I’m cur­rently in a webex sem­i­nar for Syman­tec End­point Secu­rity — the mod­er­a­tor has not joined yet. I thought I would share thoughts and ideas as this went along — and for ref­er­ence to myself at a later date. I real­ize this is no apple speech or Nin­tendo launch — but we all have to get our real time blog­ging skills up to date some­how. I signed and view no dis­clo­sure agree­ment in the invi­ta­tion that was given to me and I would not have vio­lated it if I did. This is not spe­cific to my job or com­pany so I don’t feel I’m vio­lat­ing any trust.

The sem­i­nar is sched­uled to be 1 hour and 15 min­utes — unless it’s a really short sem­i­nar and its only 1 minute 15 sec­onds — in that case I guess this is a hug waste of time.

Wait­ing for the mod­er­a­tor — we just got a mes­sage that the sem­i­nar will start in 3 min­utes — 2 min­utes late btw.

The pre­sen­ter accord­ing to the slide is Kevin Haley, Direc­tor of Tech­ni­cal Prod­uct Man­age­ment in the End­point Secu­rity Group.

Since my under­stand­ing is that replaces Syman­tec Anti-virus there is a dras­tic change as they con­sol­i­date all the prod­ucts they have pur­chased in the past try­ing to get them to work cohesively.

The sem­i­nar just started only 4 min­utes late.

Kevin is respon­si­ble for Syman­tec End Point protection.

Agenda:
Goals of the sem­i­nar
Overview of the prod­uct
Migra­tion and Migra­tion issues
Addi­tional tools

Goals:

They’ve muted the par­tic­i­pants for our own anonymity *roll eyes* — I know from expe­ri­ence that this is solely to not get stopped by pos­si­ble trig­ger points that lis­ten­ers may have.

We have options of typ­ing in ques­tions and get­ting them answered in real time.

Prod­uct Overview:

Syman­tec End­point Pro­tec­tion 11.0 and Syman­tec Multi-tier pro­tec­tions 11.0

Multi tier is the new ver­sion of SAV Enter­prise Edi­tion 8, 9, 10 — cus­tomer with upgrade pro­tec­tion and sup­port with Syman­tec will get a free upgrade. This also includes SAV for Mac OSX.

End­point pro­tec­tion 11.0 — is the upgrade for SAV CE, SCS, Syman­tec Sygate Enter­prise Pro­tec­tion, and Whole Con­fi­dence online for cor­po­rate PC’s get this in their upgrade contract

They now took a poll if we entered the beta test for Syman­tec End­point Pro­tec­tion — 9% did pub­lic — 20% did exter­nal and 69% did not (this was a sem­i­nar poll for the participants.

They are talk­ing about the rea­sons for inte­grat­ing everything

Parts

Anti­spy­ware — Leads in root kit detec­tion and removal *unless they are keep­ing quiet for Sony
Antivirus

Fire­wall tech­nol­ogy — taken from Syman­tec Client Secu­rity and Sygate

Intru­sion Pre­ven­tion — Behav­ior Based Threat pro­tec­tion — SONAR whole secu­rity — net­work traf­fic protection

Device Control/ Appli­ca­tion Control

Net­work Access Con­trol — add on client

New client is all bub­bly and vista like — take that how you want. New help and sup­port but­ton allows some basic trou­bleshoot­ing info in one spot. Access to win­dows accounts info, disk space, log files, and ver­sion infor­ma­tion. You can also import or export poli­cies from the client. Any client installed by default from the CD are ini­tially self man­aged — if you want them to be man­aged by default you need to cre­ate an instal­la­tion pack­age on your man­age­ment server.

You can change all poli­cies not just the fire­wall based on location.

The file that tells if the client is man­aged or unman­aged is located in the file sylink.xml — con­tains also server list, cer­tifi­cate info, heart­beat, and com­mu­ni­ca­tions. There is a tool to auto edit the file included on the cd for easy man­aged to unman­aged deploy­ment. You could also edit this man­u­ally and the file is said to be documented.

