Information Systems:Symantec Endpoint Protection

From uniWIKI
Jump to navigation Jump to search

Symantec Endpoint Protection is the anti-virus and anti-malware application that is used at UWD. SEP provides a barrier for malware on all desktops, laptops and Windows based servers. The application needs to have its license renewed every February and the cost of the license is determined by the number of seats needed. As of November of 2013, the number of seats needed is 70. The actual number of used seats is about 65 but there needs to be some extra for spare or temporary computers. The client application is controlled by SEP Manager which is installed on the Smithers server. SEPM is responsible for controlling the configuration, maintenance and deployment of the SEP clients. SEPM also is responsible for downloading the anti-virus and anti-malware definitions and then distributing them to the SEP clients.

The specific configuration of SEP is extremely important and absolutely critical to the software working correctly. The default factory configuration of the SEP client is too restrictive and will prevent UWD staff from being productive. The SEP client consists of modules that have different functions. The only modules that are needed by UWD are the anti-virus and anti-malware modules. Other modules such as the Symantec firewall are not needed because they conflict with the built in firewall that is included in Windows. The configuration of the SEP clients is also not change-able by restricted Windows users. The settings for turning off and on the SEP client and how it behaves is locked out to the SEPM program only. The reason for this is to prevent a virus from having the ability to disable the SEP client.

The SEP clients are configured to query SEPM for new definitions once per hour each day. If new definitions are available they are distributed from SEPM which downloads them directly from Symantec. Having only SEPM query Symantec for definitions saves on network bandwidth.

The SEP clients are configured to do a complete anti-virus scan of all files on the local hard drive each day at 5AM. It is set to occur at that time because the scan is processor intensive and would be disruptive to users if it was set to run during the work day. In the case of laptops that are usually not powered on at 5AM, the scan occurs when the machine is on and at idle and the scan runs at a low intensity for a longer period.

When a virus or malware touches the local file system or the memory of desktop/laptop/server, the SEP client will try to halt that process and present a pop up window to the user telling them to stop what they are doing and contact the IT department. The SEP client is configured to first try to delete the virus but if it can’t do that, it will try to quarantine it. If possible the SEP client will communicate to SEPM about the infection. SEPM will then notify IT by email that an infection occurred and on what machine. It is up to the IT administrator to determine if the infection is first real or a false positive, and then how to properly clean out the virus if SEP hasn’t already done it. The only way to be 100% positive that a virus is gone is to re-image the computer. This erases the entire hard drive and restores the user profile from the Superserver. Re-imaging is not always convenient but for some cases it is the quickest method to restore from a real virus infection. The safety of the corporate network is paramount and sometimes it is just the best method to wipe the machine and restore the OS image.

SEPM is capable of producing some useful reports on which computers have the latest definitions and the rates and types of infections. SEPM is also the recommended starting point to deploy the SEP client to desktops/laptops/servers. The configuration settings in SEPM are integrated into a client package and then sent over the network to install remotely on the computer. SEPM then instructs the client to reboot if needed. Doing deployments in this method makes sure that the client gets the right settings and the latest definitions in one step. Upgraded versions of the SEP client can also be deployed this way and do not require IT staff to walk around to each work station.

SEPM can be access from the Smithers desktop directly or from the web administration page at https://smithers.unipharm.local:8443/console/apps/sepm

Technical support is part of the license with first level being off shore based and second level located in Oregon. The phone number for technical support is 1-800-721-3934 and is available 24/7. The support technician will need a license number and that can be found on the license certificate document that is emailed to IT when the license is renewed each year.

CHANGELOG

  • As of Feb-05-2020 mysymentec is the way to reach out to them , https://support.symantec.com/us/en.html is the url and the username password have been added to the password list.
  • As of march-01-20 Broadcom has taken ownership of support , the above link and credentials have been migrated tot he broadcom site by aaront
  • AS OF MAY2021
  • SYMANTEC ENDPOINT MANAGER VERSION IS 14
  • CLIENT VERSIONS FOR WORKSTATIONS IS 14
  • CLIENT VERSIONS FOR SERVERS IS 12
  • Client packages located on SUPERSERVER|UWDSOFTWARE|SYMANTEC
  • SYMANTEC DIAGNOSTIC TOOL located on SUPERSERVER|UWDSOFTWARE|SYMANTEC