Endpoint Protection

 View Only
  • 1.  Location awareness

    Posted Mar 18, 2015 06:27 AM

     

    Hi I have configured location on existing group but after the clients connect through vpn it doesnt show the correct location,  and also the vpn pop up  doesnt appear and the policy related to VPN also doesnt get apply. Please help me how can i check the logs to   troubleshoot firther and if we need to configure debugging logs what are the settings need to apply.



  • 2.  RE: Location awareness

    Posted Mar 18, 2015 06:30 AM

    What condition are you using to determine the location?

    You should be able to enable ALS debugging

    How to use the advanced debug logging options for the Symantec Endpoint Protection client in SymHelp



  • 3.  RE: Location awareness

    Posted Mar 18, 2015 09:57 AM
      |   view attached

    Condition is through IP address and DNS server ip of Head office which is located in germany.



  • 4.  RE: Location awareness

    Broadcom Employee
    Posted Mar 18, 2015 10:08 AM

    Hi,

    Thank you for posting in Symantec community.

    Make sure Locations are being applied correctly on all network adapters, or only when connecting over one? (For instance: when the laptop is connected to the office network, it correctly detects the configured location, but when connecting over the wireless network card, it is not being assigned to the WIFI" location.)

    The challenge today's Network Administrator is facing is the various types of devices that appear in the corporate network through several network connection interfaces such as Eternet, WiFi and VPN.
    Furthermore the devices will be often be authorized corporate devices or personal devices.

    The following items are important to consider:

    • Location of the endpoint: Internet or the Corporate Network

    • Connection is established by what Interface: Cable, WLAN, VPN

    •  Device is a managed standard corporate device or non-standard allowed device.

    • The solution should be tamperproof like used within the Microsoft location awareness feature that separates, public, private and domain as DNS requests or pings can be manipulated

    I would recommend to go through the following articles & see the given examples:

    Usage of Location Awareness and Network Threat Protection with SEP 11 and SEP 12.1

    http://www.symantec.com/docs/TECH195231

    Best Practices for Symantec Endpoint Protection Location Awareness

    http://www.symantec.com/docs/TECH98211

    Known issue: Cisco Anyconnect VPN client is not causing the location to switch on the Symantec Endpoint Protection (SEP) client

    http://www.symantec.com/docs/TECH156546

    If you feel everything is setup correctly then need to go through the logs to troubleshoot further.