Endpoint Protection

 View Only
  • 1.  whitelisting

    Posted Apr 16, 2015 03:36 AM

    What are the necessary steps which are required for application whitelisting?

    Is application whitelisting and system lockdown, one and the same?

    ~Jalpesh



  • 2.  RE: whitelisting
    Best Answer

    Trusted Advisor
    Posted Apr 16, 2015 03:52 AM

    Hello,

    Yes, they are same.

    System Lockdown allows administrators to tightly control which applications users running the SEP Client can execute. The approved applications are contained in a so-called fingerprint list which contains checksums and locations of all applications that are approved for use.

    Implementing System Lockdown is a two step process. First, a fingerprint list needs to be created, and then this fingerprint list needs to be imported into the Symantec Endpoint Protection Manager for use in Client Policies.

    To generate the file fingerprint list, a tool is included in the Symantec Endpoint Protection Client installation. We recommend to create a software image that includes all of the applications you want users to be able to use on their computers, and to use this image to create a file fingerprint list.

    What is SYSTEM LOCKDOWN ? What Stages do I Implement SYSTEM LOCKDOWN in Symantec Endpoint Protection (SEP) ?

    https://www-secure.symantec.com/connect/articles/w...

    SEP does offer whitelisting capabilities but it doesn't do true whitelisting.

    About system lockdown

    http://www.symantec.com/business/support/index?page=content&id=HOWTO27322

    Setting up and testing the system lockdown configuration before you enable system lockdown

    Configuring system lockdown

    In case if you wants to block the Application, then he could use the System Lockdown feature which is available in the SEP 11.x and SEP 12.1 Enterprise Edition.

     

    In case, you want to Whitelist an Application, then check this Article:

    Software developer would like to add his/her software to the Symantec White-List.

    http://www.symantec.com/docs/TECH132220

    Hope that helps!!



  • 3.  RE: whitelisting

    Broadcom Employee
    Posted Apr 16, 2015 05:06 AM

    Hi,

    Thank you for posting in Symantec community.

    Q. Is application whitelisting and system lockdown, one and the same?

    --> Yes, by default system lockdown runs in whitelist mode when you enable it. You can choose a whitelist or blacklist mode if you set up Symantec Endpoint Protection Manager to show both options

    You can enable system lockdown to allow only approved applications on your client computers. Only applications in the approved list are allowed to run. All other applications are blocked. The approved list is called a whitelist. Approved applications are subject to Symantec Endpoint Protection's other protection features. 

    Check this article: Enabling system lockdown to run in whitelist mode

    http://www.symantec.com/docs/HOWTO80850



  • 4.  RE: whitelisting