Intru­sion pre­ven­tion capa­bil­ity — net­work based intru­sion pre­ven­tion tied into the tcp stack — generic exploit block­ing from SCS and Sygate IDS which sup­ports cus­tom sig­na­tures — sig­na­ture for­mat is sim­i­lar to Snort. Behav­ior block­ing — proac­tive threat scan from whole secu­rity — inno­v­a­tive behav­ior based analy­sis — uniquely accu­rate low .004% false pos­i­tive rate (test­ing for 2 years) via the web site and the con­sumer prod­uct (your enter­prise beta testers) — enables broad deploy­ment on end­points. 20 mil­lion instal­la­tions dur­ing the test — so 40 false pos­i­tives for every 1 mil­lion PC’s — can also do white list­ing so false pos­i­tives only show up once.

Stu­pid pic­ture of a cookie jar with a dig­i­tal cam­era and video cam­era — cook­ies dis­ap­pear in the night and you want to catch who is doing this used cam­era for ran­dom images or cam­corder you can review the film later but the cam­corder solu­tion is more expen­sive — so proac­tive threat scan­ning takes a pic­ture of all the processes every 15 min­utes and ana­lyzes it. *is this seri­ously the best analogy?????????

Appli­ca­tion Con­trol — you can dis­able cer­tain application

Device pro­tec­tion — block devices by type — try­ing to stop items like USB, infrared, Blue­tooth, ser­ial , par­al­lel , firewire, scsi, PCMCIA — can block read/write exe­cute on burn­able media dri­ves — can block all USB except key­board and mouse — *I would just use a browser

Fea­tures overview
email report dis­tri­b­u­tion on a sched­ule
cen­tral­ized event log­ging
cus­tomiz­able reports
real time event view­ing
noti­fi­ca­tions view
event export to SSIM or 3rd part
Embed­ded and MS SQL sup­port
Client install pack­age builder
patch and update
remote instal­la­tion
import and sync with Ad
authen­ti­cate with AD
cus­tomized agent pack­age instal­la­tion
Migra­tion from SAV, SCS, SSEP,& SNAC
Cen­tral­ized Web Based con­sole
Sim­pli­fied inter­face for SMB and enter­prise
Role Based Access
Admin­is­tra­tive domains
Assign rights by user or group
User defined multi tier groups
RSA SecurID
Inte­grated man­age­ment of all agent com­po­nents
sin­gle con­sole for man­age­ment of AV, FW, NAC and other poli­cies
Group based polices
– I missed the last two.

Migra­tion

Stan­dard migra­tion steps so far — doc­u­ment, design, install archi­tec­ture, migrate exist­ing groups and poli­cies, con­fig­ure report­ing, con­fig­ure server/site (poli­cies, groups, Admins, noti­fi­ca­tions etc. , cre­ate and test client packages,

Java based Man­age­ment — talk to it on HTTPS (admin and client) clients can be con­fig­ured for HTTP if you want unen­crypted traf­fic– SQL data­base for storage.

Data­base con­tains
Group struc­ture
poli­cies
patches
logs
content

only repli­cates
Group Policies/Logs/Content

SQL can be sep­a­rate from the man­age­ment sever — many man­age­ment servers can use a sin­gle data­base. Num­bers are to be deter­mined but there is basic info in the doc­u­men­ta­tion — hard num­bers will not be avail­able in FCS (First Cus­tomer Shipment)

Dis­trib­uted envi­ron­ment — mul­ti­ple man­age­ment servers and data­bases — Man­age­ment servers always repli­cate poli­cies and group infor­ma­tion between them — so they will all know about ALL the clients and poli­cies — any client can check into any server — but you can restrict that by server or server group — you can also setup a order it checks in. Log­ging repli­ca­tion is optional and they call it fil­ter­ing — if you have a cur­rent archi­tec­ture where all infor­ma­tion rolls up to a mas­ter server you can still do that — or you can repli­cate all logs to all servers.

Sup­ports migra­tion from SAV, SCS, and SSEP — clients upgrade to SAV 11.0 will auto­mat­i­cally con­nect to new SESM

Look and feel for report­ing data is the same

First use wiz­ard sim­pli­fies ini­tial setup

SEPM can run on the save server as a SAV man­age­ment server since they are designed to coex­ist since they use dif­fer­ent executables.

