Endpoint Protection

 View Only
Expand all | Collapse all

Live Update from Management server only

Migration User

Migration UserJan 12, 2010 07:09 AM

Rafeeq

RafeeqJan 12, 2010 10:47 AM

Migration User

Migration UserJan 12, 2010 12:21 PM

  • 1.  Live Update from Management server only

    Posted Jan 08, 2010 10:27 AM
    I just wanted to clarify if I am doing this correctly.
     
    I want to cut down the traffic on the network by clients getting updates from the management server instead of having every client getting updates from the Symantec LiveUpdate server individually. The way to do this is to set a Live Update Policy for the clients, in the Server Settings and only checking the use the Default Management Server (recommended setting)? The Live Update scheduling is then not enabled so does this mean that the default management server updates the clients as soon it receives the latest updates?


  • 2.  RE: Live Update from Management server only

    Posted Jan 08, 2010 10:33 AM

    Does this mean that the default management server updates the clients as soon it receives the latest updates?


    The client initiates the communication with the SEPM. This is commonly known as heart beat interval and by default its set to 5 minutes. When the client contacts the SEPM for updates or any policy cahnges the SEPM verifes it and then gives the latest definitions if the client does not have it.


  • 3.  RE: Live Update from Management server only

    Posted Jan 08, 2010 10:33 AM
    The way to do this is to set a Live Update Policy for the clients, in the Server Settings and only checking the use the Default Management Server (recommended setting)?
    yes

    The Live Update scheduling is then not enabled so does this mean that the default management server updates the clients as soon it receives the latest updates?
    Not as soon as it recives the update but in  the next heart beat  after the SEPM is updated , the client gets the information that the sepm is updated and client requests for the update and get updated.by default the heartbeat is 5 min.


  • 4.  RE: Live Update from Management server only

    Posted Jan 08, 2010 11:59 AM
    This is a sort of confusing part for most of the users.
    when you have management server list selected you dont have schedule for it, it will be greayed out meaning there is no schedule between manager and the clinets, the updates are sent immediately when the manager has,

    The schedule is only enabled when you select liveupdate server, in that you can set schedule to go out to internet, however there is no schedule between manager and the client. 


    https://www-secure.symantec.com/connect/forums/deploy-virus-definitons


  • 5.  RE: Live Update from Management server only

    Posted Jan 09, 2010 12:57 AM
    As  preset in earlier post you cannot schedule the updations from SEPM.The clients will get updates in its every heartbeat .
    --------------------------------------------------------------------------------------------------------------------------------------------
     If you want to schedule the updates you have to use liveupdate server(Internal or external) for updating your clients.In liveupdate policy select only liveupdate server and in schedule tab do a scheduling you can control the updation time
    -------------------------------------------------------------------------------------------------------------------------------------------
    I think GUP will be ideal solution for you ,it can reduce the traffic a lot
    For more info refer below docs
    Symantec Endpoint Protection 11.0 Group Update Provider (GUP)
    Best practices for Group Update Provider (GUP) from Symantec Endpoint Protection MR3 or earlier builds
    How to configure GUP bandwidth throttling in Symantec Endpoint Protection 11.0 MR4?
    Configuring the Group Update Provider (GUP) in Symantec Endpoint Protection 11.0 RU5


  • 6.  RE: Live Update from Management server only

    Posted Jan 10, 2010 03:54 PM
     I think your questions where answered above but I also wanted to draw your attention to our best practice guide for mobile users. Usually you will want a slightly different live update setup for laptops or other computers that will not always be connected to the SEPM. 

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008040214442248?Open&seg=ent

    Cheers
    Grant


  • 7.  RE: Live Update from Management server only

    Posted Jan 12, 2010 07:09 AM

    Thanks a bunch.



  • 8.  RE: Live Update from Management server only

    Posted Jan 12, 2010 10:29 AM
    Actually I do have another question about this.

