Update ips for an offline installation
Updated: 23 Sep 2010 | 18 comments
Hi there,
I use SEPM in an offline way.
I follow this http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007100820002048 in order to update virus definitions.
But how can I update ips while I'm offline ?
I have to use liveupdate Administrator with his own server ?
Many thanks
PS : Sorry for my english
discussion Filed Under:
Comments
Hi
You cannot do that
it only does AV and AS nothign else
its in ideas section as of now
https://www-secure.symantec.com/connect/idea/jdb-file-should-update-all-components
You need to use Liveupdate administrator if you want to get all the updates.
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
JDB will only update the AV
JDB will only update the AV and AVS , in this case install LUA it serve the objective
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Ok, many thanks for your
Ok, many thanks for your answers.
But is it a nonsens to install LUA on a server wich is not connect to the internet ? How to do that ?
You can install LUA on a
You can install LUA on a machine that has internet and then you can download the defs and then you can copy the definitons on your machine without internet (manually ) and host it on the SEPM server.
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
hi
Yes, use lua on a server which has internet then point your SEPM to that lu admin
follow this video
https://www-secure.symantec.com/connect/videos/install-lua-and-configure
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
great ! i don't no yet how to
great !


i don't no yet how to do that. But it's nice to know it's possible
I can't see the video at work
The idea is :
1 from the pc connect to internet, copy the folders/files in "Live Update/Downloads"
2 past them in the same folder but in the pc without internet
3 and then ?
hi
its not like that,
you install luadmin
open sepm
under liveudate of sepm
you give the ludadmin address
it will download it from there
Installing and configuring LiveUpdate Administrator 2.x
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007101913262648
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
Updating downloads in an
Updating downloads in an internal Live Update Administrator Server using the downloads from an external Live Update Server
http://service1.symantec.com/support/ent-security.nsf/docid/2008101508103148
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
thanks, i will follow this
thanks, i will follow this solution ;)
Ok, luadmin is
Ok, luadmin is installed
Thanks for your patience
hi
Copy paste will not work.
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
I succeed !!!!!!!! it's
I succeed !!!!!!!!
it's mostly ok. I have a lua connect to internet, an other one in the secure area. Use a liveupdate polic and a live update server (with download and distribution actions) and it's ok. Virus definition is up to date !!
but...there is a but...ips doesn't :(
The signature is : 2009-07-30 rev. 001 whereas the last version in the manager is 2009-12-31 rev. 002
Any idea ?
In your LUA connected to
In your LUA connected to internet are you downloading all three signatures ?
Virus Defs, IPS and PTP defs.
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
yes, i download : - all
yes, i download :
- all beahavioral crimeware protection (sesm Symantec XXX)
- all firewall rules (sesc ips, sesm ips)
- all products update
- all virus definitions
maybe it's because i only use antivirus and antispyware protection in user fonctionality ?
David
Why do you want IPS signatures if you are not using Network Threat Protection?
Mind you, it's a good idea to use IPS, but...
sandra
Symantec Technical Support Engineer, LAM/NAM // SAV/SEP for Mac
Don't forget to mark your thread as 'solved' with the answer that best helped you!
because i'm not sure to
because i'm not sure to understand what is ips for :D
Symantec Endpoint Protection
Symantec Endpoint Protection 11.0 Network Threat Protection (Firewall) Overview and Best Practices White Paper
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121714495348
Best practices regarding Intrusion Prevention System technology
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/a4b2056057ad5362882576070077598e?OpenDocument
Read these two docs
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
Intrusion Prevention System
Intrusion Prevention System (IPS) technology prevents malicious files from getting to your hard drive in the first place. IPS scans the network traffic stream in order to find threats using known exploits and attack vectors. It does not detect specific files but rather specific methods that can be used to get malicious files onto your network. This allows IPS to protect against both known and unknown threats, even before antivirus signatures can be created for them. Virus definitions are reactive as opposed to the IPS technology, which is proactive.
The Intrusion Prevention System analyzes network packets and compares them with both known attacks and known patterns of attack. IPS scans each packet that enters and exits computers in the network for attack signatures. Attack signatures are the packet sequences that identify an attacker’s attempt to exploit a known operating system or program vulnerability. If the packets match a known attack or pattern of attack, IPS drops the packet.
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Would you like to reply?
Login or Register to post your comment.