Endpoint Protection

 View Only
Expand all | Collapse all

Please suggest

  • 1.  Please suggest

    Posted Feb 14, 2011 12:32 AM

    Hi Team,

    I have one customer requirement is:

    One SEPM on Local Network which manage Desktops, Server and Laptops.

    One SEPM on DMZ to distribute definition and policies to roaming users.

    Scenario is:

    SEPM 1:

    Desktops and server both can pull definition first from Local SEPM and If not available then only try to download from Internet Symantec LiveUpdate server.

    SEPM 2:

    If Laptops user are roaming out of network then they can check local SEPM if not then DMZ server and If not then try to download from Internet Symantec LiveUpdate server.

    Please let me know how can I make this possible to met customer requirement.

    Thanks in advance.

     

    Regards,

    M.R



  • 2.  RE: Please suggest

    Posted Feb 14, 2011 12:49 AM

    1st Scenario: 

     

    How to configure mobile computers to automatically download virus definitions when disconnected from the Symantec Endpoint Protection Management console

    http://www.symantec.com/business/support/index?page=content&id=TECH104571&locale=en_US

    2nd Scenario:

     

    How to allow Symantec Endpoint Protection clients in a remote location to be managed by a Symantec Endpoint Protection Manager that's behind a NAT device

    http://www.symantec.com/business/support/index?page=content&id=TECH93033&locale=en_US

    if this is not available you can make it to go to symantec liveudpate same as first one..

    keep 2 sepm, one in each location, create a location specific policy for liveupdate, thats it.

     

     



  • 3.  RE: Please suggest

    Posted Feb 14, 2011 01:42 AM

    Hello Rafeeq,

     

    You mean to say that:

     

    1) I have to create Laptops group in Local SEPM.

    2) Create MSL only for Laptop group.

    3) In MSL add DMZ Server with communication port in Second Priority.

    3) Assign Policy to Laptop Group.

     

    Above is solution you are trying to suggesting me?



  • 4.  RE: Please suggest

    Posted Feb 14, 2011 01:43 AM

    If yes then I think we need to configure replication partner to do the same.



  • 5.  RE: Please suggest

    Posted Feb 14, 2011 02:20 AM

    yes, 

    I thought of writing about creating and managing Managment server list, but thought i would be making it more complicated.

    what you said is right, if you want one single sepm wich takes care of dmz and local area then you need replication..MSL.

    if there is two then you need to put one in each region.no replication only LU policy needs to be changed.

    for liveupdate all you have to do is to put laptops in one group and make the policy change for liveupdate.

    for our roaming user put a lu scheudle, when they have internet at home, it wil connect to symantec and download updates.

     

    Creating and assigning a management server list for a Symantec Endpoint Protection Manager

    http://www.symantec.com/business/support/index?page=content&id=TECH103175&locale=en_US

     

     

     



  • 6.  RE: Please suggest

    Posted Feb 14, 2011 02:29 AM

    Rafeeq,

     

    Customer wanted to install SEPM in DMZ because of the laptops user to pull desifition and policies as well.

    I understand that we can configure LU policy for laptop users to pull definition from Symantec Server but how can we point to DMZ for defintion and Policies?



  • 7.  RE: Please suggest

    Posted Feb 14, 2011 02:39 AM

    when laptop users connect, do they connect to lan or just dmz ? ?:)

    in that case you  need to configure sepm with external NAT the first link I posted above.



  • 8.  RE: Please suggest

    Posted Feb 14, 2011 02:47 AM

    Hello,

     

    Laptop should connect to LAN SEPM if they are in office, but If they are not in the office and connecting internet through their data card then they will check the followings:

     

    1. Local SEPM.

    2. DMZ SEPM. (If Local SEPM not found)

    3. If both unavailable then try to download definition from Symantec's LiveUpdate.

    Note: we are installing SEPM in DMZ for policies and definition for laptop users.



  • 9.  RE: Please suggest

    Posted Feb 14, 2011 02:48 AM

    Rafeeq,

     

    Have you check your PM which I sent before?



  • 10.  RE: Please suggest

    Posted Feb 14, 2011 02:50 AM


  • 11.  RE: Please suggest

    Posted Feb 14, 2011 02:55 AM

    And also one morething in location awareness how can we define our DMZ server?



  • 12.  RE: Please suggest

    Posted Feb 14, 2011 02:55 AM

    Refeeq,

     

    I understand about the Location awareness to update roaming clients but what about policies?



  • 13.  RE: Please suggest

    Posted Feb 14, 2011 05:03 AM

    I think we need to create replication partnet for this requirement because by doing the same only we can replicate LAPTOP group policies.

    And after finishing replication we will configure MSL policy only for LAPTOP group.

    Can anyone let me know that am driving right way?