Server Symantec and XP
Help for Schools installing Symantec on their Networks.
- Setting up a XP PC to act as a SEPM Server.
- Setting up XP PCs so that they can be managed remotely with the Symantec Endpoint Console.
| If you would like help with the installation of the MoE Symantec at your school, which includes an XP PC to manage the distribution of updates and monitoring of school PCs, call us on 06-379-6668, 021-827-660 or email us. |
In this environmnet we are using an XP PC acting at the distribution server. While this is not perfect, since only 10 PCs can get updates at a time, this is cheaper than buying a Windows 2007 Server just to act as the distribution server.
Setting up the Distribution Server
- Setup a user called antiv
- If on a Domain makes this a Domain User
- If on a Workgroup, just make them a Local User
- Set the user up as an Administrator on this PC
- Give them your default Symantec Password, what ever that is.
- REBOOT
- Install IIS
- This is how:
- REBOOT
- Run Symantecs Support Tool (available HERE)
- Fix any issues that this too highlights.
- Run this command at the CMD screen
- netsh firewall add portopening tcp 445 endpoint
- Some of the errors are bogus, like this one
-
Error 1,021.98 MB physical memory is less than the required 1G - Others like this one need attention
- Can local users authenticate as themselves?
- Open Control Panel
- Open Administrative Tools
- Open Local Security Settings
- Open Local Policies
- Open Security Options
- Open Network access: Sharing and security model for local accounts
- Change to: Classic - local users authenicate as them selves.
- Install (SEPM) Symantec Endpoint Protection Manager from the CD
- This is how:
- We use the user admin and our standard admin password.
Setting up Clients.
This tool will examine your PC for any issues. CLICK HERE
Workgroup
- You must have a user (local user) on the remote PC that has administrator rights.
- File and Print sharing must be active.
- This command achives this: netsh firewall add portopening tcp 445 endpoint
- Run the UNINSTALL-CA program from the CD
- Run Symantecs Support Tool (available HERE)
- Review errors and correct.
- Previously we have setup a one file installation package on the XP PC acting as the SEPM.
- Install SEP from this file as it has all the setting for connecting to the SEPM.
Domain
- You must have a user (from the domain) on the remote PC that has administrator rights.
- File and Print sharing must be active.
- This command achieves this: netsh firewall add portopening tcp 445 endpoint.
- Run the UNINSTALL-CA program from the CD
- Run Symantecs Support Tool (available HERE)
- Review errors and correct.
- Previously we have setup a one file installation package on the XP PC acting as the SEPM.
- Install SEP from this file as it has all the setting for connecting to the SEPM.
Converting Unmanaged Clients to be Managed.
At the Server (Plagerised from here)
- Log on to the Symantec Endpoint Protection Manager Console.
- In the Console, in the left pane, click Clients.
- In the View Clients column, select the group to which you want to assign the unmanaged client.
- Right-click the selected group, then click Export Communication Settings at the bottom of the drop-down menu.
- In Export Communication Settings, in the group name dialog box, click Browse. The default selection is My Documents.
- In the Select Export File dialog, locate the folder to which you want to export the sylink.xml file, and click OK.
- In the Export Group Registration Setting for group name dialog box, select one of the following options:
- To apply the policies from the group from which the computer is a member, click Computer Mode.
- To apply the policies from the group from which the user is a member, click User Mode.
- Click Export.
- If the file name already exists, click OK to overwrite it, or Cancel to save the file with a new file name.
At the Client
- Copy the file to the desktop of the unmanaged computer.
- Open the client interface on the unmanaged computer.
- Click on Help and Support and select Troubleshooting.
- Click Import Profile, browse to the .xml file exported from the Manager,
- and click OK.
- REBOOT
- Check that the new settings have been accepted
Close out of this Troubleshooting area and enter back in and you should see changes to status.
Open the Symantec Endpoint Protection Manager Console | Client | Clients and this Client should be there now.