Endpoint Protection

 View Only
  • 1.  SEP installation Q

    Posted Sep 07, 2010 06:21 AM
    1. Is there a way to configure disable notification of IPS port scanning on clients?
    2. How can I know that branch office clients getting LU from Branch office GUP server? Just I want to make sure branch office client will get LU from GUP which I configure on each Branch office.
    3. How to configure dedicated Group Update Provider to distribute content to its one branch office only clients?
    4. Is there a way in console client tab to view more than 1000 user?
    5. I have schedule scan on weekly base on 12 noon Monday, if client is switched off on Monday and client is switched on Wednesday does schedule scan will run when client is up. Is it going to wait for coming Monday to start the scanning?
    6. In SAV 10 schedule can show status of scanning on the client side. But in SEP 11 how I can configure to show scan status on the client side?
    7. When I click on LiveUpdate on client PC it shows Initializing...Connecting to liveupdate.symantecliveupdate.com...so this means it is downloading from syamntecliveupdate Server instance of SEPM server. Is there a way to define to connect only to manage SEPM server when I click on LiveUpdate tab on client. I don’t want to disable manual LiveUpdate in LiveUpdate policy.


  • 2.  RE: SEP installation Q
    Best Answer

    Posted Sep 07, 2010 06:30 AM

    1.            Is there a way to configure disable notification of IPS port scanning on
    clients?
     
    How to Disable Client Intrusion Prevention Notifications in Symantec Endpoint Protection Manager
     
     
    http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/fc03b94f7fe2910988257457005b1343?OpenDocument
     
    Title: 'How to Disable all Notifications in the Symantec Endpoint Protection Manager and Symantec Endpoint Protection Client (Managed and Unmanaged)'
    Document ID: 2009032320071848
    > Web URL: http://service1.symantec.com/support/ent-security.nsf/docid/2009032320071848?Open&seg=ent
     
     
     
    2.            How can I know that branch office clients getting LU from Branch office
    GUP server? Just I want to make sure branch office client will get LU from
    GUP which I configure on each Branch office.
    ---You can check this from the  Registry or from the sylink log.
     
     
    Title: 'How to confirm if Clients are receiving LiveUpdate content from Group Update Providers (GUPs)'
    Document ID: 2009110311145748
    > Web URL: http://service1.symantec.com/support/ent-security.nsf/docid/2009110311145748?Open&seg=ent
     
     
    On the client, look in the registry under
    HKEY_LOCAL_MACHINE\Software\Symantec\Symantec Endpoint Protection\LiveUpdate.
     
    Check the settings for the following keys:
     
    ■ UseLiveUpdateServer
    If this key is set to 1, the client uses an internal LiveUpdate server or Symantec LiveUpdate directly.
     
    ■ UseManagementServer   If this key is set to 1, the client uses the management server.
    ■ UseMasterClient   If this key is set to 1, the client uses a group update provider
     
    3.            How to configure dedicated Group Update Provider to distribute content to
    its one branch office only clients?
     
    ---Create a Single GUP for each group.
     
     
     
     
    4.            Is there a way in console client tab to view more than 1000 user?
    --It cannot be set to be more than 1000, An alternative would be to use the Monitors page, select specific groups via the filter and then sort the resulting client list as desired.
     
    A future version of SEP will also allow sorting of columns across multiple pages of SEP clients on the SEPM clients page.
     
     
     
     
    5.            I have schedule scan on weekly base on 12 noon Monday, if client is
    switched off on Monday and client is switched on Wednesday does schedule
    scan will run when client is up. Is it going to wait for coming Monday to
    start the scanning?
    --It will run as a missed event


     
    6.            In SAV 10 schedule can show status of scanning on the client side. But in
    SEP 11 how I can configure to show scan status on the client side?
    If you would like to see the progress on the clients, you will need to edit your antivirus policy to show the status of scans.  To do this:
    1. Go to Policies
    2.  Select your Antivirus and Antispyware policy
    3.  Right click and choose edit
    4.  Select Administrator-definied Scans.
    5.  Choose the Advanced tab.
    6.  Under the Advanced tab go to the bottom under Show Progress Options, click the drop-down box and choose Show scan progress or Show scan progress if risk detected.


    7.            When I click on LiveUpdate on client PC it shows
    Initializing...Connecting to liveupdate.symantecliveupdate.com...so this
    means it is downloading from syamntecliveupdate Server instance of SEPM
    server. Is there a way to define to connect only to manage SEPM server when
    I click on LiveUpdate tab on client. I don’t want to disable manual
    LiveUpdate in LiveUpdate policy.
     
    ..By default it goes to the SEPM only



  • 3.  RE: SEP installation Q



  • 4.  RE: SEP installation Q

    Posted Sep 07, 2010 06:41 AM

    How to Create a Single GUP for each group.
    After adding group GUP in LU policy to i need to specify a group?
    can you procide step by step to configur GUP




     



  • 5.  RE: SEP installation Q

    Posted Sep 07, 2010 06:42 AM

    Hello,
    1- I will search
    2-ıf you configure you LU policy "Don't go to Sep manager for LU" you can be sure and there is a tool for GUP "SEP_Content_DistMonitor_v4.7_BETA"
    3- you can create groups and create new LU policy for each branch offices.
    4-no you cannot, only you can export all users to excel,
    5- yes you can configure scheduled scans there is a option in scan tab "Missed scheduled scans" unchec "retry the scan within" therefore clients will wait to newt monday.
    6- you can see result in logs tab in client side. "view logs" > "antivirus and antispy protection" > Scan logs.

    7-if client is managed first goest to sep manager. and you can configure LU policy for GUP or LUA.

    Best Regards.

    Fatih



  • 6.  RE: SEP installation Q



  • 7.  RE: SEP installation Q

    Posted Sep 07, 2010 06:47 AM
    Regarding Q3.if you use multiple GUP option also all clients will receives updates only form the GUP which is present in the same subnet....


  • 8.  RE: SEP installation Q

    Posted Sep 07, 2010 06:51 AM

    i have imported groups form AD and i cant move AD groups



  • 9.  RE: SEP installation Q

    Posted Sep 07, 2010 09:53 AM
    That is  correct, you cannot  move AD groups. You need to do changes in your  AD, and then sync with SEPM, so that  those  changes would be reflected in sepm.


  • 10.  RE: SEP installation Q

    Posted Sep 08, 2010 05:53 AM
    Thanks all for your help