Endpoint Protection

 View Only
Expand all | Collapse all

SEPM 11.0.7 disable access to items

ℬrίαη

ℬrίαηNov 06, 2012 10:55 AM

  • 1.  SEPM 11.0.7 disable access to items

    Posted Nov 05, 2012 04:16 PM

    I've been able to find how to disable the Network Threat Protection setting.

    What I can't find, even though it's mentioned in these forums, is how to disable access to...

    • disable Antivirus and Antispyware Protection
    • disable Proactive Threat Protection
    • disable SEP from the taskbar

    Thanks



  • 2.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 05, 2012 04:30 PM

    Make sure the lock is closed in the AV policy for AutoProtect.

    Make sure the lock is closed in the AV policy for SONAR (unable to disable PTP)

    To disable SEP in task bar, do this,

    Go to Clients page

    Select a group you want to remove icon for

    Under location specific policies and settings, click + sign Location-specific Settings

    Click on Tasks next to Client user Interface Control Settings and select Edit Settings

    Select the Customize button

    Uncheck "Display the notification area icon"

    See these as a reference:

    https://www.symantec.com/business/support/index?page=content&id=TECH185903

    https://www.symantec.com/business/support/index?page=content&id=TECH136678

    That should do it

     

     



  • 3.  RE: SEPM 11.0.7 disable access to items



  • 4.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 09:17 AM

    I've tried all those but if I disable the NTP and PTP I won't have that protection.

     

    Also, I haven't made any changes and there are Security Status messages about Auto-Protect Failures on those computers. Not sure why that is.

    Under Monitors and Command Status, the completion status shows 0% for everything. The Details show Not Received for status.



  • 5.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 09:21 AM

    Not sure what you mean by not having that protection if disabling NTP and PTP? You don't want users to disable?



  • 6.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 09:34 AM

    Well, I'll have to say I didn't "get" something at first. The lock symbols are clickable LOL! I thought it had something to do with certain check combinations...wow, I'm done for the day lol.



  • 7.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 10:55 AM

    cool So it's good now?



  • 8.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 11:10 AM
      |   view attached

     

    Yes :)

     

    I attached a file with the report results.

    Security Status messages about Auto-Protect Failures on those computers. Not sure why that is.

    Under Monitors and Command Status, the completion status shows 0% for everything. The Details show Not Received for status.

    Attachment(s)

    docx
    report results.docx   16 KB 1 version


  • 9.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 11:39 AM

    Have you verified those PCs are reporting in to the SEPM? Have they been rebooted?



  • 10.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 12:08 PM

    How can I verify?

    They have been rebooted a few times. It's odd it shows those computers on the other items even on the home screen, but shows as failed on those couple things.

     

    Also, what would the differences between a GUP and Replication Partner be?



  • 11.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 12:52 PM

    GUP is same like al clients. it wil cache the updates and distribute to clients, they dont need to contact manager or internet for update.

    Replication : is what u see in Sepm A, will be same in SEPM B.

     



  • 12.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 01:38 PM

    You will see the green dot on the client.

    GUP provides content updates only to clients. You can setup to SEPMs to be replication partners to replicate logs, policies, etc.



  • 13.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 02:30 PM

    Ok, so GUP is more hierarchical and Rep Partner is more parallel.

     

    I checked and they have green dots.



  • 14.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 03:00 PM

    Also, what would cause the AD sync group to not display the computers that are in it? (they don't have SEP installed yet as I don't see them there) I could them under Find Unmanaged Computers as a workaround.



  • 15.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 03:09 PM

    Set the view to "Default view" when looking at the Client tab on the Clients page



  • 16.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 03:13 PM

    Haha! Thanks again. I think I've been staring at the screen too long lol.

     

    Can you also deploy clients using the Find Unmanaged Computers window? Or is it recommended to use the Migration and Deployment Wizard?

    If an x64 client was sent to an XP x86 PC it would/should fail, right?



  • 17.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 06, 2012 05:56 PM

    Yes, you can use Find Unmanaged to install SEP

    Yes, it will fail.



  • 18.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 09:06 AM

    Is there a way to find out where the SEP on the client PC received its updates from, such as SEPM or GUP?



