Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

multiple connections on port 8014 even though group update provider setup

Created: 14 Oct 2013 | 7 comments

We have a remote office that using symantec endpoint.  They have about 15 pcs located there.  In order to limit the downloading of definitions, I have setup the liveupdate policy for this group to use a group update provider (one local pc) that is located at on their network,  But according to my watchguard I still have multiple connections coming from them on port 8014.  Was is the deal?
Using symantec endpoint version - 12.1.2100.2093
the logs on the local pcs showes that its getting the def info from that group provider

Operating Systems:

Comments 7 CommentsJump to latest comment

.Brian's picture

Clients will still check in based on their heartbeat to upload logs, grab a new policy, etc. This all happens over 8014.

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

Mithun Sanghavi's picture

Hello,

I agree.

Port 8014 is used for Communication between the SEP manager and SEP clients and Enforcers by default.

Which Communications Ports does Symantec Endpoint Protection use?

http://www.symantec.com/docs/TECH163787

Symantec Endpoint Protection: The Heartbeat Process

http://www.symantec.com/docs/TECH191617

Hope that helps!!

Mithun Sanghavi
Senior Consultant
MIM | MCSA | MCTS | STS | SSE | SSE+ | ITIL v3

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

techfusion's picture

interesting - this lead me to other links

is this one still valid and if so

http://www.symantec.com/business/support/index?page=content&id=TECH94122

so it sounds like i should change to pull method.  What should the heartbeat interval be?  4-8hrs so it only pulls 3x times a day?

.Brian's picture

You can set the heartbeat to something like 30 mins. Just be aware that if an outbreak occurs, you may not be notified right away. I would definitly set to Pull mode though

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

SUPPORT-2-SUPPORT's picture

Set the hearbeat interval and randomization as per the count of the group (e.g. 1 hour if having more than 300 clients)

Regards,

S2S

Please don't forget to mark your thread solved with whatever answer helped you.

techfusion's picture

changed to pull method with interval of 30 min - randomization is 5 min

Thanks for your help everyone 

.Brian's picture

Has this helped?

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.