Endpoint Protection

 View Only
Expand all | Collapse all

SEPM Intrusion Prevention Distribution

Migration User

Migration UserFeb 13, 2014 10:22 PM

ℬrίαη

ℬrίαηFeb 19, 2014 09:16 PM

  • 1.  SEPM Intrusion Prevention Distribution

    Posted Feb 11, 2014 08:52 PM

    hi guys,

    I got 2 main SEPM in 2 different site. one of the SEPM the summary of Intrusion Prevention Distribution is like this:

    Site A

    intrusion_110214.png

    And another site look like this:

    Site B

    intrusion_110214_0.png

     

    Why SEPM in site A have a huge number in "all others"?

    Thanks

     

     



  • 2.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 11, 2014 08:54 PM

    Those clients have not yet been updated to the latest revision.

    You can run a computer status report to check what version they're on.

    How do your clients get updates, from a GUP?



  • 3.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 11, 2014 08:57 PM

    hi Brian,

    Im aware of that, but its there any cause that make this to happen?



  • 4.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 11, 2014 09:04 PM

    Are the clients connecting to the SEPM?

    How are your clients configured to get updates? SEPM? GUPs? Some other method?

    What happens if you run LiveUpdate manually on one affected client? Does the IPS content update?



  • 5.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 11, 2014 09:07 PM

    And you've confirmed those GUPs are online and supplying content to the clients?

    How to confirm if SEP Clients are receiving LiveUpdate content from Group Update Providers (GUPs)



  • 6.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 11, 2014 09:07 PM

    all the client connected to SEPM

    some of our site we set a GUP server for each region



  • 7.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 11, 2014 11:48 PM

    Is there a replication between Site A and site B? If tyes then , check the replication frequency, it should show up  correct status after some time



  • 8.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 12, 2014 11:29 AM

    All the GUP clients are updated?

    port 2967 is open between clients and GUP bidirection?



  • 9.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 13, 2014 10:22 PM

    yeap. all GUPs are up and running



  • 10.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 13, 2014 10:25 PM

    Yes, both site is replicate. 

    how to check the replication frequency?



  • 11.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 13, 2014 10:27 PM

    Hi,

    what do u mean all the GUP clients are updated?

    all port are open for SEPM services



  • 12.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 14, 2014 12:42 AM

    Can you check the replication-0.log:  to see if replication was successful between site a and site b

     



  • 13.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 15, 2014 12:25 PM

    Hi

    If replication is set can you change the frequency to Auto and check

    Regards

     



  • 14.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 19, 2014 09:10 PM

    Hi,

    where to find the log?

    btw, why is replication frequncy affected intrusion distribution to clients?



  • 15.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 19, 2014 09:12 PM

    Hi

    why is replication frequency affected intrusion distribution to clients?



  • 16.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 19, 2014 09:16 PM

    It likely won't.



  • 17.  RE: SEPM Intrusion Prevention Distribution

    Posted Feb 19, 2014 09:24 PM

    meaning the frequency doesnt affect the Intrusion distribution?

    what is the cause of this issue?