ClioSport.net

Register a free account today to become a member!
Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

  • When you purchase through links on our site, we may earn an affiliate commission. Read more here.

Symantec Endpoint Protection



Donny_Dog

ClioSport Club Member
  Jim's rejects
I've worked with this product from the early days of Norton 7.5.
Just in the process of deploying 12.1.
The chief has said there is an exam on it, anyone taken it?
 
  Nissan 350z
Had no involvement with 12, but ive been working on 11.4, 11.5, 11.6 and now 11.7
I'll be honest with, i hate it compared to McAfee. Trying to configure the estate to use Local GUPs instead of trying to saturation the network pulling from the Console is proving difficult.

Not to mention attmepting to find ANY information/report on which devices are pulling full.zip's as opposed to incremental definition updates :(
 

Donny_Dog

ClioSport Club Member
  Jim's rejects
Had no involvement with 12, but ive been working on 11.4, 11.5, 11.6 and now 11.7
I'll be honest with, i hate it compared to McAfee. Trying to configure the estate to use Local GUPs instead of trying to saturation the network pulling from the Console is proving difficult.

Not to mention attmepting to find ANY information/report on which devices are pulling full.zip's as opposed to incremental definition updates :(

The GUP component does seem like an afterthought, yet they kept tweaking it when 11 came out. I went down to Reading to do a course (after we'd rolled it out - thats how it works in our place) and queried them direct on it - they kept saying the next release will fix that, the next release will fix this...

The truth is there is little info about client updates from GUPs - even the managment log is pretty useless just saying 'definition file updated' and the like. Only way would be to wireshark or similar - but the instigation of retrieval from the GUP doesn't always execute on time!

How about deploying a Liveupdate Server? or a couple of them across the network?
 
  Nissan 350z
Problem is the clients infrastructure. We have the SEPM Console on a central server in Kent (this is also where the proxy is), and the estate is split over about 7 geographical offices in London. They used to previously all update happily from the Internet using LiveUpdate but as we increased coverage the bandwidth took a hammering and so they made the decision of switching to GUPs (one at each office) and to disable the LiveUpdate.

In theory this would work, but implementing it seems very hit and miss. I cant tell where a device is updating from (GUP or SEPM) and the only real solution to packet sniff EVERY device is a total joke. I would also like to see what devices are actually pulling accross the network (incremental updates or full definitions) but again, this isnt possible. Its things like this why i made the earlier statement about prefering McAfee.

Dont get me wrong its a good product, but it doesnt seem very user friendly and the SEPM console's whole "sort a page of devices A>Z, then go to page 2 and have to resort that page A>Z again" just stinks of amateur.
 

Donny_Dog

ClioSport Club Member
  Jim's rejects
Problem is the clients infrastructure. We have the SEPM Console on a central server in Kent, and the estate is split over about 7 geographical offices in London. They used to previously all update happily from the Internet using LiveUpdate but as we increased coverage the bandwidth took a hammering and so they made the decision of switching to GUPs (one at each office) and to disable the LiveUpdate.

In theory this would work, but implementing it seems very hit and miss. I cant tell where a device is updating from (GUP or SEPM) and the only real solution to packet sniff EVERY device is a total joke. I would also like to see what devices are actually pulling accross the network (incremental updates or full definitions) but again, this isnt possible. Its things like this why i made the earlier statement about prefering McAfee.

Dont get me wrong its a good product, but it doesnt seem very user friendly and the SEPM console's whole "sort a page of devices A>Z, then go to page 2 and have to resort that page A>Z again" just stinks of amateur.

Agreed. Even more so, it winds me up that location awareness cannot affect a clients membership status in a group! It will remain in the group, but you can apply differing policies based on location :( Massively frustrating with 2000 clients in 3 groups: Servers, Desktops, Laptops! There are pages and pages and indeed this is very amateur.

I guess the only way would be to have the GUP update the clients, but the GUP itself could be manually updated late at night, with a different policy? Ar$e about t*t though and still doesn't answer the question about incrementals.

Gone are the days of Disknet and reflex Macro Interceptor.
 
  Nissan 350z
Lol sorry to have de-railed your topic with my rant :)

Anyway if you do go on a course let me know if its any good because ive found the information available through the community forums and their support to be less than amazing so i would love the opertunity to get a good source of information on the course.
 

Donny_Dog

ClioSport Club Member
  Jim's rejects
Lol sorry to have de-railed your topic with my rant :)

Anyway if you do go on a course let me know if its any good because ive found the information available through the community forums and their support to be less than amazing so i would love the opertunity to get a good source of information on the course.

done the course already chief, it was last year.

The boss has said "there's an exam on it, its cheap - do it" So thats what I was asking really, if anyone has done it. I might just give it a go - if its easy, I'll drop you a PM! always good on a CV I suppose.
 


Top