Endpoint Protection

 View Only
  • 1.  Central Quarantine server in SEP 14 environment

    Posted Apr 03, 2020 08:17 AM
      |   view attached
    According to the articles below Central Quarantine server is no more available with the SEP 14 installation but as per the screenshot, it can be installed from an old SEP 12 install source.
    So is there someone who is using this in SEP 14 environment and is everything working fine? I am wondering why this is not available in SEP 14 anymore as it is good to have these quarantined files forwarded to a central server especially when you don't have remote access to the workstations.

    https://knowledge.broadcom.com/external/article?legacyId=tech95663
    https://knowledge.broadcom.com/external/article?legacyId=tech255506




  • 2.  RE: Central Quarantine server in SEP 14 environment

    Posted Apr 06, 2020 08:55 AM
    Anyone from Symantec to provide some info here?


  • 3.  RE: Central Quarantine server in SEP 14 environment

    Broadcom Employee
    Posted Apr 06, 2020 10:29 AM
    Hi Stefan,

    QS is no longer supported and should not be used. Please look into Advanced Threat Protection as an alternative.

    ------------------------------
    John Owens
    Principal Product Support
    Symantec
    United States
    ------------------------------



  • 4.  RE: Central Quarantine server in SEP 14 environment

    Posted Apr 06, 2020 10:49 AM
    Hi John,

    Is there any compatibility issue between the Quarantine server and SEP 14? For example if I get it and install it, is it going to work?
    The main issue is that I need all quarantined risks to be sent to a centralized server because I don't have remote access to the client machines and it is a bit difficult to get and submit files for false positive.


  • 5.  RE: Central Quarantine server in SEP 14 environment
    Best Answer

    Broadcom Employee
    Posted Apr 06, 2020 10:58 AM
    We are removing all configurable settings from the Sepm in next release. You can get similar functionality with ATP. I would not suggest you try to install quarantine server.

    ------------------------------
    John Owens
    Principal Product Support
    Symantec
    United States
    ------------------------------



  • 6.  RE: Central Quarantine server in SEP 14 environment

    Broadcom Employee
    Posted Apr 07, 2020 02:22 PM
    Hi Stefan,

    Yes, there is a major compatibility issue: Quarantine Server cannot receive files convicted by reputation, only classic AV signature convictions. So you will have limited results and probably not meet your objective, because false positives are a bit more likely to occur with reputation convictions than with signatures.

    I would recommend looking into other methods.

    It can be time consuming dealing with false positives, especially those due to highly customized or internally developed applications. There are numerous ways to assign exceptions within SEP policies, depending on which SEP technology is reacting to the business-critical application incorrectly. Many exceptions can be added to one or more Exceptions policies directly from the Risk or SONAR logs. Also, you don't always have to submit a file; you can submit a filehash to the false positive submission portal, and the hash is usually provided in the SEP log. Much easier to collect!

    Hope this is helpful.