Endpoint Protection

 View Only
  • 1.  Disable IPS on servers

    Posted Sep 18, 2014 03:07 AM

    Hi,

    I have about 180 servers and i want to disable Network Threat Protection (IPS) from SEPM without need to restart the servers.

    Thanks



  • 2.  RE: Disable IPS on servers

    Posted Sep 18, 2014 03:10 AM

    Network Threat Protection required reboot.without reboot you can't remove NTP feature.

    How to add or remove features to existing Symantec Endpoint Protection (SEP) client installations

    Article:TECH90936 | Created: 2008-01-18 | Updated: 2014-08-14 | Article URL http://www.symantec.com/docs/TECH90936


  • 3.  RE: Disable IPS on servers

    Posted Sep 18, 2014 03:31 AM

    Sooooo, as James007 correctly states above, full removal of NTP from the client requires a reboot.

    However, just withdrawing the IPS policy from the servers will prevent it from blocking traffic (so while it's still loaded, it won't do anything).  It's up to you whether or not this is sufficient.



  • 4.  RE: Disable IPS on servers

    Trusted Advisor
    Posted Sep 18, 2014 03:32 AM

    You can not uninstall IPS without a reboot. You can setup an auto upgrade to remove and not force a reboot but IPS won't be fully removed until the machine is physically rebooted. 



  • 5.  RE: Disable IPS on servers
    Best Answer

    Posted Sep 18, 2014 07:58 AM

    If you want to disable it, just withdraw the policy.

    If you want to remove the component, a reboot is needed.

    Withdrawing a policy from a group



  • 6.  RE: Disable IPS on servers

    Posted Sep 21, 2014 07:05 AM

    I believe disabling the component is the right choice in my case as .Brian mentioned but can i disable it to specific server from SEPM? What would be the effect on the servers when i disable IPS? Would i still protected? 



  • 7.  RE: Disable IPS on servers

    Posted Sep 21, 2014 08:33 AM

    You can disable on specific serversif you wish but you won't be protected against malicious network traffic which is what the IPS does. You would only be relying on the AV component



  • 8.  RE: Disable IPS on servers
    Best Answer

    Posted Sep 22, 2014 03:36 AM

    To disable IPS on a single machine, you'll have to move it into a group of its own and withdraw the IPS policy from that group (as I mentioned earlier).

    The level of protection you have left depends on what else is installed and how it's configured.  In a typical install on a server with the "Full Protection for Servers" feature set chosen, you still have AV, Download Protection, SONAR, A&DC, and the FW to protect the machine with.  Configure these as appropriate.