Endpoint Protection

 View Only
Expand all | Collapse all

Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

  • 1.  Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 01:55 AM

    Hi Guys

    in my office most of the time senior managment is out of the country traveling so i want a way to update the clients (LU) Automatically so that when the managment come back to the office my network doesnt have the threat.

    furthermore lets just say i had deployed a policy of USB Flash drive blocking and a senior manager is on travel and suddenly he wanted to write something ond USB or DVD so is there a way to change the policy on the system when its not connected to the SEPM?

    i really need help on this issue guys. your hel is really appriciated  

    P.S : i am using SEPM 12.1.3



  • 2.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Broadcom Employee
    Posted Jul 29, 2013 01:57 AM

    yes, you need to set a location awareness and policy accordingly. Location awareness can be when connected to SEPM one set of policy and when not connected another set,

    for update check this link

    How to configure mobile computers to automatically download virus definitions when disconnected from the SEPM

    http://www.symantec.com/business/support/index?page=content&id=TECH104571&locale=en_US



  • 3.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 02:00 AM

    For the first option you need to create a location awareness policy as mentioned by Pete

    for the second one ,there is no way that you can force a policy change if client is not communicating with SEPM.What you can do is you can export a policy from SEPM and send it via email so that he can import those policy manually.

    How to Export and Import a Symantec Endpoint Protection client policy



  • 4.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Broadcom Employee
    Posted Jul 29, 2013 02:02 AM

    you can set a location awareness as stated in article

    http://symantec.com/docs/HOWTO80746

     



  • 5.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 02:07 AM

    I am agree with Rafeeq. When user is not in connectivity with SEPM (like - traveling) then there is no way to push the policy. Only you can import the policy from other client and send to user to import into that client.



  • 6.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 02:09 AM

    Hi,

    Please check my post  in below article.

    https://www-secure.symantec.com/connect/forums/how-configure-mobile-computers-automatically-download-virus-definitions

     

    How to configure mobile computers to automatically download virus definitions when disconnected from the Symantec Endpoint Protection Management console

    http://www.symantec.com/docs/TECH104571

    In case, of SEP 12.1, please check out the below link:

    Configuring mobile computers to automatically download definitions when disconnected from the Symantec Endpoint Protection 12.1 Management console

    http://www.symantec.com/docs/TECH177361



  • 7.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 02:31 AM

    ok is there a way to  connect to the SEPM if the client is outside the office?

    lets just say client is out of the country so is it a way to connect to the SEPM over the internet and then push the policy on the clients Rather then to import?



  • 8.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Broadcom Employee
    Posted Jul 29, 2013 02:48 AM

    for that you need to have SEPM on public IP address.



  • 9.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 02:52 AM

    Hi, 

    Possible but you need to have a public IP which will redirected to your SEPM only for policies.

    For updates you can configure location based policy when the client is not on your network take update from internet.

    Regards

    Ajin



  • 10.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 03:39 AM

    ok what will be the process for public ip?



  • 11.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 03:42 AM

    ok what will be the process for public IP Address

     



  • 12.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork
    Best Answer

    Broadcom Employee
    Posted Jul 29, 2013 03:44 AM


  • 13.  RE: Enabling of SEP Auto live update if SEPM is not available and Changing of Policies on Client when its ouside the newtork

    Posted Jul 29, 2013 04:41 AM

    Hello,

    if the remote client system joins your enterprise network via VPN to properly work (as it should be to get secure access to internal material, enterprise email servers, etc.) it should not be difficult to set your network to allow it to connect to the SEPM for logs and policies without having to use a public IP address and, with the location awaraness, still have that client to use Symantec LiveUpdate servers for updates.