Migra­tion 1 — on same server as your SAV server
Install SEPM
Move Group and Pol­icy info from SSE
Install SAV 11
Decom­mis­sion orig­i­nal Par­ent server

Migra­tion 2 — dif­fer­ent server
Poli­cies can migrate with first use wiz­ard — other steps very similar

Report­ing migration

Sav 10.1 — you can redi­rect clients to the new SEP 11 data­base for reporting.

Client instal­la­tion — sup­port to install over SAV 9–10.1, SCS 3–3.1, SEP 5.1, SPA 5.1 (don’t have to unin­stall these products)

Already rolled out inter­nally at Syman­tec with 5000 users

First use wiz­ard — which will enable you to migrate your groups, poli­cies, users to your new man­age­ment server — they will not install the client auto­mat­i­cally on a man­age­ment server-so this will have to be done man­u­ally. They warn about installing the client fire­wall on the servers install — LOL — I can see why but I won­der how many admin­is­tra­tors actu­ally did that.

Con­tent distribution

SEPM gets client updates and con­tent from Syman­tec live update — clients can be patched from man­age­ment server using only a small dif­fer­ence file that can be pushed down.

Still can get con­tent from cen­tral inter­nal live update server or rapid release definitions

Clients send events, oper­a­tion state, and com­mand sta­tus to the SEPM server — com­mands are sent to client from server, pro­files, con­tent, updates sent to client — con­tent and updates only the dif­fer­ent micro def­i­n­i­tions they don’t’ have are sent instead of all the def­i­n­i­tions each time.

Clients with a group update provider — will go to the group update provider for con­tent (av defs, etc.)

The group update providers caches infor­ma­tion from the SEPM server — designed for low band­width architectures.

Unman­aged clients can still go to live update on their own

Addi­tional tools

http://edm.symantec.com/endpointsecurity/

http://www.symantec.com/endpointsecurity/migrate — migra­tion infor­ma­tion
Con­sult­ing Ser­vices and support

Good­byes and that’s the end

Ques­tions and Answer from the text box:+

Ques­tion: Sorry missed what said… Did you men­tion Mac­in­tosh would be included?
Answer: Yes, MAC will be included

Ques­tion: Will the Multi-Tier con­sole server han­dle Mac­in­tosh clients?
Answer: MAC will not be man­aged by the SEPM con­sole this release

Ques­tion: Will it be Vista com­pli­ant?
Answer: Yes

Ques­tion: Will the Syman­tec Multi-tier Pro­tec­tion for MAC be able to uti­lize the Par­ent Servers for Win­dows?
Answer: No. MAC has its own con­sole as it stands today.

Ques­tion: Ask­ing about the con­sole. Will there still be a seper­ate con­sole server for Macs?
Answer: Yes

Ques­tion: So there won’t be a Mac solu­tion if we’re a SEPM cus­tomer?
Answer: MAC is included in the Multi-Tier Pro­tec­tion but it is man­aged by a seper­ate con­sole and server struc­ture

Ques­tion: What is the upgrade from SAVCE
Answer: Syman­tec End­point Pro­tec­tion 11.0

Ques­tion: is the full end­point suite required, or can you still pur­chase prod­ucts sep­a­rately?
Answer: You get every­thing as long as you are cur­rent on main­te­nance.

Ques­tion: Assum­ing no more con­sole?
Answer: MAC will be man­aged by its own con­sole. SEPM will man­age all win­dows clients

Ques­tion: Can you turn off var­i­ous com­po­nents?
Answer: Yes, you can enable and dis­able the fea­tures as needed.

Ques­tion: Will it have built in report­ing capa­bil­i­ties or do we need to con­tinue with SAV reporter?
Answer: SEPM has report­ing built in.

Ques­tion: Will the SEP v11 con­sole be able to man­aged legacy clients (SAV10, etc)
Answer: No. It will not man­age legacy SAV clients

Ques­tion: Will this all still be in a sin­gle agent?
Answer: Yes, Sin­gle Client with all the men­tioned tech­nolo­gies

Ques­tion: Will these prod­ucts be Vista logo’d or just Vista com­pli­ant? Also will you be pro­vid­ing both 32bit and 64bit clients?
Answer: Yes, we will be pro­vid­ing both 32 and 64 bit ver­sions of the client. Vista com­pli­ant.

