Data Loss Prevention

 View Only

 Symantec DLP Enforce - adding existing Detection servers

Brian Miller's profile image
Brian Miller posted Jan 13, 2021 08:42 PM
For my customer I have installed a new Enforce console, version 15.7.  

The customer has existing Symantec DLP Detection servers, presently connected to their existing (old, but still operating) Enforce server.  The current Detection servers have version 15.1 installed.  

My question is this; can I add the existing 15.1 Detection servers to the newly installed 15.7 Enforce console?  If so, is there any downtime in incident processing (assuming I have all required policies added and enabled in the 15.7 Enforce) upon adding the 15.1 Detection servers?  

I will be upgrading the 15.1 Detection servers to version 15.7, should this be accomplished prior to adding the Detection servers to the 15.7 Enforce console?  And again, if so, what kind of downtime should be assumed in processing of incidents - during the upgrade of the Detection servers and adding them to the new Enforce console?
Alvaro Cervantes's profile image
Alvaro Cervantes
On this Question:
Q: can I add the existing 15.1 Detection servers to the newly installed 15.7 Enforce console?
A: You can. Downtime is the time it takes to install the Java installers, maybe 10 minute? depends on resources. If the servers are Endpoint servers, endpoint will continue processing and will send incidents once they get connected again; if they are other kind of servers, they will not process anything during that tie (no email, no HTTPs, etc.).
Q: I will be upgrading the 15.1 Detection servers to version 15.7, should this be accomplished prior to adding the Detection servers to the 15.7 Enforce console? 
A: You don't add servers to an upgraded Enforces server, that are already running. You add brand new detection servers to the console. You upgrade server either at the same time or after upgrading enforce server, manually. Read the upgrade guide.

Note: from your first sentence, looks like you didn't upgrade but install a new server and the old server still running, that is a bad practice not instructed by Symantec. You will have to uninstall old detection servers and install new ones, then add it to the console, basically starting from scratch. Agent will not talk any more to the new detection server most likely (different certificate).

I will suggest always have a test environment and test your changes before deploying them to production. Call consultant services if you don't have a test environment, as it will be a challenge to play with old production servers and new servers, when upgrade/install guide was not followed.

Good luck,
A.C.