Endpoint Protection

 View Only
Expand all | Collapse all

Is it possible to manage a client that is not on the domain?

Migration User

Migration UserMay 27, 2009 04:45 PM

Migration User

Migration UserMay 28, 2009 04:56 AM

Migration User

Migration UserMay 28, 2009 01:38 PM

  • 1.  Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 04:36 PM

    Symantec Endpoint Manager is installed on a domain.

    I have many managed computer on the domaine.

    Can i do the same thing on a non-domain computer?

    I gonna have to set local credential of the computer insted of my domain admin acount when i deploy the Antiviruse from the server but after this...

    I am going to be able to see the virus definition version and manage the scan from the server?

    Even if the password of the account which I used during the installation changes?

    Thanks!

    Jim



  • 2.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 04:45 PM
    yep, no problems with that


  • 3.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 06:17 PM
    @Jim2009:

    Finding unmanaged computers would allow you to search either by IP or Computer Name with Logon credentials that can allow you to logon on a Domain or Workgroup level. It's in the Clients window of SEP Management Console.

    After installation, as long as the connection between the server and client is maintained or can be made, then you can manage the computer.

    Is this for a desktop or a laptop?


  • 4.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 08:21 PM
    It's for laptop.

    What do you mean by as long as the connection between the server and client is maintained or can be made?

    Laptops goes out of the network often in a week.

    When they come back the connection can be done without any credential?

    If i understand, the credential is only for the installation, after the client can contact the server without any problem is the computer is on the same network.

    Thanks!

    Jim


  • 5.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 09:27 PM
    You can enable locations to get the job done, one location is the client communication to the management server by default, and other location is client not communicate to the management server. each location setting can have its own way to configure the policy, I think the most you care is how client can receive virus definitions when the laptops are not communicating to your management, which you can configure the client to go to Symantec LU site to receive the av definitions. Hope this is helpful.


  • 6.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 09:50 PM
    I know about location and how to configure update for laptop when they are not on the network.

    I just want to be sure that i can see  information about Virus definition version, viruses detection... of non-domain computer.

    Thanks

    Jim


  • 7.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 10:04 PM

    When the laptop connects to the network. It will report its logs to the SEPM.
    I'm assuming that it gets its updates from the internet.



  • 8.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 27, 2009 10:46 PM
    It is possible, but you will need open the firewall port so that your client can communicate with your management server. but I will not recommend to do that.

    Here is the SEP communication port
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007090614430148


  • 9.  RE: Is it possible to manage a client that is not on the domain?

    Broadcom Employee
    Posted May 28, 2009 01:37 AM
    yes, you need to open a port between the client and the SEPM, however you can customize the port.

    Cheers
    Pete!


  • 10.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 28, 2009 04:21 AM
    You can manage all ur clients if it is accesseble in network



  • 11.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 28, 2009 04:41 AM
    Say you have 50 clients on a diffrent domain or a workgroup out of which 10 are laptops.

    For the clients to be able to get updates from the server and to be able to communicate to the server

    1)Make sure you are able to ping client from the server
    2)Make sure port for File & Print sharing are open for Client to be able to post logs and retreive updates from the server.
    3)For the laptops you can put them in a diffrent group and you can enable Manual Liveupdate scheduling and downloading.
    4)It does not matter how you are installing SEP on them Deploying them or Locally installing them with the exported package.


  • 12.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 28, 2009 04:56 AM
    yes, it is possible.


  • 13.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 28, 2009 05:16 AM
    HAHA. ROTFFL !!!!!

    @ Kajal - WOW, the simplest answer I've seen till date on the forums!!!!!


  • 14.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 28, 2009 05:53 AM
    you can create new location. thats why you can create new live update policy.
    we have laptops too and i create new location. and out of office rule. its rule works with this rule
    "If client cannot connect to SEPM" change location"
    and out of office rule say go to internet for live update.
    Have a nice day. 


  • 15.  RE: Is it possible to manage a client that is not on the domain?
    Best Answer

    Posted May 28, 2009 07:28 AM
    "I just want to be sure that i can see information about Virus definition version, viruses detection... of non-domain computer"

    No need to worry whether the client is part of Domain or Workgroup.

    After creating a Client installation package, if you install it on the Domain Client or Workgroup Client it will start reporting to the SEPM and provide the information about the Defintion date, scan or not etc...

    Only for laptop users who are roaming for them the information on the console will not be changed untill and unless they are on network.

    Hope this address your query


  • 16.  RE: Is it possible to manage a client that is not on the domain?

    Posted May 28, 2009 01:38 PM
    Tank you for all you answer!!!

    Jim