Endpoint Protection

 View Only
  • 1.  Ports for SEPM to communicate with Another SEPM

    Posted Sep 27, 2011 07:42 PM

    Hi

     

    I have one SPEM installed in my network. We have a DMZ network with SEP client. As they cannot talk SPEM with is out of DMZ. We are looking to install a SPEM inside DMZ and join other SEPM as a site so that we can manage polcies and reporting from one point. I am looking for ports which needs to be open between these two SPEM to establish communcation..

     

     

    Any help would be appreciatable.

     

     

    Regards
    Sam



  • 2.  RE: Ports for SEPM to communicate with Another SEPM

    Posted Sep 27, 2011 08:22 PM

    If there are only a few clients on the DMZ, you may want to instead create a static route between the client and the SEPM server. You only need to keep the 8014 open for communication for the logs and definitions. And if you're planning on deploying the client remotely, use port 443. Although if there are few clients, you'd probably just manually update them. If you still plan on adding another SEPM in the DMZ, add port 8443 and 9090.

    Article URL http://www.symantec.com/docs/TECH102416



  • 3.  RE: Ports for SEPM to communicate with Another SEPM

    Trusted Advisor
    Posted Sep 28, 2011 09:33 AM

    Hello,

    You can open port 8014 (if you installed it with default settings) for general communication. It's found on page 50 of the Installation guide. Also, you need to open port 8443 for replication

    p.s Here is the guide to port numbers: http://www.symantec.com/docs/TECH102416

    Also, check this: Security recommendations regarding SEP client installed on server located in DMZ

    http://www.symantec.com/docs/TECH122858

     
    What I am unable to understand is, since this is a DMZ network, how are you planning to have the SEPM updated with Virus definitions?
     
     
    Hope this helps!!


  • 4.  RE: Ports for SEPM to communicate with Another SEPM

    Posted Sep 28, 2011 10:08 AM

    Are you looking to have SEPM as a relication partner? For this port 8443 needs to be allowed.



  • 5.  RE: Ports for SEPM to communicate with Another SEPM

    Posted Sep 28, 2011 01:16 PM

    Which communications ports does Symantec Endpoint Protection use?
    http://www.symantec.com/docs/TECH163787
     
    About firewalls and communication ports
    http://www.symantec.com/docs/HOWTO55379
     
    Security recommendations regarding SEP client installed on server located in DMZ
    http://www.symantec.com/docs/TECH122858
     



  • 6.  RE: Ports for SEPM to communicate with Another SEPM

    Posted Sep 28, 2011 01:40 PM

    It would recommend to open 8014 port for SEPM IP for the subnet range of DMZ and have clients communicate directly to SEPM.

    This is what is normally followed if you have many clients in DMZ and in same subnet.