Endpoint Protection

 View Only
  • 1.  Update Content Command

    Posted Jun 24, 2010 01:31 PM
    Since we have installed SEP 11, we have had an issue where a large percentage of workstations will not update their Network Threat Protection/Protection Content/TruScan definations from the management server.  I have found that if I run LiveUpdate two days in a row, most of the time they will start updating from the management server again. 

    It also appears that running the Update Content command from the Management console will also resovle the issue.  My question is what does the Update Content command actually do?  Does it run LiveUpdate from the client and get updates from the internet or does it run a different update procedure that gets the updates from the GUP? 

    It is important to know because we want to limit WAN traffic during the day so it will be available for the users.  If it goes to the intenet to get the definations,  I want to only issue the command at the end of the day.  If it gets the definations from the GUPS, then it is fine to do it at any time.

    Bruce Singer


  • 2.  RE: Update Content Command

    Posted Jun 24, 2010 01:46 PM
    update command will make clients to take the updates from the manager
    this will also update the policy also
    once clients know that manager has updates ,they will take the updates only from manager, it will not go to internet for liveupdate


  • 3.  RE: Update Content Command

    Posted Jun 24, 2010 02:29 PM
    Running the update content command is not the solution for the issue.

    Please let us know:
    1. SEP Version
    2. No. of Clients
    3. OS on the SEPM
    4. Heartbeat interval.


  • 4.  RE: Update Content Command
    Best Answer

    Posted Jun 24, 2010 02:32 PM
    According to the Admin Guide (p. 76), Update Content command "Updates content on clients by initiating a LiveUpdate session on the clients. The clients receive the latest content from Symantec LiveUpdate."

    sandra


  • 5.  RE: Update Content Command

    Posted Jun 24, 2010 04:22 PM
    Please let us know:
    1. SEP Version
    SEP 11 RU5
    2. No. of Clients
    ~10500
    3. OS on the SEPM
    Two SEPM on Windows 2008 Standad X32 w SP2 using 2005 SQL on a Windows 2003 x32 bit SP3 OS.
    4. Heartbeat interval
    3 hours.


  • 6.  RE: Update Content Command

    Posted Jun 24, 2010 04:33 PM
    Thank you!

    I knew it had to be different than the standard update process becuase it updates the TruScan definations when the standard process doesnt. 

    That means I have to wait until after hours to issue the command to conserve our WAN bandwidth.

    It also means I don't know any way to resolve this problem on all the machines that are not allowed internet access.


  • 7.  RE: Update Content Command

    Posted Jun 24, 2010 05:05 PM
    Yes, unfortunately there is no way to update PTP and NTP signatures 'offline' (like you can do with a JDB file for virus definitions).  An internet connection has to be involved somewhere to get that content, whether to the SEPM or to the LUA server.  (...though the 'standard process' should update PTP; sometimes it takes a few heartbeats to do it, however.)

    I would suggest you vote this idea up:

    https://www-secure.symantec.com/connect/idea/jdb-file-should-update-all-components

    :)
    sandra