Endpoint Protection

 View Only
  • 1.  Symantec Lockdown

    Posted Mar 09, 2015 03:20 AM

    I have two queries on Symantec Lockdown.

    a) Do I need a separate license to use this feature?

    b) Can I define Updaters with Symantec Lockdown. For example I wany my Windows Update client to update the monthly MS security patches without any intervention with the Symantec Lockdown.



  • 2.  RE: Symantec Lockdown

    Broadcom Employee
    Posted Mar 09, 2015 03:23 AM

    Hi,

    Thank you for posting in Symantec community.

    I would be glad to answer your query. No need to call support just to get answer of these two queries.

    a) Do I need a separate license to use this feature?

    --> Separate License is not required, System lockdown is one of the SEP feature.

    #Edit

    b) Can I define Updaters with Symantec Lockdown. For example I wany my Windows Update client to update the monthly MS security patches without any intervention with the Symantec Lockdown.

    -->  SEP system lockdown feature, in whitelist mode (which is the default mode of system lockdown), puts the most strict control on what applications can run on a computer. So usually it is expected that the executable binary files do NOT change much on the computer. These changes include software upgrade, Windows update and SEP definitions update. Due to the strict control, frequent Windows update or SEP definitions update becomes unnecessary. If it does become necessary, then careful planning and administrative overhead is usually unavoidable. Please consider carefully on which computers should have system lockdown enabled.

    Typically when using System Lockdown it is best to install new hotfixes in a testing environment first, and create new fingerprint files after installing the updates. Once the new fingerprints have been added to the System Lockdown policy you can allow the hotfix to be installed on the user systems.Failure to add new fingerprints for the system files modified by the hotfix into the System Lockdown policy could cause problems with the Operating System

    Refer these articles:

    Configuring system lockdown

    http://www.symantec.com/docs/HOWTO55130

    Enabling automatic updates of whitelists and blacklists for system lockdown

    http://www.symantec.com/docs/HOWTO81097

     

     



  • 3.  RE: Symantec Lockdown

    Posted Mar 09, 2015 03:31 AM

    No you dont need separate license for this.its all covered, you are good to go :)

    for windows updates follow this document but its not available now, call support they will get you the steps

    https://www-secure.symantec.com/connect/forums/i-need-how-configure-system-lockdown-allow-microsoft-security-updates

     



  • 4.  RE: Symantec Lockdown

    Posted Mar 09, 2015 07:03 AM

    No separate license is required. It's a component/feature of SEP.

    In addition to allowing MS updates you will also need to allow Symantec updates, see here:

    Symantec Endpoint Protection system lockdown blocks definitions updates

    The article on allowing MS updates seems to have expired. Contact support as they can provide something.