Endpoint Protection

 View Only
  • 1.  Symantec Endpoint *unmanaged computers

    Posted Nov 03, 2011 10:51 AM

    Is there a better way to scan your network for computers that are not protected with symatnec endpoint.

    Instead of running a "find unmanged computers"

    I have a computer that is set as "configure unmanged detector" but doesnt report anything *how can I view these reports as well.

     

    what does everyone else use a group policy?



  • 2.  RE: Symantec Endpoint *unmanaged computers

    Trusted Advisor
    Posted Nov 03, 2011 11:37 AM

    Hello,

    UnManaged Detector - check this Articles:

    What does it mean to set a client as an Unmanaged Detector?
     
     
    Best Practices: When to use the "Find Unmanaged Computers" or "Unmanaged Detector" features in Symantec Endpoint Protection 11.0
     
     
    Find Unmanaged Clients on a remote network location using the Unmanaged Detector
     
     
    Setting notifications when using the "Unmanaged Detector" feature in the SEPM
     
     
    That would help you.


  • 3.  RE: Symantec Endpoint *unmanaged computers

    Posted Nov 03, 2011 11:47 AM

    Unmanaged Detector Basics
    Upon booting, a computer sends out Address Resolution Protocol (ARP) traffic to identify itself on a network. Once enabled, the Unmanaged Detector listens for gratuitous ARP traffic and collects Internet Protocol (IP) and Machine Address (MAC) data from traffic passing it on the local network. This data is then forwarded to the Unmanaged Detector’s SEPM which compares the IP address and MAC address of detected systems against its known list of managed endpoint clients and reports on the unmanaged endpoint clients.

    An unmanaged detector is configured by right-clicking a managed SEP client in the Clients page of the SEPM console, and selecting "Make unmanaged detector".

    Use Unmanaged Detector when you want to:

    • Be proactively notified (by setting a notification for "unmanaged computers". Also under the Security Status details from Home page in Symantec Endpoint Protection Manager).
    • Coverage over time and not a "snapshot" of systems currently connected to the network.


    See the following document for information on how to find out if a computer has been discovered using the Unmanaged Detector feature:

    Title: 'Setting notifications when using the "Unmanaged Detector" feature in the SEPM'
    Document ID: 2008050813205048
    > Web URL: http://service1.symantec.com/support/ent-security.nsf/docid/2008050813205048

    Find Unmanaged Computer Basics
    A network range is scanned based on the range that is configured for computers that are not running Symantec Endpoint Protection.

    To use this feature, click "Find Unmanaged Computers" in the Clients page of the SEPM console.

    Use the Find Unmanaged Computer feature when you want to:

    • Check a network segment at a particular point in time.
    • Get a snapshot of systems connected to the network when run.
    • Deploy a client package to unmanaged systems by deploying Symantec Endpoint Protection client (with login credentials).


    Both tools offer some help to administrators



  • 4.  RE: Symantec Endpoint *unmanaged computers

    Posted Nov 30, 2011 11:12 AM

    Is there a way to test this notification email? I've set it up but havent receieved any email. Is there any logs I can check what the problem may be.

    Even setup the mail config using port 25



  • 5.  RE: Symantec Endpoint *unmanaged computers

    Posted Nov 30, 2011 11:23 AM

    im not getting any email alerts either, i;ve setup multiple "unmanaged detectors" Would be interested in a way to test this out.

    plus we have a bunch of clients that are no longer on the network that are still showing up under clients causing my SEPM to show "attention needed" and clients that havent been updated.