Endpoint Protection

 View Only
  • 1.  Pull definitions from SEPM

    Posted Dec 12, 2017 12:16 PM

    Hi,

    I am in the process of setting up an SEPM that does not have an outbound internet connection and I am struggling to find out how I can get these definitions, downloading them every couple of days is not a long term solution. We already have a separated network which has an SEPM with an outbound internet connection, and I can pitch the need for access between the new SEPM that doesn’t have outbound internet to the SEPM that doesn’t have outbound internet.

    Is it possible for one SEPM to pull definitions from another SEPM? If so is there a knowledge base article detailing these instructions?

    If it isn’t possible is there a way around this situation?

    Thanks,

    Jon



  • 2.  RE: Pull definitions from SEPM

    Posted Dec 12, 2017 12:19 PM

    You could setup a LUA:

    http://www.symantec.com/docs/HOWTO44060

    http://www.symantec.com/docs/TECH154896



  • 3.  RE: Pull definitions from SEPM

    Posted Dec 12, 2017 12:28 PM

    That did seem to be the only solution I could find, although I did read it is not advisable to run this product on the same server that SEPM runs on. Is this still the case? 

    Thank you for the articles you have provided I will see if this will fit our needs.



  • 4.  RE: Pull definitions from SEPM

    Posted Dec 12, 2017 12:31 PM

    It should have its own server.



  • 5.  RE: Pull definitions from SEPM

    Posted Dec 12, 2017 02:14 PM

    Hello,

    One thing pops into my mind but not sure if SEPM could download updates from anther SEPM with LU reverse-proxy setup :) but maybe worth trying? 



  • 6.  RE: Pull definitions from SEPM

    Broadcom Employee
    Posted Dec 13, 2017 04:05 PM

    LUA would be your only option for this. If you could allow a connection to the other public SEPM, you could install this SEPM as a replication Partner.  You could then set up the public SEPM to download content and to replicate that content over to this dark SEPM.

    This would involve you uninstalling the dark SEPM and then reinstalling as a replication partner though.

    John