    We only have about 200 clients here. I'm not setting up a GUP because all are on the same subnet with the exception of a few. I have a LiveUpdate policy for the majority of the clients that get updates from the Default Management server only. The SEPM is set to get updates from the Symantec LiveUpdate Server and the client on the SEPM has it's own LiveUpdate policy set to get updates from both the Default Management server and the Symantec LiveUpdate Server. I have been having a problem recently of where the clients are taking some time or not at all pulling the updates from the SEPM unless I manually do a "Run Command From Group" - "Update Content", than they update.

    Any suggestions?


  • 9.  RE: Live Update from Management server only

    Posted Jan 12, 2010 10:47 AM
    Are you running on MU5 ?
     


  • 10.  RE: Live Update from Management server only

    Posted Jan 12, 2010 12:21 PM
    Yes 11.0.5002.333


  • 11.  RE: Live Update from Management server only

    Posted Jan 12, 2010 06:44 PM
     How much is "some time"? 

    Clients only check-in with the SEPM at the "heartbeat interval". So if your heartbeat interval is set to 60 minutes then they will only pull updates every 60 minutes. By running a command you are actually forcing a heartbeat. So my suggestion is too look at what your heartbeat is set to, and wait that amount of time to see if the client updates. If it is still not updating outside of that interval then please come back and let us know.

    Thanks
    Grant


  • 12.  RE: Live Update from Management server only

    Posted Jan 12, 2010 11:44 PM
     i am agreeing with Grant .An addition his comment. It will be better to enable randomization.you can set this for 5 min.This also increase the possibility of clients getting connected in different time.


  • 13.  RE: Live Update from Management server only

    Posted Jan 13, 2010 07:25 AM
    Just to let you know this only started happening after the new year.

    Is this set in the LiveUpdate policy or in the ADMIN, Site Properties, LiveUpdate section? In the LiveUpdate policy, Randomization is set to two hours and the retry is set to one hour.

    In the Site Properties LiveUpdate section updates run daily, the Retry  Interval is set to 15 minutes and the Retry window is one hour. The start time window is set to start: 12:00pm and end: 12:00 am

    Also these clients have a policy assigned to them with only the Use Default Managment Server checked, Use a LiveUpdate Server is unchecked, and the Scedule and Advanced sections are grayed out.

    The few clients that have Use "Default Managment Server " checked, "Use a LiveUpdate Server" checked, "Enable LiveUpdate scheduling" checked, and "Allow the user to manually launch LiveUpdate" checked update with no issues. (I set this for some of our servers to have this capability).






  • 14.  RE: Live Update from Management server only

    Posted Jan 13, 2010 07:56 AM
    Both of US are referring to the communication settings
    It is present in Clients---> <prefered group> --->policies
     


  • 15.  RE: Live Update from Management server only

    Posted Jan 13, 2010 08:49 AM
    Ok.

    Hearbeat Interval is 5 minutes
    Download Randomization is enabled and set to 5 minutes
    Download is in Push Mode



  • 16.  RE: Live Update from Management server only

    Posted Jan 14, 2010 09:41 AM

    Thanks

    The hearbeat is set to 5 minutes.

    I have several groups created but for example I have a workstations group created. The heartbeat interval and download randomization are set for 5 minutes. Since I want these clients to only get updates from the management server only I have "use the default management server" checked. "Use a Live Update server" is not checked.

    The only way to get around this problem is to either force a "content update" or check the "Use a LiveUpdate server". I could do this and I have but isn't having "use the default management server" only supposed to work?

    I've also tried changing the communication setting to "Pull Mode" and setting up a GUP but that didn't help.

    *** I only have 2 groups checked to both "use the default management server" and "Use a Live Update server" and of course they work fine.