Ques­tion: What? We will need to run mul­ti­ple con­soles? Will they all feed into SSIM?
Answer: SEPM will man­age the win­dows clients only with this release. Yes, we will have a col­lec­tor for SSIM

Ques­tion: Will we go over migrat­ing an exist­ing Report­ing Server to the built-in report­ing in SEPM?
Answer: There is a white paper that will be avail­able as well as a migra­tion wiz­ard

Ques­tion: would this be red if I dis­abled it from man­age­ment side?
Answer: Yes

Ques­tion: does the user need admin rights to exe­cute a FIX
Answer: The fix can be run as sys­tem by the client

Ques­tion: Are there dif­fer­ent lev­els of users pro­vided in the SEPM?
Answer: Yes, admin­is­tra­tors can have dif­fer­ent func­tions and rights as con­fig­ured. There is lim­ited admin­is­tra­tion.

Ques­tion: Will the 64-bit client dif­fer by proces­sor type, or will the 64-bit client be uni­ver­sal?
Answer: Uni­ver­sal

Ques­tion: Cur­rent instal­la­tion from CD presents you an option to choose the man­age­ment server if you want to install man­aged. Why has that been removed?
Answer: You can cre­ate pack­ages that are “unman­aged” still it is just a dif­fer­ent process.

Ques­tion: can it be locked so a cleint can’t remove from a server?
Answer: Yes

Ques­tion: In pre­vi­ous ver­sions, we could spec­ify man­age­ment server. This is not possible

now?
Answer: Yes. It still is pos­si­ble to spec­ify the server that will man­age the client.

Ques­tion: Will the client upgrade han­dle all cur­rent indi­vid­ual com­po­nents that may be installed on the desk­top (SSEP, SAV10, etc.)?
Answer: Yes, absolutely

Ques­tion: Does the new pol­icy import/export replace the usage of GRC.dat and the need to at times man­u­ally imple­ment it.
Answer: Yes. Sylink.xml is the new file used.

Ques­tion: Will the SPEM have the abil­ity to set secu­rity access for other users/groups to man­age their servers or sites?
Answer: Yes

Ques­tion: So the sylink.xml replaces the grc.dat except it doesnt dis­ap­pear once processed by the client?
Answer: Yes, exactly

Ques­tion: When will this release be avail­able?
Answer: End of the month

Ques­tion: can you import SNORT sig­naturs?
Answer: No, we sup­port REGEX and have a lan­guage sim­il­iar to snort

Ques­tion: Is there a max­i­mum net­work latency value between a pol­icy sevrer andf end client that we should con­sider when deter­mine the count and loca­tion of pol­icy servers on our global net­work?
Answer: We will have a scal­a­bil­ity doc­u­ment for dis­tro

Ques­tion: Does the cur­rent license also include the sig­na­ture sub­scrip­tion for IDS?
Answer: Yes

Ques­tion: Has the port range for com­mu­ni­ca­tion between SErvers and Clients decreased? Or will it still range from 1024–4999?
Answer: It will be SSL

Ques­tion: Will this pre­sen­ta­tion be avail­able for down­load so we can share with upper man­age­ment?
Answer: Via email

Ques­tion: Does the client upgrade require a reboot from ver­sion 10.x
Answer: to start the fire­wall but not for AV pro­tec­tion

Ques­tion: We cur­rently install the SAVCE client on Win­dows Server OS man­aged by a Par­ent server. Which prod­uct is rec­om­mended for Win­dows Server OS or which com­po­nents are recommeded to be dis­abled on Server OS?
Answer: SEP can be run on servers and clients. All tech­nolo­gies are portable

Ques­tion: is the man­age­ment con­sole still MMC based?
Answer: No

Ques­tion: Is there a report­ing server for this sim­i­lar to the SAV 10 report­ing server?
Answer: No, it is inte­grated now.

Ques­tion: When will train­ing be avail­able for SEP 11?
Answer: At release

Ques­tion: will we be able to cus­tomize the white list
Answer: Yes

Ques­tion: Does Behav­ior block­ing han­dle rogue key­log­gers?
Answer: Yes

Ques­tion: Will the new con­sole be able to com­mu­ni­cate with “legacy’ SSEP agents (or, can we upgrade the SSEP-PM with­out requir­ing the SSEP agents to upgrade at the same time)?
Answer: It will sup­port legacy SSEP clients but not SAV.

