Endpoint Protection

 View Only
Expand all | Collapse all

SEP on clustered exchange

Migration User

Migration UserJun 03, 2009 04:39 AM

Migration User

Migration UserJun 03, 2009 05:40 AM

Migration User

Migration UserJun 04, 2009 02:54 AM

  • 1.  SEP on clustered exchange

    Posted Jun 03, 2009 04:06 AM
    Hi,

    I have MS Windows Server 2003 with MS Exchange 2003 on a clustered environment. Previous installations prevents the failover to proceed.
    We're trying to install with the package I just made: The only diffence I made was using Silent and Default for the settings. (I made 2 packages)
    Not seen on the picture is that I selected a group specifically for that server.
    imagebrowser image

    The client server got this:
    imagebrowser image


    What's wrong with this picture?


  • 2.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 04:39 AM
    imagebrowser image

    Something to do with dependencies?


  • 3.  RE: SEP on clustered exchange



  • 4.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 05:40 AM
    what is the SEP version you are using?


  • 5.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 06:02 AM
    @Ajju: We're using SEP version 11.0.4014.26.

    We've just done a cleanwipe on the server and installing again. Antivirus and Antispyware only.


  • 6.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 06:13 AM
    Contrary to what the readme.txt says:
    "It is recommended that you click Yes in response to all prompts."
    Don't answer YES to the drivers!


  • 7.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 04:16 PM
     Since it is a Exchange server I would reccomend not to use Cleanwipe on it..As i have seen Cleanwipe doing disasters on servers.
    I would suggest you the safest but a bit boring way..
    Manual removal SEP..follow the doc TOP to bottom this issue should be resolved.

    How to manually uninstall Symantec Endpoint Protection client from Windows 2000, XP and 2003, 32-bit Editions

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007073018014248


  • 8.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 05:43 PM
    Please don't use cleanswipe, and any other Symantec Products installed on this server?



  • 9.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 05:52 PM
    I suggest you create a separate install package and feature set.


  • 10.  RE: SEP on clustered exchange

    Posted Jun 03, 2009 09:57 PM
    Yes, I learned that the hard way. :(
    The admin I was talking to doesn't WANT to do the manual removal I sent before that. So here we are.


  • 11.  RE: SEP on clustered exchange
    Best Answer

    Posted Jun 04, 2009 01:06 AM
    I'd recommend that in a clustered env. you install the SEP as an unmanaged client on all the shared arrays.

    So it'd be one client on each node. Thats the best way I've found it to work, and in the process I've also had to turn off the Tamper Protection to prevent any untoward issues like I'd faced for a POC while I was working in Symantec.




  • 12.  RE: SEP on clustered exchange

    Posted Jun 04, 2009 02:25 AM
    Thanks for the fresh insight. It reminded me of the problem I had with SAV not updating unless set to unmanaged.


  • 13.  RE: SEP on clustered exchange

    Posted Jun 04, 2009 02:54 AM
    Here are some of the alerts from the logs:
    imagebrowser image


  • 14.  RE: SEP on clustered exchange

    Posted Jun 04, 2009 12:11 PM
    That's the SMS logs mon, How about the logs of the Cluster Service? Btw, for the other nodes, what AV is currently installed? Is it SAV? is it unmanaged? What was the previous setup?


  • 15.  RE: SEP on clustered exchange

    Posted Jun 04, 2009 08:38 PM
    Hi Paul,

    We're currently migrating from SAV 10 to SEP 11. The other node is still in SAV.
    The one with SAV can still be managed by the SAV server.


  • 16.  RE: SEP on clustered exchange

    Posted Jun 04, 2009 10:22 PM
    The server admin says that it is currently working. But during observation in the past tests, the passive cluster works for about 2 days then fails.
    Symantec support says that there is nothing SEP related on the error logs and that this could be a MS OS problem and that we contact MS.

    That server was working fine in SAV until it was migrated to SEP. It also works fine without an AV.


  • 17.  RE: SEP on clustered exchange

    Posted Jun 05, 2009 05:49 PM
    I know this setup would not be recommended but can you try to test it without AV software for 2 days? So that we can isolate if it is an OS or AV problem.


  • 18.  RE: SEP on clustered exchange



  • 19.  RE: SEP on clustered exchange

    Posted Jun 06, 2009 01:28 PM
    No. I wouldn't suggest to have a production exchange server to run without an AV just to test it. Not even for half a day. They don't have a similar setup for testing, so we're stuck with what we have.

    If I know it is safe to run that, knowing that all shares are disabled and only the exchange is running on that server. Someone, please reassure me that no network threats will come to this server.


  • 20.  RE: SEP on clustered exchange

    Posted Jun 09, 2009 03:48 AM
    I already sent the instructions to create a package with only antivirus and antispyware enabled and there is no default group assigned. I'm going with the inmanaged/stand-alone solution. I'll post any updates here.


  • 21.  RE: SEP on clustered exchange

    Posted Jun 10, 2009 03:47 AM
    "If one SEP client in the cluster is temporarily down, virus definitions on that node will not be updated until the SEP client succcessfully starts and updates itself from the designated management server."

    as stated on the KB, I think they are no issues with SEP even on managed.


  • 22.  RE: SEP on clustered exchange

    Posted Jun 15, 2009 09:58 AM
    Thanks.

    Apparently, setting the SEP to unmanaged did the trick. Although I'm taking this as a workaround and not a solution. I've also discussed this with my other colleagues and they also said that the passive node should be unmanaged.