    I've also run the steps in this link
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008041516215948

    one of the numbered folders in the "C:\Program Files\Common Files\Symantec Shared\VirusDefs" path would not allow me to delete it, "20100112.053"

    but I went thorugh the steps anyway. The last step is to run a SEPM live update, I did receive an error

    "January 14, 2010 8:32:59 AM EST: There is an error in the LiveUpdate upload URL parameters. [Site: My Site] [Server: xxxxxxx]"

    January 14, 2010 8:36:02 AM EST: Cleaned up 1 LiveUpdate downloaded content [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:55 AM EST: LiveUpdate succeeded. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:55 AM EST: LUALL.EXE finished running. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:34 AM EST: LUALL.EXE successfully updated the content. Return code = 0. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:16 AM EST: Symantec Endpoint Protection Win64 11.0.4202.75 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:14 AM EST: Symantec Endpoint Protection Win64 11.0.5002.333 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:11 AM EST: Symantec Endpoint Protection Win32 11.0.4202.75 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:08 AM EST: Symantec Endpoint Protection Win32 11.0.5002.333 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:07 AM EST: TruScan proactive threat scan engine Win32 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:06 AM EST: TruScan proactive threat scan commercial application list Win32 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:06 AM EST: TruScan proactive threat scan whitelist Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:05 AM EST: Intrusion Prevention signatures Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:05 AM EST: TruScan proactive threat scan engine Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:04 AM EST: Submission Control signatures 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:04 AM EST: TruScan proactive threat scan data 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:03 AM EST: TruScan proactive threat scan whitelist Win32 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:03 AM EST: TruScan proactive threat scan commercial application list Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:02 AM EST: Antivirus and antispyware definitions Win32 11.0 MicroDefsB.CurDefs was successfully updated. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:34:09 AM EST: Cleaned up 1 LiveUpdate downloaded content [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:36 AM EST: Decomposer Win32 and Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:35 AM EST: Symantec Endpoint Protection Manager Content Catalog 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:35 AM EST: TruScan proactive threat scan commercial application engine 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:35 AM EST: Antivirus and antispyware definitions Win64 11.0 MicroDefsB.CurDefs was successfully updated. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:32:59 AM EST: Intrusion Prevention signatures Win32 11.0 failed to update. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:32:59 AM EST: There is an error in the LiveUpdate upload URL parameters. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:29:22 AM EST: LUALL.EXE has been launched. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:29:22 AM EST: Download started. [Site: My Site] [Server: xxxxxxxxxx]

     After running this the client that is installed on the SEPM updated after about 5 minutes, with the rest I've waited about an hour and as you can see they are not updating.

    Definitions Computers  
    2010-01-13 rev. 050  1
     
    2010-01-12 rev. 053  1
     
    2010-01-12 rev. 025  2
     
    2010-01-11 rev. 024  195
     
    all others  4
     


     



  • 17.  RE: Live Update from Management server only

    Posted Jan 14, 2010 09:42 AM

    Thanks

    The hearbeat is set to 5 minutes.

    I have several groups created but for example I have a workstations group created. The heartbeat interval and download randomization are set for 5 minutes. Since I want these clients to only get updates from the management server only I have "use the default management server" checked. "Use a Live Update server" is not checked.

    The only way to get around this problem is to either force a "content update" or check the "Use a LiveUpdate server". I could do this and I have but isn't having "use the default management server" only supposed to work?

    I've also tried changing the communication setting to "Pull Mode" and setting up a GUP but that didn't help.

    *** I only have 2 groups checked to both "use the default management server" and "Use a Live Update server" and of course they work fine.

    I've also run the steps in this link
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008041516215948

    one of the numbered folders in the "C:\Program Files\Common Files\Symantec Shared\VirusDefs" path would not allow me to delete it, "20100112.053"

    but I went thorugh the steps anyway. The last step is to run a SEPM live update, I did receive an error

    "January 14, 2010 8:32:59 AM EST: There is an error in the LiveUpdate upload URL parameters. [Site: My Site] [Server: xxxxxxx]"

