Video Screencast Help

Situational awareness with GUP and Subnets

Created: 22 Aug 2013 • Updated: 22 Aug 2013 | 4 comments


         I have a SEPM on the east coast of the U.S. and a GUP that will be setup in Europe.  All the European offices will point to the GUP for their delta package updates.  What I am trying to do is setup situational awareness so if an employee in the U.S. flies to Europe and plugs into a an office over there, they are not going over the WAN for their definition updates and will point to the local GUP in Europe.  I'd like to do the same for European employees that fly to the states, so that they point to the SEPM while they are here.

I was wondering if there is anyone that can recomend the best way to go about doing this, keeping inline with Symantec's recomended "best practices"?  Any advice/insight would be appreciated.

Operating Systems:

Comments 4 CommentsJump to latest comment

ᗺrian's picture

Have you looked into the Explicit GUP for roaming clients?

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

Chetan Savade's picture


Thank you for posting in Symantec community.

I would be glad to answer your query.

You should configure Explicit group update provider.

It is important to understand that now the clients have ability to roam to a GUP outside of their own subnet, rather than their ability to find a nearest GUP. In previous SEP versions, the clients would only connect to a GUP outside of their own subnet, if such a GUP was configured as "backup" GUP.

Explicit Group Update Provider:

It will allow clients to use specific GUP's outside their subnet.

Only configurable through SEPM

This is not auto discovery feature

Path: SEPM --> Policies --> Liveupdate Policy --> Edit liveupdate setting policy --> Server Settings --> Group Update Provider

Refer this article:

SEP 12.1 RU2 And Explicit Group Update Providers

Chetan Savade
Sr.Technical Support Engineer, Endpoint Security
Enterprise Technical Support

Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<

Seyad's picture

You can use location awareness and create different conditions based on the IP range of the clients and configure the clients to look for a specific source (for updates) depending upon their IP.

More about Location Awareness in Symantec Endpoint Protection (SEP)