Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SEPM & ISA server 2004

Updated: 09 Dec 2010 | 11 comments
almirk's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

I installed SEPM 11.0.6 on the same server (ws2003r2 std) where is the Isa Server 2004.

I would like to know, which protocol(s) and port(s) I have to integrate/open into firewall policy on ISA, to establish communication between SEPM and SEP client ?

 

thanks

Comments

Pawel Lakomski's picture
08
Dec
2010
0 Votes 0
Login to vote

Hi, Please have a look

Hi,

Please have a look on:

Considerations when using antivirus software on ISA Server
http://technet.microsoft.com/en-us/business/support/library/cc707727.aspx

ISA server:
http://www.isaserver.org/tutorials/Allowing_Norton_AntiVirus_software_LiveUpdate_through_ISA_Server.html
http://www.isaserver.org/tutorials/How_to_allow_Symantec_Liveupdate_access_through_ISA.html

--

Cheers,

Symantec Technical Specialist
Symantec Certified Specialist
MCP & MCITP
Cisco Certified Network Associate
Citrix Certified Administrator

 

Kurt G.'s picture
08
Dec
2010
1 Vote +1
Login to vote

The following document contains our default ports.

The following document contains our default ports. Our traffic will need to be allowed through these ports in order for clients to connect to the SEPM server. You may need to adjust these if you have utilized any custom ports during installation.

Which Communication Ports does Symantec Endpoint Protection 11.0 use?
http://www.symantec.com/business/support/index?pag...

Kurt G.
Symantec Technical Specialist: Endpoint Security Advanced Team

Symantec Corporation www.symantec.com

Symantec Enterprise Support: (800) 342 0652 

Fatih Teke's picture
08
Dec
2010
0 Votes 0
Login to vote

Just idea

Hello almirk,

I just want to share my thinks with you. Isa server should be very busy about your internet requests, and id you publish your OWA via Isa and if share VPN with ISA. Therefore your network should be fast. Because ISA is already comminicate users which want to surf on internet, and sep manager will comminicate clients too. this is only idea came from experiance :)

Best Regards.

Fatih

 Everything works better when everything works together.

Rafeeq's picture
08
Dec
2010
0 Votes 0
Login to vote

hi

open IIS, expand symantec webserver, check the port, if its 8014, thats the one u need to allow for communication; thats it

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

zer0's picture
08
Dec
2010
0 Votes 0
Login to vote

Trusted Advisor?

Maybe if you only want to allow SEP to SEPM traffic.

You seem to of forgotten all of the other SEP ports

443 - for optional secured https

1433 - for sql datase comms

1812 - for snac enforcer

9090 and 8443 - for remote admin console

Prashant Bharadwaj's picture
08
Dec
2010
0 Votes 0
Login to vote

You will need to open only

You will need to open only 8014 for a normal SEPM-SEP client communication.

A typical ISA configuration will be:

Internal - Local Netowrk through port 8014

Prashant Bharadwaj, CEH, MCTS Windows Server 2008 Active Directory, Configuration, SCS Symantec Endpoint Protection 11.0

VKalani's picture
09
Dec
2010
0 Votes 0
Login to vote

You  just need to open port

You  just need to open port 8014...that's  it!

-VKalani

almirk's picture
09
Dec
2010
0 Votes 0
Login to vote

thanks to all of you, I

thanks to all of you, I resolved my problem...

Pawel Lakomski's picture
09
Dec
2010
0 Votes 0
Login to vote

We're glad to have helped.

We're glad to have helped.

--

Cheers,

Symantec Technical Specialist
Symantec Certified Specialist
MCP & MCITP
Cisco Certified Network Associate
Citrix Certified Administrator

 

GPCALI's picture
09
Dec
2010
0 Votes 0
Login to vote

If you are currently running the ISA 2004 firewall

 

The behavior-based TruScan Proactive Threat Scan feature is not supported on servers, therefore it is recommended that this feature should not be selected for this specific client installation package.

 The Antivirus Email Protection features are aimed at providing additional protection to client-side email applications such as Microsoft Outlook and Lotus Notes, therefore if you won‟ run these directly on the Small Business Server, these features should not be selected.

 If you are currently running the ISA 2004 firewall on the Microsoft Small Business Server, you should ensure the Network Threat Protection feature is not be selected.

almirk's picture
10
Dec
2010
0 Votes 0
Login to vote

On the servers OS's I

On the servers OS's I installed only antivirus&antispyware component, that's recommended i think.