Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Update ips for an offline installation

Updated: 23 Sep 2010 | 18 comments
David Patin's picture
0 0 Votes
Login to vote

Hi there,
I use SEPM in an offline way.
I follow this http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007100820002048 in order to update virus definitions.
But how can I update ips while I'm offline ?

I have to use liveupdate Administrator with his own server ?

Many thanks

PS : Sorry for my english

discussion Filed Under:

Comments

Rafeeq's picture
18
Mar
2010
0 Votes 0
Login to vote

Hi

You cannot do that
it only does AV and AS nothign else
its in ideas section as of now 
https://www-secure.symantec.com/connect/idea/jdb-file-should-update-all-components
Y
ou need to use Liveupdate administrator if you want to get all the updates.

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Prachand's picture
18
Mar
2010
0 Votes 0
Login to vote

JDB will only update the AV

JDB will only update the AV and AVS , in this case install LUA it serve the objective

Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)

David Patin's picture
18
Mar
2010
0 Votes 0
Login to vote

Ok, many thanks for your

Ok, many thanks for your answers.
But is it a nonsens to install LUA on a server wich is not connect to the internet ? How to do that ?

Vikram Kumar-SAV to SEP's picture
18
Mar
2010
0 Votes 0
Login to vote

You can install LUA on a

You can install LUA on a machine that has internet and then you can download the defs and then you can copy the definitons on your machine without internet (manually ) and host it on the SEPM server.

Rafeeq's picture
18
Mar
2010
0 Votes 0
Login to vote

hi

Yes, use lua  on a server which has internet then point your SEPM to that lu admin
follow this video 

https://www-secure.symantec.com/connect/videos/install-lua-and-configure

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

David Patin's picture
18
Mar
2010
0 Votes 0
Login to vote

great ! i don't no yet how to

great !
i don't no yet how to do that. But it's nice to know it's possible :)
I can't see the video at work :(
The idea is :
1 from the pc connect to internet, copy the folders/files in "Live Update/Downloads"
2 past them in the same folder but in the pc without internet
3 and then ? 

Rafeeq's picture
18
Mar
2010
0 Votes 0
Login to vote

hi

its not like that, 
you install luadmin
open sepm
under liveudate of sepm
you give the ludadmin address
it will download it from there 

Installing and configuring LiveUpdate Administrator 2.x

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007101913262648

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Vikram Kumar-SAV to SEP's picture
18
Mar
2010
1 Vote +1
Login to vote

Updating downloads in an

Updating downloads in an internal Live Update Administrator Server using the downloads from an external Live Update Server
http://service1.symantec.com/support/ent-security.nsf/docid/2008101508103148

David Patin's picture
18
Mar
2010
0 Votes 0
Login to vote

thanks, i will follow this

thanks, i will follow this solution ;)

David Patin's picture
18
Mar
2010
0 Votes 0
Login to vote

Ok, luadmin is

Ok, luadmin is installed

  1.  "under liveupdate of sepm", you mean "live update policy->use  a specific liveupdate server" ?
  2. the luadmin adress is something like : "http://localhost:7070/lua" ?
  3. the pb is lua is not connected to internent, so it can't download anything. It's why i said copy/past.

Thanks for your patience

Rafeeq's picture
18
Mar
2010
0 Votes 0
Login to vote

hi

Copy paste will not work.

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

David Patin's picture
19
Mar
2010
0 Votes 0
Login to vote

I succeed !!!!!!!! it's

I succeed !!!!!!!!
it's mostly ok. I have a lua connect to internet, an other one in the secure area. Use a liveupdate polic and a live update server (with download and distribution actions) and it's ok. Virus definition is up to date !!
but...there is a but...ips doesn't :(
The signature is : 2009-07-30 rev. 001 whereas the last version in the manager is 2009-12-31 rev. 002
Any idea ?

Vikram Kumar-SAV to SEP's picture
19
Mar
2010
0 Votes 0
Login to vote

In your LUA connected to

In your LUA connected to internet are you downloading all three signatures ?
Virus Defs, IPS and PTP defs.

David Patin's picture
19
Mar
2010
0 Votes 0
Login to vote

yes, i download : - all

yes, i download :
- all beahavioral crimeware protection (sesm Symantec XXX)
- all firewall rules (sesc ips, sesm ips)
- all products update
- all virus definitions

maybe it's because i only use antivirus and antispyware protection in user fonctionality ?

sandra.g's picture
19
Mar
2010
0 Votes 0
Login to vote

David

Why do you want IPS signatures if you are not using Network Threat Protection?

Mind you, it's a good idea to use IPS, but...

sandra

Symantec Technical Support Engineer, LAM/NAM //  SAV/SEP for Mac
Don't forget to mark your thread as 'solved' with the answer that best helped you!
 

David Patin's picture
19
Mar
2010
0 Votes 0
Login to vote

because i'm not sure to

because i'm not sure to understand what is ips for :D

Vikram Kumar-SAV to SEP's picture
19
Mar
2010
0 Votes 0
Login to vote

Symantec Endpoint Protection

Symantec Endpoint Protection 11.0 Network Threat Protection (Firewall) Overview and Best Practices White Paper

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121714495348

Best practices regarding Intrusion Prevention System technology

http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/a4b2056057ad5362882576070077598e?OpenDocument

Read these two docs

Prachand's picture
19
Mar
2010
0 Votes 0
Login to vote

Intrusion Prevention System

Intrusion Prevention System (IPS) technology prevents malicious files from getting to your hard drive in the first place.  IPS scans the network traffic stream in order to find threats using known exploits and attack vectors. It does not detect specific files but rather specific methods that can be used to get malicious files onto your network. This allows IPS to protect against both known and unknown threats, even before antivirus signatures can be created for them. Virus definitions are reactive as opposed to the IPS technology, which is proactive.

The Intrusion Prevention System analyzes network packets and compares them with both known attacks and known patterns of attack. IPS scans each packet that enters and exits computers in the network for attack signatures. Attack signatures are the packet sequences that identify an attacker’s attempt to exploit a known operating system or program vulnerability. If the packets match a known attack or pattern of attack, IPS drops the packet.

Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)