  • 19.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 09:30 AM

    Look at the System Log on the client

    View Logs >> Client Management >> View Logs >> System Log

    You will see "Downloaded new content from..."

    This will tell you.



  • 20.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 10:21 AM

    Also, when SEP is deployed, does the AV updates go with it or install at some point later?



  • 21.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 10:27 AM

    Awesome! Thank you very much!

    I've seen a flow of how the system works, such as LiveUpdate>SEPM>GUP. So a computer in another octet will pick up only that one, SEPM as x.x.101.20, and GUP as x.xx102.34.

    Here's an interesting question which I'm sure will have a simple answer. If the server with GUP has two network cards, one x.x.102.x and the other 10.0.1.x, the clients (on a separated network which cannot access internet at all) will update only from the GUP, right?

     

    If I have a SEPM server and GUP in same net, x.x.101.x, how do I make everything, except what the GUP handles 10.0.1.x, go to the SEPM?



  • 22.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 10:42 AM

    The clients will only go to the GUP for content updates. The client will check in and upload logs, download policy, etc from the SEPM. This is mandatory and can't be changed or handled by the GUP.



  • 23.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 10:43 AM

    The client will be installed with defs however they may be out of date.

    You can deploy SEP with latest updates, see this:

    https://www.symantec.com/business/support/index?page=content&id=TECH104779



  • 24.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 11:49 AM

    So this would be the way things go...

     

    SiteA (x.x.101.x) has the SEPM

    SiteB (x.x.102.x) and SiteC (x.x.103.x) have GUPs

     

    PCs at SiteB will only go through SiteB GUP

    PCs at SiteC will only go through SiteC GUP

    PCs at SiteA will only go through SiteA SEPM



  • 25.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 11:54 AM

    Yes, you can set it up that way using Location Awareness. It really just depends on what you want.

     

    Setting up Scenario Two location awareness conditions

    https://www.symantec.com/business/support/index?page=content&id=HOWTO80747

    Usage of Location Awareness and Network Threat Protection with SEP 11 and SEP 12.1

    https://www.symantec.com/business/support/index?page=content&id=TECH195231



  • 26.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 03:03 PM

    Back to syncing above, what will happen if one of those computers in the AD sync had to be rebuilt? Will SEPM reinstall the software, or what would need to be done?



  • 27.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 03:20 PM

    It would need to be done manaully, unless you assigned an update package to the group or had a GPO in place.

    AD sync just keeps SEPM in sync with AD to manage your PCs. I won't automatically install SEP for you.



  • 28.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 03:32 PM

    Ok.

    Do you have a link with more info on assigning update packages?

    For GPO, would we use the the MSI from the extracted X:\Symantec EP 11.0.7\SEPWin64\x64 folder, and will the SEPM policies configure the PC?



  • 29.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 07, 2012 03:44 PM

    See this link on auto upgrade:

    https://www.symantec.com/business/support/index?page=content&id=TECH166317

    You will want to create a custom install package in the SEPM

    See this on GPO deployment:

    https://www.symantec.com/business/support/index?page=content&id=TECH91330



  • 30.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 09, 2012 09:40 AM

    Thanks Brian.

    I've been thinking on the subnets.

    ServerA is a SEPM, ServerB is a GUP, and ClientB1 is a PC in a ServerB's subnet.

    ServerB has two nics, one for domain network and the other for subnet (10.x.x.x).

    ServerB will receive updates from ServerA.

    Will ClientB1 receive updates from ServerB (GUP)?



  • 31.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 09, 2012 10:03 AM

    It will if you setup that condition in the location awareness policy. You can set a condition by IP subnet that says if ClientB1 has an IP in this subnet than it should be in Location X. As long as Location X has the LiveUpdate to point it to that GUP than it will get updates from that GUP.



  • 32.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 09, 2012 10:30 AM

    If I make any changes to policies etc, and I have a stand-alone EXE (or non-EXE) package, will I have to re-export those client install packages to export with the changes?



  • 33.  RE: SEPM 11.0.7 disable access to items

    Posted Nov 09, 2012 10:34 AM

    If you want the client to have the latest policy than yes. Otherwise you can wait it checks in after the install and it will get the latest policy. So it may be a few minutes behind...