Endpoint Protection

 View Only
Expand all | Collapse all

have to move endpoint protection manager to another server

  • 1.  have to move endpoint protection manager to another server

    Posted Jul 19, 2011 03:06 PM

    ready to do the upgrade to endpoint protection 12, and found that the manager will not run on Windows 2000 server.

    that is what we currently have the manager running on.

    where can I find information on installing the manager on a different server and moving everything to point to the new server rather than the old?



  • 2.  RE: have to move endpoint protection manager to another server

    Posted Jul 19, 2011 03:16 PM

    its all covered here

     

    Upgrading and migrating to Symantec Endpoint Protection 12.1



  • 3.  RE: have to move endpoint protection manager to another server

    Posted Jul 19, 2011 03:24 PM

    Hello,

    Please check out the link below,

    Overview of how to move the Symantec Endpoint Protection Manager from one machine to another

    http://www.symantec.com/business/support/index?page=content&id=TECH148555&actp=search&viewlocale=en_US&searchid=1311103226346

    Installation and Migration Documents for Symantec Endpoint Protection 12.1

    http://www.symantec.com/business/support/index?page=content&id=TECH163707&key=54619



  • 4.  RE: have to move endpoint protection manager to another server

    Posted Jul 19, 2011 04:58 PM

    hi

    when you are trying to move Endpoint protection manager to another server, here are the simple steps

    try to make a loadbalancing server for your SEPM - try to install sepm on another server make priority as 2

    Once when your priority 1 server is not up and running automatically second server will take care of, Later you can delete the first priority server so that the second server (new server) will become active



  • 5.  RE: have to move endpoint protection manager to another server

    Posted Jul 21, 2011 04:24 PM

    I tried to setup the 2003 server as an additional site, but keep getting the error "the schema versions for the local server and the remote partner do not match.  the server cannot be added as a replication partner."



  • 6.  RE: have to move endpoint protection manager to another server

    Posted Jul 22, 2011 03:24 AM

    Use the links provided by Idimple and follow the Disaster Recovery Procedures. :D



  • 7.  RE: have to move endpoint protection manager to another server

    Posted Jul 22, 2011 07:52 AM

    my problem is the disaster recovery procedures require you to port over the settings to a server with same host name and IP address.

    but symantec endpoint manager is not the only thing running on this server, so I cannot do that.  what other options do I have then?



  • 8.  RE: have to move endpoint protection manager to another server

    Posted Jul 22, 2011 08:01 AM

    Follow Step 2

     

    How to move Symantec Endpoint Protection Manager from one machine to another

     

    http://www.symantec.com/business/support/index?page=content&id=TECH104389



  • 9.  RE: have to move endpoint protection manager to another server

    Posted Jul 24, 2011 08:37 PM

    Hi James, hope you've checked the links provided by the other members. Specifically the on posted by James.

    If you plan on moving the machine while the old one stays up. Configure the 2nd one separately and use the Sylink replacer tool. It might be time consuming on the admins part, but this is a clean install. :D

    As compared to adding and removing replication partners which might limit flexibility since this would act as a secondary server and clients would just tag the old one as permanently offline.



  • 10.  RE: have to move endpoint protection manager to another server

    Posted Dec 12, 2011 12:28 AM

    Solution

    Disaster Recovery method

    IMPORTANT NOTE:SEPM installed on Machine B must be the same version as on Machine A (same release and same language)

