Endpoint Protection

 View Only
  • 1.  Query

    Posted Aug 19, 2011 12:21 AM

    Query:- If we configure GUP working on 2967 Port , So GUP server is telnet on 2967 from SEP agent and also required Port 80 ??

    and second From SEPM to GUP We need to open SAme as Port 80 ??

     



  • 2.  RE: Query

    Posted Aug 19, 2011 01:43 AM

    GUP is also a client so it needs port 80 to talk to SEPM like all others.

    For clients to take updates from GUP. 2967 should be open.

    ***********************************************************************

    When you make a computer as GUP , that means its providing a service, when you are providing a service, there is PORT (like door) associated with that, 

    If I say HTTP service, its on port 80 , DNS on 53, simillary GUP on 2967 ( Configurable thought !!)



  • 3.  RE: Query

    Broadcom Employee
    Posted Aug 19, 2011 02:04 AM

    yes, client will still need to talk to SEPM for definition, hence client should able to contact GUP on 2967 and SEPM on assigned port ( 8014 or 80).



  • 4.  RE: Query

    Trusted Advisor
    Posted Aug 19, 2011 08:06 AM

    Hello,

    Please understand: 

     

    Port Number Port Type Initiated by Listening Process Description
    80, 8014 TCP SEP Clients svchost.exe (IIS) Communication between the SEPM manager and SEP clients and Enforcers. (8014 in MR3 and later builds, 80 in older).

     

    2967 TCP SEP Clients Smc.exe The Group Update Provider (GUP) proxy functionality of SEP client listens on this port.

     

    Here, SEPM  <----communicates----->  SEP and vice versa on port 80/8014, when it comes to SEP client which works as Group Update Provider, the proxy functionality of SEP client listens on 2967port.

    Reference: http://www.symantec.com/docs/TECH102416

    http://www.symantec.com/docs/HOWTO26654



  • 5.  RE: Query
    Best Answer

    Posted Aug 19, 2011 11:27 AM

    GUP to SEPM (80 or 8014)

    GUP to Client ( 2967)

    Client to SEPM  (80 or 8014)

    GUP in a JUST NORMAL SEP Client

    When SEPM pushes the defs, it doesn't telnet to the client and then push the defs.

    It pushes the def on the port that is configuired, if the port is open the defs go to the client.

    If telent is no connecting to a machine on specfic port that doesn't mean that the port is blocked.