Symantec 360R Administration Guide - Page 106

Configuring AVpe

Page 106 highlights

106 Advanced network traffic control Configuring AVpe ■ If your network is comprised of clients that are unmanaged and access LiveUpdate directly for their AV updates, decide which client to designate as the master. The master should always be turned on, have an active Symantec antivirus client, and have a connection to the Internet where it can download virus definition updates. ■ If your network topology includes a configuration in which client workstations are located behind an enclave firewall, and iff the firewall performs address transforms, which changes the client's actual IP address, the security gateway is unable to communicate with the client (as is required to validate client virus definitions). In this configuration, the security gateway contacts the firewall, not the client. ■ Ensure that traffic is not being blocked by a personal firewall. You must allow UDP/Port 2967 on all personal firewalls. This is set by default in Symantec Client VPN version 8.0. Configuring AVpe Configuring AVpe for a Symantec AntiVirus Corporate Edition environment and a client-only network is similar. Configuring for Symantec AntiVirus Corporate Edition servers involves the following tasks: ■ Defining the location of the primary and (optionally) a secondary Symantec AntiVirus server and verifying that a client has the Symantec AntiVirus Corporate Edition client installed and that the virus definitions and the scanning engine on client computers are up-to-date. See "Configuring AVpe" on page 106. ■ Enabling AVpe for Computer or VPN Groups. See "Enabling AVpe" on page 107. Configuring for networks with unmanaged antivirus clients (without Symantec AntiVirus Corporate Edition) involves the following tasks: ■ Defining the location of the policy master client and verifying that it has a supported Symantec antivirus client installed and that the virus definitions and the scanning engine on client computers are up-to-date. ■ Enabling AVpe for Computer or VPN Groups. See "Enabling AVpe" on page 107. ■ Configuring the AV clients. See "Configuring the antivirus clients" on page 109.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

106
Advanced network traffic control
Configuring AVpe
If your network is comprised of clients that are unmanaged and access
LiveUpdate directly for their AV updates, decide which client to designate as
the master. The master should always be turned on, have an active
Symantec antivirus client, and have a connection to the Internet where it
can download virus definition updates.
If your network topology includes a configuration in which client
workstations are located behind an enclave firewall, and iff the firewall
performs address transforms, which changes the client’s actual IP address,
the security gateway is unable to communicate with the client (as is required
to validate client virus definitions). In this configuration, the security
gateway contacts the firewall, not the client.
Ensure that traffic is not being blocked by a personal firewall. You must
allow UDP/Port 2967 on all personal firewalls. This is set by default in
Symantec Client VPN version 8.0.
Configuring AVpe
Configuring AVpe for a Symantec AntiVirus Corporate Edition environment and
a client-only network is similar.
Configuring for Symantec AntiVirus Corporate Edition servers involves the
following tasks:
Defining the location of the primary and (optionally) a secondary Symantec
AntiVirus server and verifying that a client has the Symantec AntiVirus
Corporate Edition client installed and that the virus definitions and the
scanning engine on client computers are up-to-date.
See
“Configuring AVpe”
on page 106.
Enabling AVpe for Computer or VPN Groups.
See
“Enabling AVpe”
on page 107.
Configuring for networks with unmanaged antivirus clients (without Symantec
AntiVirus Corporate Edition) involves the following tasks:
Defining the location of the policy master client and verifying that it has a
supported Symantec antivirus client installed and that the virus definitions
and the scanning engine on client computers are up-to-date.
Enabling AVpe for Computer or VPN Groups.
See
“Enabling AVpe”
on page 107.
Configuring the AV clients.
See
“Configuring the antivirus clients”
on page 109.