Advice Request Help with Symantec unmanged client config

Please provide comments and solutions that are helpful to the author of this topic.

Vitali Ortzi

Level 22
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
So basically I have been trying to edit/config Symantec endpoint unmanaged client SRP
module but unfortunately wasn't able to, Sine Symantec doesn't allow editing without SPEM (Managed) even tried to edit the .dat policy files, but they are encrypted
The only possible way is via XML export from a managed client .
if anyone has SPEM or Configured Sep with default deny policy for (application and device control module) and only needed ports allowed (53,80,4443,443,8080).
You can see the image below for the modules I currently have installed .
link to Broadcom guide in how to export configured XML :
ביאור 2020-03-28 005452.png
 

Burrito

Level 24
Verified
Top Poster
Well-known
May 16, 2018
1,363
@ForgottenSeer 58943 can you export a xml / dat policy file or provide a link to spem trial ?

@ForgottenSeer 58943 is a good guy to ask. He may have a link to a sperm trial. But he only checks into MT occasionally now.

Possibly @bjm_ would know.... but maybe he's more of a Norton guy -- rather than Symantec. Not sure.

I run SEP on 2 machines... but I have nothing beyond the unmanaged endpoints.

And... I will lose SEP 14 soon, as my comped copy is being taken away.

On an old computer, I have SEP 12.1-- but definitions EOL is coming up for that one. And that's too bad. SEP 12.1 is perfect for an old machine.

And so........ Burrito & SEP will part ways. 😐
 

Vitali Ortzi

Level 22
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
@ForgottenSeer 58943 is a good guy to ask. He may have a link to a sperm trial. But he only checks into MT occasionally now.

Possibly @bjm_ would know.... but maybe he's more of a Norton guy -- rather than Symantec. Not sure.

I run SEP on 2 machines... but I have nothing beyond the unmanaged endpoints.

And... I will lose SEP 14 soon, as my comped copy is being taken away.

On an old computer, I have SEP 12.1-- but definitions EOL is coming up for that one. And that's too bad. SEP 12.1 is perfect for an old machine.

And so........ Burrito & SEP will part ways. 😐
Thankfully my license is rated as non expiring at least till SES replaces SEP(inbuilt slf )
anyway doesn't just the definition update(live update module) is blocked after expire for non managed?
 

Burrito

Level 24
Verified
Top Poster
Well-known
May 16, 2018
1,363
Thankfully my license is rated as non expiring at least till SES replaces SEP(inbuilt slf )
anyway doesn't just the definition update(live update module) is blocked after expire for non managed?

Typically yes.

For SEP, often the software is tied to an enterprise/corporate account. In some cases, the software will become nonfunctional if the associated enterprise account is terminated or if a sysadmin (from the sponsoring enterprise entity) cuts off unmanaged clients.

But often, you get to keep SEP forever until they stop providing definitions. In many cases though (depending on the account that your SEP is linked to) -- you cannot get software updates.

If you have SEP 14 --- then that's great. It's good and light protection.
 

Dave Russo

Level 21
Verified
Top Poster
Well-known
May 26, 2014
1,056
Typically yes.

For SEP, often the software is tied to an enterprise/corporate account. In some cases, the software will become nonfunctional if the associated enterprise account is terminated or if a sysadmin (from the sponsoring enterprise entity) cuts off unmanaged clients.

But often, you get to keep SEP forever until they stop providing definitions. In many cases though (depending on the account that your SEP is linked to) -- you cannot get software updates.

If you have SEP 14 --- then that's great. It's good and light protection.
When they stop providing definitions(if thy do) will the only way to know is that the live update status will no longer work ,no you think?
 

Vitali Ortzi

Level 22
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
When they stop providing definitions(if thy do) will the only way to know is that the live update status will no longer work ,no you think?
it might take some time to migrate the whole enterprises systems to SES.
I bet we will get at least a year before stopping live updates on SEP from the moment Symantec sends the free upgrade to SES.
 

Burrito

Level 24
Verified
Top Poster
Well-known
May 16, 2018
1,363
it might take some time to migrate the whole enterprises systems to SES.
I bet we will get at least a year before stopping live updates on SEP from the moment Symantec sends the free upgrade to SES.

I think you will get a lot more time than that.

At the link I posted above.... SEP 12 will get definitions until April 21.

I suspect that SEP 14 will get them for quite a bit longer.

But.... with Broadcom in charge.... hard to know for sure.
 

Vitali Ortzi

Level 22
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
I think you will get a lot more time than that.

At the link I posted above.... SEP 12 will get definitions until April 21.

I suspect that SEP 14 will get them for quite a bit longer.

But.... with Broadcom in charge.... hard to know for sure.
I just cant trust Broadcom with that ,
you know already the hell that enterprises and suppliers have with licensing.
at least I hope someone could just port a good xml policy that might help even after the end of support !
so we can use the superb SEP firewall and SRP module .
 

Dave Russo

Level 21
Verified
Top Poster
Well-known
May 26, 2014
1,056
Thankfully my license is rated as non expiring at least till SES replaces SEP(inbuilt slf )
anyway doesn't just the definition update(live update module) is blocked after expire for non managed?
Have you changed any of the firewall settings? 1.,I added"Block all traffic until Firewall starts and after Firewall stops 2.Enable network application monitoring.
 

Vitali Ortzi

Level 22
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
Have you changed any of the firewall settings? 1.,I added"Block all traffic until Firewall starts and after Firewall stops 2.Enable network application monitoring.
Yes I did , so I don't need a firewall policy other then what's optional by the GUI.
Only missing is the limited use of the SRP without a policy change via SPEM.
 

Vitali Ortzi

Level 22
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
if anyone wants full sep capability i can make a policy for an unmanaged client
just pm me
i have a trick to get very long extended SPEM trial pm me if you want it
 
  • Like
Reactions: [correlate]

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top