Endpoint Protection

 View Only
  • 1.  Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 07:29 AM

    Hi Guys:

    Is there anyway where we can force SEPM to download definitions via ssl from liveupdate.symantec.com instead of ftp ?

    Cheers!



  • 2.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 07:31 AM

    How are you seeing it coming via ftp?

    The connections happen automatically so there really isn't anything you can configure within SEPM.



  • 3.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 07:34 AM

    See this.

    • LiveUpdate connects over TCP ports 80 (HTTP), 21 (FTP) and 443 (HTTPS).
    • The file that connects to the Internet is LuComServer_*_*.exe in LiveUpdate 2.5 and later and Lucomserver.exe in LiveUpdate 2.0 and earlier.
    • The default folder for this file is C:\Program Files\Symantec\LiveUpdate.
    • LiveUpdate connects via HTTP to the domains liveupdate.symantecliveupdate.com, liveupdate.symantec.com, and akamai.net.
    • If a connection fails, LiveUpdate tries to connect to one of the other listed domains. The listed domains may change because of server maintenance.
    • If LiveUpdate cannot make an HTTP connection, LiveUpdate connects via FTP to update.symantec.com/opt/content/onramp

    How to determine whether your firewall is blocking LiveUpdate

    Article:TECH139451 | Created: 2010-09-09 | Updated: 2011-08-26 | Article URL http://www.symantec.com/docs/TECH139451


  • 4.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 07:57 AM

    I can see this clear text communication in my SIEM. 



  • 5.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 07:58 AM

    This just happens automatically.



  • 6.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 08:26 AM

    @ Brain : Is there anyway we could change it to SSL ? 



  • 7.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 08:33 AM

    No way It's default Live update URL.

    See Symantec live update URL.

    https://www-secure.symantec.com/connect/forums/urls-default-symantec-liveupdate-server



  • 8.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 16, 2014 08:40 AM

    No not from the SEPM. This starts on the Symantec end. LU does use 443 as well in addition to 80 and 21 but it may vary.



  • 9.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 17, 2014 04:27 AM

    But can we change it to 80 ?



  • 10.  RE: Changing SEP live updates to ssl from ftp

    Posted Sep 17, 2014 04:31 AM

    As per below articles you need to open below firewall port for update defination.

    How to determine whether your firewall is blocking LiveUpdate

    Article:TECH139451 | Created: 2010-09-09 | Updated: 2011-08-26 | Article URL http://www.symantec.com/docs/TECH139451


  • 11.  RE: Changing SEP live updates to ssl from ftp
    Best Answer

    Posted Feb 13, 2015 06:07 AM

    So if I block 80/8080 in my firewall , the communication happens on 443 only. that's the best way to go with.



  • 12.  RE: Changing SEP live updates to ssl from ftp

    Posted Feb 13, 2015 06:14 AM

    You can try may be it will work.