ProxySG & Advanced Secure Gateway

 View Only
  • 1.  SEPM Integration with CAS

    Posted Jul 16, 2018 05:02 AM

    Hi,

     

    Is SEPM Integration with CAS is similar to Kaspersky or additional setting need to bee done on CAS.

    Can we use AV on CAS at a time ?



  • 2.  RE: SEPM Integration with CAS
    Best Answer

    Posted Jul 16, 2018 05:23 AM

    Hi Aboo,

     

                   SEPM integration is to control the outbreak of a malicious file which CAS knows after the Sandboxing. The exact feature can be found below

     

    "When Content Analysis is integrated with Symantec Endpoint Protection Manager (SEPM), the endpoint computers are managed by SEPM and proxied through a ProxySG that is connected to Content Analysis. After configuring SEPM to work with Content Analysis, the administrator will be sent a threat alert when sandbox analysis reveals a file to be malicious. The admin then has the option of adding the file hash to the file fingerprint list (a blacklist) on SEPM. Once SEPM knows about this threat, no other end users will be able to run the file since it is on the endpoint blacklist; this stops the lateral spread of a malicious file on the network. In addition, administrators have the option of running SEPM remediation policy to clean up the initial infection; it executes the remediation policy that has been configured on SEPM."

     

                You can check the webguide for more info https://origin-symwisedownload.symantec.com/resources/webguides/contentanalysis/21/index.htm#Topics/Tasks/services_sandboxing_sepm.htm