    January 14, 2010 8:36:02 AM EST: Cleaned up 1 LiveUpdate downloaded content [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:55 AM EST: LiveUpdate succeeded. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:55 AM EST: LUALL.EXE finished running. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:34 AM EST: LUALL.EXE successfully updated the content. Return code = 0. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:16 AM EST: Symantec Endpoint Protection Win64 11.0.4202.75 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:14 AM EST: Symantec Endpoint Protection Win64 11.0.5002.333 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:11 AM EST: Symantec Endpoint Protection Win32 11.0.4202.75 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:08 AM EST: Symantec Endpoint Protection Win32 11.0.5002.333 (English) is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:07 AM EST: TruScan proactive threat scan engine Win32 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:06 AM EST: TruScan proactive threat scan commercial application list Win32 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:06 AM EST: TruScan proactive threat scan whitelist Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:05 AM EST: Intrusion Prevention signatures Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:05 AM EST: TruScan proactive threat scan engine Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:04 AM EST: Submission Control signatures 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:04 AM EST: TruScan proactive threat scan data 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:03 AM EST: TruScan proactive threat scan whitelist Win32 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:03 AM EST: TruScan proactive threat scan commercial application list Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:35:02 AM EST: Antivirus and antispyware definitions Win32 11.0 MicroDefsB.CurDefs was successfully updated. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:34:09 AM EST: Cleaned up 1 LiveUpdate downloaded content [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:36 AM EST: Decomposer Win32 and Win64 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:35 AM EST: Symantec Endpoint Protection Manager Content Catalog 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:35 AM EST: TruScan proactive threat scan commercial application engine 11.0 is up-to-date. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:33:35 AM EST: Antivirus and antispyware definitions Win64 11.0 MicroDefsB.CurDefs was successfully updated. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:32:59 AM EST: Intrusion Prevention signatures Win32 11.0 failed to update. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:32:59 AM EST: There is an error in the LiveUpdate upload URL parameters. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:29:22 AM EST: LUALL.EXE has been launched. [Site: My Site] [Server: xxxxxxxxxx]

    January 14, 2010 8:29:22 AM EST: Download started. [Site: My Site] [Server: xxxxxxxxxx]

     After running this the client that is installed on the SEPM updated after about 5 minutes, with the rest I've waited about an hour and as you can see they are not updating.

    Definitions Computers  
    2010-01-13 rev. 050  1
     
    2010-01-12 rev. 053  1
     
    2010-01-12 rev. 025  2
     
    2010-01-11 rev. 024  195
     
    all others  4
     


     



  • 18.  RE: Live Update from Management server only
    Best Answer

    Posted Jan 14, 2010 12:39 PM
     Currently SEPM cannot handle/Distribute definitions dated 2010.Even though on home it shows SEPM def version is 12th Jan. but if you go to SEPm -Admin- Local Site- Show Liveupdate content--You will see the def Antivirus 32 bit would be 31-12-2009.

    All the clients that have got the definitions have got it from Internet ( "Use liveupdate Server" / Update Content )

    The 2010 fic for SEPM should be released today or tommorow.So I would suggest for a day or two select the " Use Liveupdate Server" to update the definitions.


  • 19.  RE: Live Update from Management server only

    Posted Jan 14, 2010 02:25 PM
     I agree with Vikram. In case anyone wants to know more about the 12-31-09 issue then please visit this link https://www-secure.symantec.com/connect/forums/official-status-sepm-definitions-stay-31-12-2009-last-updated-04-jan-2010. I has the latest information regarding the issue.

    Grant-


  • 20.  RE: Live Update from Management server only

    Posted Jan 15, 2010 12:18 AM
    Pls change it to push mode with Hear beat Interval 1 hour.Keep the randomization as 5 min only.This will reduce your traffic.
     


  • 21.  RE: Live Update from Management server only

    Posted Jan 17, 2010 12:46 PM
    Patch is out now to solve the 12-31-09 issue. More information can be found here http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2010010308571348.

    Grant-


  • 22.  RE: Live Update from Management server only

    Posted Jan 19, 2010 12:58 PM

    My clients are updating now. It's possible this 12-31-09 issue might have been part of the problem.

     

    Thank for your help!



  • 23.  RE: Live Update from Management server only

    Posted Jan 19, 2010 02:28 PM
     as i said above as well..this was very much the same issue..just because SEPM din't download 2010 defs and clients updated 2010 defs made everybody confused..