Symantec 10551441 Administration Guide - Page 51

Forcing the access list to reload, Rolling out the access list

Page 51 highlights

Managing Symantec AntiVirus 51 Enhancing server group security Forcing the access list to reload By default, the access list is refreshed every five minutes. If you want a change that you make to the list to take place immediately, you can force the reload. To force the access list to reload 1 Start a registry editor, such as Regedt32. 2 Open the HKEY_LOCAL_MACHINE\SOFTWARE \INTEL\LANDesk\ VirusProtect6\CurrentVersion\ProductControl key. 3 Type ReadAccessList as a new DWord. 4 Type 1 as the binary data associated with the ReadAccessList DWord value. 5 Close the registry editor. Rolling out the access list You can roll out the access list by performing the following tasks: ■ Create a registry script with the information that you want to add to the access list, such as new values to authorize additional computers. ■ Roll out the access list via your preferred distribution tool. ■ Force the Symantec AntiVirus antivirus component to import the access list immediately. See "Forcing the access list to reload" on page 51. Logging unauthorized configuration change attempts When the Symantec AntiVirus antivirus component receives communication from an address that is not included in the access list, an event can be written to the Symantec AntiVirus Event Log. When the event occurs on a computer running Symantec AntiVirus, the log event is forwarded to the parent server. Note: Unauthorized configuration change information is not written to logs by default. Log changes and set logging frequency You can edit the registry to log unauthorized changes. You can specify the frequency with which these items are logged. To log unauthorized configuration changes 1 Start a registry editor, such as Regedt32.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

51
Managing Symantec AntiVirus
Enhancing server group security
Forcing the access list to reload
By default, the access list is refreshed every five minutes. If you want a change
that you make to the list to take place immediately, you can force the reload.
To force the access list to reload
1
Start a registry editor, such as Regedt32.
2
Open the HKEY_LOCAL_MACHINE\SOFTWARE \INTEL\LANDesk\
VirusProtect6\CurrentVersion\ProductControl key.
3
Type
ReadAccessList
as a new DWord.
4
Type
1
as the binary data associated with the ReadAccessList DWord value.
5
Close the registry editor.
Rolling out the access list
You can roll out the access list by performing the following tasks:
Create a registry script with the information that you want to add to the
access list, such as new values to authorize additional computers.
Roll out the access list via your preferred distribution tool.
Force the Symantec AntiVirus antivirus component to import the access list
immediately.
See
“Forcing the access list to reload”
on page 51.
Logging unauthorized configuration change attempts
When the Symantec AntiVirus antivirus component receives communication
from an address that is not included in the access list, an event can be written to
the Symantec AntiVirus Event Log. When the event occurs on a computer
running Symantec AntiVirus, the log event is forwarded to the parent server.
Note:
Unauthorized configuration change information is not written to logs by
default.
Log changes and set logging frequency
You can edit the registry to log unauthorized changes. You can specify the
frequency with which these items are logged.
To log unauthorized configuration changes
1
Start a registry editor, such as Regedt32.