    1. From Machine A
      1. Backup the Database
      2. Export the Server Certificates
        1. Log on to the Console, and then click Admin.
        2. In the Admin pane, under Tasks, click Servers.
        3. Under View Servers, expand Local Site, and then click the computer name that identifies the local site.
        4. Under Tasks, click Manage Server Certificate.
        5. In the "Welcome" panel, click Next.
        6. In the Manage Server Certificate panel, check Backup the server certificates and click Next.
        7. Select the folder and click Next.
        8. Click on Finish
      3. Copy the Database Backup and the Exported server keys to Machine B
    2. On Machine B
      1. Install SEPM
      2. Log in to the SEPM
      3. Import the Server Certificates
        1. Click Admin.
        2. In the Admin pane, under Tasks, click Servers.
        3. Under View Servers, expand Local Site, and then click the computer name that identifies the local site.
        4. Under Tasks, click Manage Server Certificate.
        5. In the "Welcome" panel, click Next.
        6. In the Manage Server Certificate panel, check Update the Server Certificate and click Next.
        7. Under "Select the type of certificate to import", check JKS keystore and click Next.
          Note: If you have implemented one of the other certificate types, select that type. 
        8. In the "JKS Keystore" panel, click Browse, locate and select your backed up as "keystore_.jks" keystore file, and then click OK.
        9. Open the backed up "server_.xml" file and then copy the keystorepass.
        10. Activate the "JKS Keystore" dialog box and then paste the keystore password into the "Keystore" and "Key" boxes.
          Note: The only supported paste mechanism is Ctrl + V. 
        11. Click Next.
          Note: If you get an error message that says you have an invalid keystore file, it is likely you entered invalid passwords. Retry the password copy and paste process as described above. 
        12. In the "Complete" panel, click Finish.
      4. Log off of the Console.
      5. Restart the Symantec Endpoint Protection Manager service
        1. Click Start>Settings>Control Panel>Administrative Tools>Services.
        2. In the "Services" window, right-click Symantec Endpoint Protection Manager and click Stop
        3. Right-click Symantec Endpoint Protection Manager and click Start.
          Note: By stopping and starting Symantec Endpoint Protection Manager, you fully restore the certificate
      6. Log in to the SEPM
      7. Confirm that the SEPM is working fine
      8. Log out of the SEPM
      9. Restore the Database backup
        1. Click Start>Settings>Control Panel>Administrative Tools>Services.
        2. In the Services window, right-click Symantec Endpoint Protection Manager, and then click Stop.
          Note: Do not close the Services window until you are finished with this procedure. 
        3. Create the following directory:
          \\Program Files\Symantec\Symantec Endpoint Protection Manager\data\backup
        4. Copy your database backup file to the directory.
          Note: By default, the database backup file is named date_timestamp.zip. 
        5. Click Start>Programs>Symantec Endpoint Protection Manager>Database Back Up and Restore.
        6. In the Database Back Up and Restore dialog box, click Restore.
        7. In the Restore Site dialog box, select the backup file that you copied to the backup directory, and then click OK.
          Note: The database restoration time varies and depends on the size of your database. 
        8. When the Message prompt appears, click OK.
        9. Click Exit.
      10. Run the Management Server Configuration Wizard.
        1. Click Start>Programs>Symantec Endpoint Protection Manager>Management Server Configuration Wizard.
        2. In the Welcome panel, check Reconfigure the Management Server, and then click Next.
        3. In the Server Information panel, modify input values if necessary to match previous inputs, and then click Next.
        4. In the Database Server Choice panel, check the database type to match the previous type, and then click Next.
        5. In the Database Information panel, modify and insert input values to match previous inputs, and then click Next.
          Note: The configuration takes a few minutes. 
        6. In the Configuration Completed dialog box, click Finish
      11. Create a new Management Server List
        1. Click Policies > Policy Components > Management Server Lists > Add Management Server List
        2. Add MACHINE_2 IP address and Hostname (with the exact http port number) under Priority 1
        3. ClickAdd>Priority and a new Priority would get added named as "Priority2"
        4. Add MACHINE_1 (with the exact http port number) under Priority 2, and assign this New Management Server List to all the groups.
    3. On Machine A
      1. Log in to the SEPM
      2. Create a new Management Server List
        1. Click Policies > Policy Components > Management Server Lists > Add Management Server List
        2. Add MACHINE_2 IP address and Hostname (with the exact http port number) under Priority 1
        3. ClickAdd>Priority and a new Priority would get added named as "Priority2"
        4. Add MACHINE_1 (with the exact http port number) under Priority 2, and assign this New Management Server List to all the groups.
    4. Clients will then move from old SEPM to new one gradually
    5. Later (decide the time in accordance to the number of clients and the geographic location of the clients), Stop the "Symantec Endpoint Protection Manager" and "Symantec Embedded Database" service on Machine A to verify whether all client now report to the new SEPM on Machine B
    6. Once verified that all the clients are reporting into the new SEPM, uninstall SEPM from Machine A

    Title: 'How do I move Symantec Endpoint Protection Manager from one server to another with a different IP address and host name?'

    http://www.symantec.com/business/support/index?page=content&id=TECH104389



  • 11.  RE: have to move endpoint protection manager to another server

    Posted Dec 28, 2011 12:17 AM
      |   view attached

    Please find the readymade document how you can migrate from Old Server to new Server

    Mark as a solution if it helps

    Regards

    Attachment(s)

    pdf
    SEPM-MIGRATION_3.pdf   796 KB 1 version