Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

JDB File Should update All components

Updated: 08 Sep 2009 | 9 comments
Rafeeq's picture
42 Agree
1 Disagree
+41 43 Votes
Login to vote
Status: Reviewed

The current update method of Manager using JDB ( Manaually ) Updates only AntiVirus and AntiSpyware.
Howerver it would be good if we can have PTP and NTP updated
The JDB files should update
AntiVirus and AntiSpyware.
Proactive threat protection
Network Threat Protection

 

Comments

Vikram Kumar-SAV to SEP's picture
01
Sep
2009
1 Vote +1
Login to vote

People really want IPS defs

People really want IPS defs for thier closed network..

AravindKM's picture
06
Sep
2009
1 Vote +1
Login to vote

It is a good idea. I would

It is a good idea. I would like to see this idea implemented as soon as possible.

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

GrahamA's picture
08
Sep
2009
2 Votes 0
Login to vote

Understand the request.

..but there are no currently plans to implement this.

For closed networks, LUA 2.x or LUAU 1.x is the recommended method to download content and transfer it to those networks.

For other environments, the use of GUPs is recommended and where that doesn't suit, the IPS content is not updated as frequently as AV/AS content and IPS updates tend to be < 200k so are relatively small. PTP content updates are even smaller.

So the main concern around bandwidth usage is AV/AS content and for this reason the JDB exists as an alternative method of distribution.

All that said, lets see what the customer community think and how they vote on this idea. That will of course influence our future decisions on this topic.

GrahamA Product Management, Symantec Security Solutions

Swado77's picture
02
Mar
2010
0 Votes 0
Login to vote

I'll vote for it

I think this is a good idea as I am managing several isolated machines with an unmanaged client installed. The machines have their network cards turned off due to security reasons. :)

Bruce.A.Singer@oa.mo.gov's picture
28
Jun
2010
0 Votes 0
Login to vote

We have ~10500 workstations. 

We have ~10500 workstations.  On any given day, we have approximately 500 {5%} of our machnes get "corrupted" PTP/TruScan/TruScan Permitted Applications definitions and will not update from the SEPM.  Typically, you have to run LiveUpdate twice to clear out the "corrupted" definitions and then they will start updating from the SEPM again.  We also have ~5% of our workstations firewalled to limit they access.  They can not get out to the internet to run LiveUpdate so I have no way to easily clear the "corrupted" PTP/TruScan/TruScan Permitted Applications definitions.  If you do a standard re-install of  SEP 11, 2/3 of the time the PTP/TruScan/TruScan Permitted Applications definitions are the same date as before the re-install and the will still not update from the SEPM.  At this point, we need to reimage the machines to get them working again.  {Note, I have yet to try cleanwipe}

I definately would like to some way to manually update the PTP/TruScan/TruScan Permitted Applications.  It would save a lot of reinstalling/reimaging of our workstations.

CalWebster's picture
04
Mar
2010
1 Vote +1
Login to vote

We desperately need a method

We desperately need a method of acquiring definitions for PTP! NTP definition updates would be helpful too but at least there I can opt to use the Windows Firewall instead.

I've begun rolling out SEP 11 to replace our SAVCE infrastructure that's been in place for over a decade. Since first installing SAVCE with a strict security policy our networks have never had a successful virus infection of any kind. I decided to upgrade to SEP to take advantage of the additional features and supported platforms.

After the first installation attempt of SEPM corrupted our WSUS IIS site using the "default" web site option I was a bit frustrated. Taking a chance on the "custom web site" install, I found that the Install Guide lied about disabling the default web site (containing WSUS services). The rest of the SEP 11 install was painless. The pushed client installs went quickly and flawlessly too. I was fully expecting to have a completely working SEP service after updating the VDB definitions. I naively assumed that threat protection updates would be complete with the new JDB definitions file.

The networks I manage are all isolated from any outside networks, including the Internet. Consequently, I've had to develop an update process using a Linux external server connected to the Internet upon which we maintain mirrors of Linux, Solaris, MS Windows (in MS WinSvr virtual machine), and other software updates. A script synchronizes these updates with a large USB drive for scanning and transfer to the internal network where automated updates are accomplished through local update servers.

Symantec threat protection is a vital part of our Information Assurance management infrastructure. Maintaining this infrastructure takes a large amount of time and effort as it is. Having to maintain yet another software package (LUA) only adds to the overhead burden. Copying a single file containing the combined definitions, or even a small set of definition files, seems much simpler than maintaining and training for LUA.

That's my $0.02 worth...

sandra.g's picture
24
Jun
2010
1 Vote +1
Login to vote

Offline update...

...If not within the JDB itself, then perhaps separate downloads to update these components in a closed environment.

sandra

Symantec Technical Support Engineer, LAM/NAM //  SAV/SEP for Mac
Don't forget to mark your thread as 'solved' with the answer that best helped you!
 

wdjread's picture
18
Jan
2011
0 Votes 0
Login to vote

Offline Update

Defintely for a manual download of PTP and NP defs.  At this time we don't even enable NP or PTP because it's too painful to update the definitions.  I certainly vote for either rolling it into .jdb or creating sep downloads for those defs. 

w-d's picture
12
Apr
2011
0 Votes 0
Login to vote

I strongly agree with that

I strongly agree with that idea. There should be a possibility to update all components when the machine is offline.

What are the Symantec Endpoint Protection (SEP) versions released officially?
https://www-secure.symantec.com/connect/articles/w...