Endpoint Protection

 View Only
  • 1.  IPS configuration from SEP 12.X

    Posted Nov 09, 2018 03:41 PM

    Dear,

    In the company at the moment still using SEP 12.x , the SEPM manager using the version 14.0.3752.1000 and the IPS signatures from this version is not update, in the contentinfo.txt show the follow:

    {C0FF7368-0AD3-236B-4AD5-75F88948BE6A}: SESC AntiVirus Client Security Fix Win32 - 14.0 RU1 - English
    {3A1B6BF3-0AD3-236B-4AD5-75F847D3EECF}: SESC AntiVirus Client Security Fix Win64 - 14.0 RU1 - English
    {535CB6A4-441F-4e8a-A897-804CD859100E}: SEPC Virus Definitions Win32 12.1 RU6 - MicroDefsB.CurDefs - SymAllLanguages
    {07B590B3-9282-482f-BBAA-6D515D385869}: SEPC Virus Definitions Win64 (x64) 12.1 RU6 - MicroDefsB.CurDefs - SymAllLanguages
    {4F6D9685-BCD6-43C4-A109-7399795F5D97}: SEPC Virus R Definitions Win32 12.1 RU6 - MicroDefsB.CurDefs - SymAllLanguages
    {38B770CC-A70B-43D0-92AF-24F6CB39114B}: SEPC Virus R Definitions Win64 (x64) 12.1 RU6 - MicroDefsB.CurDefs - SymAllLanguages
    {50B092DE-40D5-4724-971B-D3D90E9EE987}: SEPC SRTSP Settings - 12.1 RU5 - SymAllLanguages
    {A78E095A-8FED-4937-9D5C-0B6C20EA696C}: SEPC SRTSP Settings - 14.0 RU1 - SymAllLanguages
    {5A7367E1-D1F6-43b5-BD94-4AFFA896D724}: SEPC SMR Definitions 14.0 - MicroDefsB.CurDefs - SymAllLanguages
    {FDDBF0FB-0A93-1B05-74DA-0710C2E8441D}: SEPC SMR Definitions 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {1A79EE79-891B-4CB6-9A00-8D07FC6BF1FF}: SEPC Virus Definitions SDS Win32 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {151387BE-8D1C-467D-8B7A-AC215B16A144}: SEPC Virus Definitions SDS Win64 (x64) 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {7C177419-4112-42B6-8CEF-094385474554}: SEPC Virus R Definitions SDS Win32 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {67F66706-F04B-4432-9947-F8354949D2A6}: SEPC Virus R Definitions SDS Win64 (x64) 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {8EC79BE5-0A4B-0378-008D-E760EE4D9D2F}: SEPC SRTSP Settings - 12.1 RU6 MP8 - SymAllLanguages
    {D6AEBC07-D833-485f-9723-6C908D37F806}: SEPC Behavior And Security Heuristics 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {55DE35DC-862A-44c9-8A2B-3EF451665D0A}: SEPC CIDS Signatures 14.0 - MicroDefsB.CurDefs - SymAllLanguages
    {0D03AEA1-B630-43F8-828E-F10E80A68B99}: SEPC CIDS Signatures 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {1AD331AC-DEF8-4f6f-A7B5-7B259423BBCF}: SEPC HI Policy Contents Windows - 14.0 RU1 - SymAllLanguages
    {B6DC6C8F-46FA-40c7-A806-B669BE1D2D19}: SEPC Submission Control Data - 14.0 RU1 - SymAllLanguages
    {EDBD3BD0-8395-4d4d-BAC9-19DD32EF4758}: SEPC Iron Whitelist 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {810D5A61-809F-49c2-BD75-177F0647D2BA}: SEPC Iron Revocation List 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {263395A0-D3D8-4be4-80B5-202C94EF4AA0}: SEPC Iron Settings 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {E8827B4A-4F58-4dea-8C93-07B32A63D1C5}: SEPC Extended File Attributes and Signatures 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {03485132-6B4C-4075-8B19-3BE002B2AE80}: SEPC EDR - 14.0 - SymAllLanguages
    {88F5AA7A-AD7C-426A-8F25-465D3D43B1F1}: SEPC EDR - 14.0 RU1 - SymAllLanguages
    {075551EC-66BD-4487-9E2E-40645AF6F8B0}: SEPC STIC - 14.0 RU1 - SymAllLanguages
    {6040605B-DC27-4B91-8A7A-8671C606FF54}: SEPC AdvML (Static) Win32 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages
    {0717B2A8-65E5-48C8-8E06-4613B170EAA9}: SEPC AdvML (Static) Win64 14.0 RU1 - MicroDefsB.CurDefs - SymAllLanguages

    Anyone can tell me how its the name form the IPS ? this is it my setting:

     

     

     

     

     



  • 2.  RE: IPS configuration from SEP 12.X

    Posted Nov 09, 2018 03:44 PM

    CIDS Signatures are for IPS



  • 3.  RE: IPS configuration from SEP 12.X

    Posted Nov 09, 2018 03:48 PM

    Thanks Brian, but in the contentinfo.txt only download the IPS for the version 14, how download the IPS from the version 12?



  • 4.  RE: IPS configuration from SEP 12.X

    Posted Nov 09, 2018 04:01 PM
      |   view attached

    Is it checked?

     



  • 5.  RE: IPS configuration from SEP 12.X

    Posted Nov 09, 2018 04:04 PM

    Yes, all the component are selected



  • 6.  RE: IPS configuration from SEP 12.X
    Best Answer

    Posted Dec 20, 2018 01:47 PM

    Dear,

    In this case a have to add in the LUA server the version 14.0 for download and distributtion , after this change the IPS definition updated normally.

    The answer from Symantec was , for dessing of product the SEPM console need the definition of version 14 in the LUA server.