LiveUpdate with Reporting

This issue has been solved. See solution.
Symantec World's picture

Dear Team,

Customer has 13000 odd sep clients installed, with one SEP sever at HO and all clients scattered across locations connected via WAN.

Requirement: Clients should take update from HO SEP server when they are connected any coporate LAN/WAN Network.

If the client is not connected to corporate network SEP should take update from LiveUPdate server or SEP Manager which ever is best and also should report back its update status to SEP manager so tht even if client laptop is out for 2 months we are aware about status of definition update.

Very appreciate your prompt response.appp ge { margin: 0.79in }
P { margin-bottom: 0.08in }
A:link { so-language: zxx }
-->

 

appreciate

Rafeeq's picture

Hi

you need to create location specific policy check this link and post

You may follow the following link to create location specific policy

https://www-secure.symantec.com/connect/forums/endpoint-11-live-update-clients

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008040214442248

 

Rafeeq

sandip_sali's picture

LiveUpdate with Reporting

Solution

Hi,

      You need to configure the Live Update Policy to take the updates from the desired location.

imagebrowser image

Thanks & Regards

Sandip C Sali

kristopherjturner's picture

In this case it does sound

In this case it does sound like three locations could be configured.

1. Network or Office
2. Remote
3. VPN

This is how we have done it at other offices with that situation.

The Network Location we had a LiveUpdate policy set to pull from the SEPM on that site. We had it only to use the Management server for updates.

The Remote Location Policy we had LiveUpdate set to allow updates via LiveUpdate at Symantec.

The VPN Location we had setup so when the client was connected it still would report back to the SEPM.  On this location policy we still have the client grabbing it's live updates from Symantec.

Symantec World's picture

Re

Dear All,

Thanx for your comments,

But we already configured liveupdate options and all laptops users are able to download definition from Symantec LiveUpdate, but never report to manager b.coz he is not connected to my lan.

What I want when laptop users are away from the local network for two to four month they should report my SEPM that I am updated.

We are not using VPN.

Thanxxx...

Regards,
M.R

Rafeeq's picture

Hi

If i understood this line correct

"What I want when laptop users are away from the local network for two to four month they should report my SEPM that I am updated"

When users are away , not connected they cannot tell manager that they are updated. There should be some communication between the client and the manager.

is this what you were looking for?

Rafeeq

Symantec World's picture

Re

Hi Rafeeq,

Yes you correct but there is no solution?

I open a case in support and below is the reply from the support.

 Hello Sir,
 
Thank you for contacting Symantec. It was my pleasure assisting you on the issue faced under case xxx-xxx-xxx.
 
Please find below the clarification to the issue that you required.
 
Requirement 1 : Clients should take update from HO SEP server when they are connected any corporate LAN/WAN Network.
This is going to be possible, as the client that connects to the corporate network via the VPN, will get an IP assigned to it which is part of the IP range of the corporate that the administrators sets on the VPN server.

Requirement 2:
1)   If the client is not connected to corporate network SEP should take update from LiveUPdate server or SEP Manager which ever is best….
Here we can set up a location awareness policy in such a way that when the client is out of the corporate network, the Liveupdate button on the SEP UI will be enabled and we can set a Liveupdate schedule.
2)   and also should report back its update status to SEP manager so that even if client laptop is out for 2 months    we are aware about status of definition update.

This is shall not be possible as the client need to upload the logs to the SEPM for any reporting, however if the computer connects to the corporate network via the VPN, within 14 days (default period of the client log retention) then the logs will also be uploaded to the SEPM.
Due to the security risks inherent in exposing a server to the Internet, the configuration of making Symantec Endpoint Manager accessible on the Internet is neither recommended nor endorsed by Symantec.
 
Thank You.
With Regards, 

Please revert if you have an option to make this possible.

Regards,
M.R

Rafeeq's picture

Nope

This is the only option ,no way to tell them that they are updated without reporting to the manager.

 

Rafeeq

Peterpan's picture

yes I agreed with rafeeq, you

yes I agreed with rafeeq, you shoul asure that sep client is connected and has a green dot which mean the spe client are ready for getting updates and policy from the management server

:-)