Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

LiveUpdate Policies from xdb file

Updated: 21 May 2010 | 6 comments
sec091's picture
0 0 Votes
Login to vote

I have a new project of upgrading a group of workstations from SAV 10 to SEP 11.  The AV licenses on these computers recently expired and now need our new SEP 11 software.  The only difference between these computers and the others on our network is the way in which they are going to get their LiveUpdate Content.  The other computers on my network go to the default Symantec LiveUpdate server and the management server on a daily basis.  These workstations can only be updated if I get both the go ahead from another company after they have tested the newer policies and I receive the .xdb from them.  I then would go ahead and push out this new policy to the group of workstations.  

The company that does all this testing suggested that I go ahead and install another SEPM on their server that controls all these workstations (this is the way we had done it with SAV 10, before I started work here and moved to SEP 11).  But I feel that there is just a simple way of adding another group and creating a non-shared LiveUpdate policy and telling these computers not to go to the default Symantec LiveUpdate server and only do LiveUpdate when I tell it to and point to the .xdb.  I have managed to make a group where the computers do not do LiveUpdates on their own, but I don't see a way to point to a .xdb and send out the content. 

Do I have to install LiveUpdate Administrator to do this?  Or is there a more simple way to do what I am trying to do?

Thanks,

Storm

Comments

Swaminathan's picture
28
Oct
2009
0 Votes 0
Login to vote

Hi, .xdb was used by SAV and

Hi,

.xdb was used by SAV and SEP does not use it, it uses .jdb

Note: .jdb file will only update the Antivirus and Antispyware definitions and not the PTP and NTP (IPS) definitions.

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2009072204590148

shp's picture
28
Oct
2009
0 Votes 0
Login to vote

You can have one SEP. Create

You can have one SEP.

Create two groups

Group1( default Symantec LiveUpdate server)
You can have sub group based on office or sections and assign a GUP(Which is equivalent to secondary servers in SAV) for updating client.
REF:
http://service1.symantec.com/SUPPORT/ent-security....

OR

Configure a nonshared liveupdate policy to point to symantec liveupdate site and schedule it whenever you want.

Group2( Internal Liveupdate server). 

You can use LUA and create a distribution center on remote site. You can distribute the liveupdate contect whenever you want.

Creat a liveupdate policy to point all the client to that distribution center. whenever LUA distributes updates to distribution center client will get updates... you will have control over the updation.
REF:
https://www-secure.symantec.com/connect/articles/i...
https://www-secure.symantec.com/connect/articles/c...

You can have GUP also.....

Regards,
Srinivas H.P.
HCL Infosystems Ltd

sandip_sali's picture
28
Oct
2009
0 Votes 0
Login to vote

LUA

The option of a Live Update Administrator is Good as it will ensure Centralized Distribution of the virus definitions.
Check this link :-      http://service1.symantec.com/SUPPORT/ent-security....

Thanks & Regards Sandip C Sali

sec091's picture
29
Oct
2009
0 Votes 0
Login to vote

Installed and configured LUA

I have installed and configured the LUA to work with my SEPM.  I have a new group in SEPM that only uses the LUA Distribution Center for its LiveUpdates.  But I am still confused on setting up my LUA Distribution. 

What I need is a Distribution target that points to one set of definitions that I receive from a company that controls and manages one set of workstations.  This definition package has been tested by them and need no testing from me or my LUA.  Both the LUA and the LiveUpdate on my SEPM side for this one group CANNOT pull updates from symantec.  The updates will only come from the file they send me.  I can't see the folder I am supposed to place this .zip file in and what to rename instead of .zip to allow the Distribution to notice this package as a definitions package. 

Here is an image of the files that were contained inside the zip file that I was sent.  This is the set of policies that they say they support for SEP 11.  Are these files compatible with SEP 11 or are they really still for SAV 10? 

Capture.JPG

sec091's picture
29
Oct
2009
0 Votes 0
Login to vote

Found a couple good articles

I found a good article called "How to update definitions for Symantec Endpoint Protection Manager using a JDB file".  This explains how to download and place a JDB file in the \Symantec Endpoint Protection Manager\date\inbox\content\incoming  directory.  Once this is done, it seems that SEPM automatically applies this policy to all groups that are created in this SEPM. 

 I also found the article called "How to manually update definitions for a managed Symantec Endpoint Protection Client using the .jdb file".  This article shows how to do this on the client machine.  Is there a way to do this remotely one one group?  Or is the aforementioned technique going to only perform policy updates one the groups in which I have enabled the 3rd party content management?

Thanks for the help.

-Storm

shp's picture
29
Oct
2009
0 Votes 0
Login to vote

If they are using a tested

If they are using a tested jdb file then you can update as mentioned in the above article...

Even SEP is having a option to lock the liveupdate content to one particular revision..
Its available under policies-->Liveupdate-->Liveupdate content policy....

Regards,
Srinivas H.P.
HCL Infosystems Ltd