Symantec 360R Administration Guide - Page 107

Enabling AVpe, Antivirus Policy, Query Master, Verify Latest Virus Definitions

Page 107 highlights

Advanced network traffic control 107 Configuring AVpe To configure antivirus policy enforcement See "AVpe field descriptions" on page 207. 1 In the SGMI, in the left pane, click Antivirus Policy. 2 In the Primary AV Master text box, in the right pane, under Server Location, type the IP address or fully qualified domain name of your primary antivirus server or master client. 3 Optionally, in the Secondary AV Master text box, type the IP address or fully qualified domain name of a backup antivirus server, if supported in your environment. 4 In the Query AV Master Every text box, type an interval (in minutes) for the appliance to query the antivirus server for updated virus definitions. 5 To force a manual update, click Query Master. 6 Under Policy Validation, next to Verify AV Client is Active, select one of the following: ■ Latest Product Engine To check a client's antivirus configuration to ensure it uses a supported Symantec antivirus product with the latest product scan engine. ■ Any Version To check a client's antivirus configuration to verify that a the correct version of a supported Symantec antivirus product is installed on the client's workstation. 7 To enable the appliance to validate whether a client is using the latest virus definitions, check Verify Latest Virus Definitions. 8 In the Query Clients Every text box, type an interval (in minutes) for the appliance to query clients to validate whether they are using updated virus definitions. 9 Click Save. Enabling AVpe AVpe is enforced at the computer group and VPN group level. To enable AVpe, you first select a group, and then enable AVpe once for all members of that group. You also decide whether you want to warn or to denny WAN access to clients if their antivirus configuration is not compliant with expected security policies.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

107
Advanced network traffic control
Configuring AVpe
To configure antivirus policy enforcement
See
“AVpe field descriptions”
on page 207.
1
In the SGMI, in the left pane, click
Antivirus Policy
.
2
In the Primary AV Master text box, in the right pane, under Server Location,
type the IP address or fully qualified domain name of your primary antivirus
server or master client.
3
Optionally, in the Secondary AV Master text box, type the IP address or fully
qualified domain name of a backup antivirus server, if supported in your
environment.
4
In the Query AV Master Every text box, type an interval (in minutes) for the
appliance to query the antivirus server for updated virus definitions.
5
To force a manual update, click
Query Master
.
6
Under Policy Validation, next to Verify AV Client is Active, select one of the
following:
Latest Product Engine
To check a client’s antivirus configuration to ensure it uses a supported
Symantec antivirus product with the latest product scan engine.
Any Version
To check a client’s antivirus configuration to verify that a the correct
version of a supported Symantec antivirus product is installed on the
client’s workstation.
7
To enable the appliance to validate whether a client is using the latest virus
definitions, check
Verify Latest Virus Definitions
.
8
In the Query Clients Every text box, type an interval (in minutes) for the
appliance to query clients to validate whether they are using updated virus
definitions.
9
Click
Save
.
Enabling AVpe
AVpe is enforced at the computer group and VPN group level. To enable AVpe,
you first select a group, and then enable AVpe once for all members of that
group. You also decide whether you want to warn or to denny WAN access to
clients if their antivirus configuration is not compliant with expected security
policies.