Intel,Altiris Group

  • 1.  how to exclude intrusion prevetion and firewall features from installed symantec clients

    Posted Aug 17, 2009 02:57 AM
    Hi
    Here comes new query. I installed SEP client on a PC
    package have following items
    1-antivirus and antispyware protection
    2-network threat protection-application and device control for USB device
    3-Proactive threat protection-Truscan proactive threat scan

    Now i want to exclude following features from installed clients
    proactive Threat Protection
    Firewall
    Intrusion Prevention

    But dont want to exclude Application and Device Control Policy

    Any Suggestion?


  • 2.  RE: how to exclude intrusion prevetion and firewall features from installed symantec clients

    Posted Aug 17, 2009 03:16 AM
    To use Application and Device Control you will have to install all the features of SEP.
    However later you can turn them off by applying policies.You you cannot u-install them and use application and Device Control.


  • 3.  RE: how to exclude intrusion prevetion and firewall features from installed symantec clients

    Posted Aug 17, 2009 03:26 AM

    Ok tel me how to "turn them off by applying policies".mean Policy is enable but filter features are ON



  • 4.  RE: how to exclude intrusion prevetion and firewall features from installed symantec clients
    Best Answer

    Posted Aug 17, 2009 04:39 AM

    Firewall and Intrution prevention.

    For Firewall add a Blank Rule Firewall Rule in SEPM . Blank RUle is nothing but Allow All.

    For Intrution Prevention: Edit the Intrution Prevention Policy -go to Settings
    Uncheck
    Enable Intrution Prevention
    Enable Denial of Service Detection
    Enable Port Scan Detection.

    For Proactive Threat scan you can leave it as enabled you can just increase the scan frequency

    default is 1 hour

    Edit Antivirus and Antispyware policy - Truscan Proactive threat scan -Scan Frequency -

    or if you want to disable Truscan then on Truscan Proactive threat scan polic uncheck and lock

    Scan for Trojans and Worms and Scan for Key loggers.

    On the bottom for both the condition you can change it to ignore from the default Log