Endpoint Protection

 View Only
  • 1.  Symantec Endpoint protection Network level Traffic understanding

    Posted May 20, 2013 04:11 AM

    Hi!

     

    We have been using Symantec Endpoint protection in our organization for quite a while now. But everyday new surprises are thrown to us by the traffic utilizations of clients. At times , we have observed that the individual client is downloading 50 Mb of data even if the latest virus definition is stale by 1 or 2 days. We have had lot of discussion in our team regarding the traffic utilization by our clients but always it happens that we are proved wrong.

     

    Based on our understanding, I'm posting a table regarding our traffic data analysis under SEP. 

     

     

    Content type

    Size of Package

    Comments

    Deliverable via Group Update Provider (GUP)

    Heartbeat (with no updates to be exchanged)

    Between 2 KB and 3 KB per heartbeat

     

    The GUP does not directly manage clients; it delivers content to clients on its local network segment.

    Policies (i.e. AV/AS, Firewall, OS Protection, Host Integrity)

    Typically varies between 20 KB and 80 KB.

     

    No. The policies must come from a Symantec Endpoint Protection Manager.

    IPS Signature Updates

    50 KB and 100 KB

     

    Yes. The client receives information from the Symantec Endpoint Protection Manager when to download content from the GUP.

    AV Signatures

    50 KB to 200 KB (daily)

    If We assume that the signatures are updated successfully every day

    Logs

    Varies

     

    Logs are forwarded from the client to the Manager.

    Heartbeat for Major Location

    2 Hours

     

     

     

    Total Approximate Size of SEP data if Client is Fully Updated (during 8 Hours) à  300 KB

    If Definition is older than 10 Days à 3 MB

    If Definition is older than 20 Days à 6 MB

    If def ignition is older than 30 days à 9 MB

     

     

    We would be pleased to hear comments on our analysis if this is correct or wrong. We welcome any kind of inputs/data/information/conclusion regarding networl level traffic utilization by Symantec Clients. 

     

    Thank you 

     



  • 2.  RE: Symantec Endpoint protection Network level Traffic understanding

    Broadcom Employee
    Posted May 20, 2013 04:16 AM

    by any chance have you noticed what data has been downloaded? is it definition/policy etc?



  • 3.  RE: Symantec Endpoint protection Network level Traffic understanding

    Posted May 20, 2013 04:31 AM

    Hi 

     

    How can i identify that if the data is Policy Level or Definition level. What i can provide you is the screenshot of traffic utilization by one location in 6 hours.

     

     

     

     

     

    traffic_0_0.PNG

     

    Please ask for more inputs , if required...10.120.15.187 is our SEPM server..no GUP here 



  • 4.  RE: Symantec Endpoint protection Network level Traffic understanding

    Broadcom Employee
    Posted May 20, 2013 04:46 AM

    are these clients consisitent, you can enable the sylink log to understand the data size downloaded becuase of signature



  • 5.  RE: Symantec Endpoint protection Network level Traffic understanding

    Posted May 20, 2013 06:13 AM

    Yes, i can run the sylink monitor. But is it possible for you to comment on the table of data analysis/information  which we have provided? Thank you



  • 6.  RE: Symantec Endpoint protection Network level Traffic understanding

    Broadcom Employee
    Posted May 20, 2013 06:36 AM

    the traffic is between SEPM and SEP :-) however the detailed information is not possible.

    why not have GUP if it is a remote site.



  • 7.  RE: Symantec Endpoint protection Network level Traffic understanding

    Posted May 20, 2013 09:03 AM

    Hello,

    what observed and reported in the table seems as expected.



  • 8.  RE: Symantec Endpoint protection Network level Traffic understanding

    Posted May 21, 2013 01:25 AM

    Hello, 

     

    I need some more conclusions on the figures mentioned in table. Please make a comment on that. The sizes of SEP definition has been proved to be a nightmare for us.Its very unpredictable.



  • 9.  RE: Symantec Endpoint protection Network level Traffic understanding

    Broadcom Employee
    Posted May 21, 2013 01:33 AM

    please enable sylink on client and monitor the data downloaded (content)



  • 10.  RE: Symantec Endpoint protection Network level Traffic understanding

    Posted May 21, 2013 02:14 AM

    Hi, 

    Please collect the sylink log between the client and SEPM and share.

    How to enable sylink -- follow the below KB

    http://www.symantec.com/docs/TECH104758

     
    Regards
    Ajin