot be installed on some network devices such as printers or IP
telephones. To allow for those cases, you can configure a trusted vendor list. If
the name of the vendor is considered trusted, then the Symantec NAC Integrated
Enforcer will not authenticate the device. The devices will obtain normal IP
addresses from the DHCP server.
To configure a trusted vendor list
1 On the Windows taskbar of the Integrated Enforcer computer, click Start >
Programs > Symantec Endpoint Protection > Symantec NAC Integrated
Enforcer.
2 In the left-hand panel, click Symantec Integrated Enforcer > Configure >
DHCP Trusted Vendors Configuration.
3 To enable the trusted vendor list, check Turn on Trusted Vendors.
When the Turn on Trusted Vendors box is checked, Host Integrity will not
be enforced for DHCP traffic from the selected trusted vendors.
4 Select the vendors you want to establish as trusted vendors.
5 Click Save.
This would have saved me considerable time and cost just mentioning here that the Enforcer needed to be set in Allow all mode.
My rant is somewhat over so if I am completely wrong about this, please feel free to let me know. Hopefully this may even save someone the few minutes or in my case hours of frustration it took to try and configure the trusted vendors configuration.
It would probably be more
It would probably be more helpful to other people if it said "Trusted Vendors Configuration" in the title somewhere. I'm not sure if you can edit the title of original discussions or whether a moderator would have to do that for you.
There we go, Done.
There we go, Done.
Would you like to reply?
Login or Register to post your comment.