Ques­tion: so just 443 and 80
Answer: Exactly!

Ques­tion: Can spe­cific appli­ca­tions be “black listed”?
Answer: Yes

Ques­tion: what are the func­tion­al­ity dif­fer­ences between Sym End­point Pro­tec­tion and Sym Multi-tier Pro­tec­tion?
Answer: Same tech­nolo­gies SMP includes email pro­tec­tion and MAC/linux

Ques­tion: will the clients lis­ten on a port for server ini­ti­ated com­mu­ni­ca­tion, or is the com­mu­ni­ca­tion only ini­ti­ated by the client?
Answer: no client lis­ten port. Client ini­ti­ates all com­mu­ni­ca­tion to the server

Ques­tion: Will SEP require SQL?
Answer: You can use SQL but the embed­ded (included) DB is Sybase

Ques­tion: Will mobile devices be sup­ported? If so, what devices?
Answer: Seper­ate prod­uct

Ques­tion: Will the Q&A be made avail­able after the call?
Answer: Yes

Ques­tion: any chance of get­ting a copy all the slides to review after the meet­ing?
Answer: Yes

Ques­tion: Is there an esti­mate avail­able of the resource impact on a host machines due to the proac­tive threat scan­ning?
Answer: We will have this doc­u­mented and avail­able in a whitepa­per
Ques­tion: Will SMS5 — Syman­tec Mobile Secu­rity Suite 5 inte­grate into SEP?
Answer: No.

Ques­tion: Do the antivirus capa­bil­i­ties within SEP 11 use less resources on a typ­i­cal client and server? We have many prob­lems with SAV 10 chew­ing up too much mem­ory and CPU uti­liza­tion, espe­cially on vir­tual servers.
Answer: Yes, lower mem­ory foot­print

Ques­tion: Is there an over­ride for the USB block­ing?
Answer: Yes

Ques­tion: Can devices be blocked based on Man­u­fac­turer / Model?
Answer: No– win­dows class ID, not ven­dor class ID.….coming in the future though

Ques­tion: can usb thumb dri­ves be blocked but other usb devices, ie scan­ner, printer be allowed?
Answer: Absolutely!

Ques­tion: is patch/maintenance release man­age­ment going to be sim­pli­fied over pre­vi­ous ver­sions? (i.e. all inclu­sive rollups not requir­ing pre­vi­ous upgrades to a base ver­sion)?
Answer: Def­i­nitely

Ques­tion: so SMP includes the sygate fire­wall tech­nol­ogy?
Answer: Yes!

Ques­tion: A new ver­sion of pack­ager come with this — I am aware its unsup­ported but if new ver­sion does come with it will it be sup­ported? If not any idea when?
Answer: Pack­ager is gone. The pack­ag­ing mech­a­nism is the Sygate tech­nol­ogy

Ques­tion: Will the schema be avail­able for the data­base, so we can query it?
Answer: Def­i­nitely!!!

Ques­tion: Will SMSDOM (Mail Secu­rity for Domino) Still be sup­ported as well as Pre­mium Anti-Spam? How about for Exchange?
Answer: Yes

Ques­tion: Are the INTEL por­tions from pre­vi­ous NAV/SAV ver­sions been elim­i­nated alto­gether?
Answer: Yep

Ques­tion: Are the poli­cies for the client avail­able to be pushed via Group Pol­icy in AD?
Answer: Yes

Ques­tion: can you restrict file types allowed to write to USB dri­ves? i.e. allow MP3, but not DOC or XLS?
Answer: Yes.
Ques­tion: Can the Class ID block­ing be man­aged by OUs, say the Direc­tor level can use usb dri­ves, reg­u­lar sales can­not?
Answer: Yes, using group­ing

Ques­tion: Can indi­vid­ual com­po­nents — say, the fire­wall por­tion — be dis­abled selec­tively? For exam­ple, we may want AV on a server but not nec­es­sar­ily fire­wall (even more specif­i­cally, for per­for­mance sav­ings?).
Answer: YES!

