+ All Categories
Home > Technology > SEPM Outsourcing

SEPM Outsourcing

Date post: 08-Jun-2015
Category:
Upload: asherad
View: 628 times
Download: 2 times
Share this document with a friend
Description:
Here is a presentation I recently have to the a Midwest security user group on how to manage multiple environments, or clients, with Symantec Endpoint Protection.
Popular Tags:
33
Outsourcing SEPM Tony Asher
Transcript
Page 1: SEPM Outsourcing

Outsourcing SEPM

Tony Asher

Page 2: SEPM Outsourcing

Agenda• Goal: Successfully manage endpoint security for

outsourced clients, while minimizing time and resources.

• Requirements / Challenges

• Solutions– 3 Unique ‘features’ we leveraged.

• Issues

Page 3: SEPM Outsourcing

Requirements1. Single point of:

• Management• Visibility• Alerts• Reporting• Reporting

2 Neutral from client environments2. Neutral from client environments

3 A t ti ti k t ti3. Automatic ticket generation

Page 4: SEPM Outsourcing

Challenges – 1) Independent secure network, allow client communication

Page 5: SEPM Outsourcing

Challenges – 1) Independent secure network, allow client communication

Page 6: SEPM Outsourcing

Challenges – 2) Updates to enclave without Internet connection

Page 7: SEPM Outsourcing

Challenges – 2) Updates to enclave without Internet connection

Page 8: SEPM Outsourcing

Challenges – 3) Clients ability 'go-away'

Page 9: SEPM Outsourcing

Challenges – 4) Ticket generation

Page 10: SEPM Outsourcing

Steps Towards Solutions

Page 11: SEPM Outsourcing

Solutions – 1) Replication• Choices: Site Replication vs. GUPs

– GUPs: Can’t manage independent client admins, won’t centrally collect logs, open ports.Domains vs Groups– Domains vs. Groups

Page 12: SEPM Outsourcing

Replication Process

Page 13: SEPM Outsourcing

Replication Process (cont.)

Page 14: SEPM Outsourcing

Replication Process (cont.)

Page 15: SEPM Outsourcing

Steps:Steps:1. Verify ‘Additional Site’ in SEPM

2. Edit Properties of Replication

3. Replicate Now

4. Check Log

5. Setup ‘Limited Admin’p

Page 16: SEPM Outsourcing

Edit Replication Properties

Page 17: SEPM Outsourcing

Issues:1 SEPM S V i1. SEPM = Same Version

2. Shut down replication during upgradepg

3. Remember to turn back on

4 Easily ‘Deleted’4. Easily Deleted

Page 18: SEPM Outsourcing

Solutions – 2) Live Update ServerC• Challenge:– Couldn't communicate with Internet.

• Solution: Live Update Server on Tier 3 with– Live Update Server on Tier 3 with Internet connectivity

– Pushes out to 'Distribution share' on a server within the Secureon a server within the Secure Enclave (use for 4th box!).

Page 19: SEPM Outsourcing

LUA = Def Pusher

Page 20: SEPM Outsourcing

Live Update Server

Page 21: SEPM Outsourcing

Live Update Server (cont.)

Page 22: SEPM Outsourcing

Live Update Server (cont.)

Page 23: SEPM Outsourcing

Live Update Server (cont.)

Page 24: SEPM Outsourcing

LUA Issues

1. Postgres.exe 100%

2 T bl h ti d f’ (3 42. Troubleshooting def’s (3-4 spots)

3 Patch’s more difficult3. Patch s more difficult

4. 12/31 disaster

5. No ‘delta’ benefit

Page 25: SEPM Outsourcing

Solutions – 3) Ticket Automation• Challenge:

– No ‘flip switch’ options to escalate alerts.L h d t f t h i SEM/SIM l ti– Laughed at for not having SEM/SIM solution.

• Solution: – Syslog serverSyslog server– Remedy server reads Syslog

Page 26: SEPM Outsourcing

Steps:

1. Configure ‘External Logging’

2. Point to Syslog server IP/porto t to Sys og se e /po t

3. SLOWLY turn on Log Filters

4 Request tickets be pulled4. Request tickets be pulled

5. Verified ticket generation

6. Solid Security Incident Response Process in place.

Page 27: SEPM Outsourcing

External Logging - Config

Page 28: SEPM Outsourcing

External Logging Ticket

Page 29: SEPM Outsourcing

Other Issues• Firewall Change Requests = > 80% of time

Cli t P k ti h ld ‘ t ’ SEPM• Client Packages sometimes held ‘master’ SEPM in Sylink.xml file. • Opened ticket – Due to TS installation.

• Use CD Package with custom Sylink

Page 30: SEPM Outsourcing

Sylink Issue

Page 31: SEPM Outsourcing

Sylink Issue

Page 32: SEPM Outsourcing

Resources: Exclusion Process

Page 33: SEPM Outsourcing

Resources: Exclusion Form


Recommended