Ques­tion: What ver­sion of java?
Answer: Local ver­sion

Ques­tion: how much space is required for the sql ie per machine?
Answer: DB size will vary by client count

Ques­tion: Does this ver­sion get away from stor­ing client infor­ma­tion in the reg­istry?
Answer: Yep

Ques­tion: Can the man­age­ment server be installed on VM?
Answer: Yep!

Ques­tion: Did he say the client port is 80?
Answer: Or 443 depend­ing on selec­tion by admin­is­tra­tor

Ques­tion: is a cer­tifi­cate server required?
Answer: no

Ques­tion: In the cur­rent ver­sion of SAV10 Report­ing, there is a vul­ner­a­bil­ity of the PHP com­po­nent. Will SEPv11 pro­vide bet­ter response to lay­ered com­po­nents that have known vul­ner­a­bil­i­ties?
Answer: Absolutely!

Ques­tion: the client/server traf­fic is based on port 80/443 cor­rect? How is that going to affect clients run­ning web­sites using port 80/443?
Answer: There should not be a con­flict but the ports are con­fig­urable

Ques­tion: from the reme­di­a­tion aspect, will SAFE mode be required for a 100% detec­tion and clean­ing?
Answer: Depends on the threat. SEP 11 will clean bet­ter than SAV 10 though

Ques­tion: For repli­ca­tion what type of nband­width does it use over a WAN?
Answer: All doc­u­mented in the scal­a­bil­ity doc

Ques­tion: Since the client infor­ma­tion is no longer in the reg­istry how can we check AV sta­tus through scripts? Is there a WMI inter­face?
Answer: Some sta­tus can still be checked via the reg­istry
Ques­tion: Since this is run­ning on 80 or 443 is it using some type of web server under­neath for com­mu­ni­ca­tion (e.g. Tomcat/Apache/etc.)?
Answer: on the man­ager yes. There is a tom­cat server and IIS

Ques­tion: We have encoun­tered issues with the vol­ume of net­work traf­fic gen­er­ated by cor­rupted defs. How does the 11.x ver­sion address this issue?
Answer: cor­rupt defs should be a thing of the past.

Ques­tion: are there any JRE ver­sions that are not sup­ported or are rec­om­mended for the man­age­ment con­sole? Will the client itself require JRE to be installed for SEP to work?
Answer: CLient does not require JRE. The ver­sion installed is a local ver­sion spe­cific to SEPM.

Ques­tion: will reg­istry still use intel\landesk\virusprotect6 struc­ture?
Answer: Nope. All intel tech­nolo­gies for man­age­ment are gone and the reg­istry has been changed as far as struc­ture

Ques­tion: How can we obtain the scal­a­bil­ity doc­u­ment?
Answer: It will be posted at release

Ques­tion: has sepm been cer­ti­fied for vm
Answer: We sup­port VM envi­ron­ments. Not sure if it is cer­ti­fied by VM

Ques­tion: Why is this not back­wards capa­ble with SAV 10 or 9? Upgrad­ing an entire enter­prise can take a while.
Answer: Com­pletely dif­fer­ent man­age­ment archi­tec­ture.

Ques­tion: is there a method for users to alter admin­is­tra­tive scan sched­ule (but not any other option)?
Answer: Yes

Ques­tion: what about Sygate 4.1?
Answer: no

Ques­tion: Will you be able to save all the old data from the SAV 10.1?
Answer: yes, migra­tion wiz­ard will cover this

Ques­tion: no over intall for 7.x is that cor­rect
Answer: right

Ques­tion: OVerin­stall of 10.2 for Vista sup­ported?
Answer: yes

Ques­tion: he said that scal­a­bil­ity doc will be avail­able about a month after SEP 11.0 release
Answer: prob­a­bly sooner
Ques­tion: when you overin­stall does this require a reboot on the end­point
Answer: Yes, but not for AV, just for the FW

Ques­tion: Will the overin­stall work even if the pre­vi­ous client is pass­word pro­tected? Or will it still require a reg­istry hack to remove?
Answer: It will work

Ques­tion: can SAV10 client groups be migrated, or is there gran­u­lar­ity to sup­port that type of group?
Answer: Migra­tion wiz­ard will allow this

Ques­tion: Does SEP sup­port NT4.0 clients?
Answer: no
Ques­tion: does it work on vm . Cur­rently ver­sion 10 I have on vm
Answer: Yes

Ques­tion: Is the upgrade to SAV 11 more reli­able than the upgrade to SAV 10? We were forced to use NONAV to pre-clean the SAV 8 and SAV 9 sys­tems before going to SAV 10
Answer: Yes.

Ques­tion: What is the SEPM blog URL?
Answer: https://forums.symantec.com/syment?category.id=endpoint

Ques­tion: Is the installer fol­low stan­dard MSI best prac­tices?
Answer: Yes

Ques­tion: will man­age­ment server install require reboot (win­dows server 2003)?
Answer: no

Ques­tion: This includes cen­tral man­age­ment and report­ing for the FW?
Answer: Yes

Ques­tion: Any prob­lems cre­at­ing an SMS pack­age for installing to clients?
Answer: no

Ques­tion: to install over 4.1 do you need to unin­stall 4.1, reboot and install SEP or can you unin­stall 4.1, install SEP and reboot?
Answer: Yes

Ques­tion: Can our TAM answer ques­tions regard­ing SEP 11 yet? Or do we have to wait until the release?
Answer: Yes

Ques­tion: We run Syman­tec Mail Secu­rity for Exchange. If we run SEPv11 on the same box, are the defs com­pat­i­ble? Can they co-exist?
Answer: They can co-exist

Ques­tion: you men­tioned ear­lier that the client ini­ti­ates all con­tact with the server. What about Virus sweeps, updates that you want to push, do you have to wait til the next time the client checks in
Answer: No

Ques­tion: does the patch require a reboot? We have lots a 24x7 servers.
Answer: no

Ques­tion: Will the dif patch require reboots on the clients?
Answer: no

Ques­tion: No prob­lem to run in a mixed envi­ron­ment, e.g. legacy clients report­ing to pre­vi­ous man­age­ment con­sole, newer clients report­ing to newer man­age­ment con­sole?
Answer: no prob­lem with a par­al­lel environment

Ques­tion: We are going to have a lot of lan­guage require­ments (Thai, Ger­man, French, Russ­ian, Swedish, Japan­nesse, Chi­nesse). Is there a link on your web page to the sup­ported lan­guage ver­sions?
Answer: It will be posted but is not right now. Should be at release time. We are local­iz­ing alot of languages

Ques­tion: For def­i­n­i­tion dis­tri­b­u­tion, what is the approx size of the diff-defs? If a client has been off the net­work for a week or longer, what is the approx size of the diff-def?
Answer: will vary

Ques­tion: Thanks for the GUP!!
Answer: :)

Ques­tion: If a client goes to a GUP and then that client goes to another group will it still look for the GUP group A
Answer: no

Ques­tion: With ver9 and > Syman­tec expanded the fea­ture set to com­bat spy­ware and mal­ware, many cus­tomers com­plained of CE being bloated, memory-intensive, and caus­ing issues with many line-of-business appli­ca­tions. With all these added fea­tures in this new prod­uct release can you point to any doc­u­men­ta­tion related to this ver­sion bench­marks and/or per­for­mance specs com­pared to pre­vi­ous releases?
Answer: Its all doc­u­mented. Check the por­tal

Ques­tion: will rapid release def­i­n­i­tions be avail­able for the Live­up­date server?
Answer: yes with LUA 2.5

Ques­tion: Not sure if this was asked. But when a client con­nects to a 11.0 server does it use a cer­tifi­cate like in the past for com­mu­ni­ca­tions?
Answer: no

Ques­tion: Can the gups be con­fig­ured as Pri­mary, sec­ondary, and can the clients rec­og­nize that
Answer: no

Ques­tion: when will this be avail­able for down­load from the plat­inum site?
Answer: end of the month

Ques­tion: Thank You
Answer: You are welcome

  • With what seperate console and server structure will Mac be managed with?
    Im not sure i understand.
  • Joy
    Question: Is there an override for the USB blocking?
    Answer: Yes

    Please tell How???????????
  • flypig
    Interesting. I am looking at a monster SEP11 implementation. Looking for all the info I can.
blog comments powered by Disqus