Endpoint Protection

 View Only
Expand all | Collapse all

vshield, Agent-less SEP?

  • 1.  vshield, Agent-less SEP?

    Posted Dec 07, 2012 07:45 PM

    http://www.symantec.com/connect/blogs/symantec-endpoint-protection-12-adds-vshield-integration-increases-security-effectiveness

    Why does the above blog seem to say there is agent-less vshield integration with the newest version of SEP?

     



  • 2.  RE: vshield, Agent-less SEP?

    Posted Dec 07, 2012 08:50 PM
      |   view attached

     

    This refers to the Shared Insight Cache (SIC)
     
    The Symantec Endpoint Protection Security Virtual Appliance is a Linux-based
    virtual appliance that you install on a VMware ESX/ESXi server. The Security
    Virtual Appliance integrates with VMware’s vShield Endpoint. The Shared Insight
    Cache runs in the appliance and lets Windows-based Guest Virtual Machines
    (GVMs) share scan results. Identical files are trusted and therefore skipped across
    all of the GVMs on the ESX/ESXi host. Shared Insight Cache improves full scan
    performance by reducing disk I/O and CPU usage.
     
    Check the attached admin guide starting on Chapter 29 for full details
     
     


  • 3.  RE: vshield, Agent-less SEP?

    Posted Dec 08, 2012 12:36 PM

    Yeah, I know about all that, but none of that makes it agentless, does it?



  • 4.  RE: vshield, Agent-less SEP?

    Posted Dec 08, 2012 02:47 PM

    No, you still need the agents



  • 5.  RE: vshield, Agent-less SEP?

    Posted Dec 08, 2012 03:04 PM

    OK, that's what I thought. Basically the blog post from the Director of something something.. is wrong then.

     

    From the blog:

    VMware vShield Endpoint provides Symantec anti-malware protection with an additional layer of defense in-depth, agent-less and directly from VMware cloud infrastructure. This can improve the overall security posture and compliance for a growing number of virtual machines deployed without security agents, i.e. test and development and private cloud deployments.



  • 6.  RE: vshield, Agent-less SEP?

    Posted Dec 08, 2012 03:12 PM

    Unless I'm missing something, the SIC sort of acts like the repository for all the files that are scanned and determined to be good or not. So files on the clients will be skipped if deemed good by the SIC. So I guess you could somewhat see this as agentless in some sense but you still need the client on each one so it can talk with the SIC.



  • 7.  RE: vshield, Agent-less SEP?

    Trusted Advisor
    Posted Dec 10, 2012 09:10 AM

    Hello,

    Symantec is not currently using the vShield Endpoint API for agent-less AV on virtual machines in Symantec Endpoint Protection (SEP) 12.1. vShield support is planned to be integrated into future releases of the product.

    Check this Article:

    Does Symantec Endpoint Protection 12.1 support VMWare vShield?

    http://www.symantec.com/docs/TECH175568

    Hope that helps!!



  • 8.  RE: vshield, Agent-less SEP?

    Posted Jan 11, 2013 04:27 PM

    Your post directly contradicts this article:

     

    https://www-secure.symantec.com/connect/blogs/symantec-endpoint-protection-12-adds-vshield-integration-increases-security-effectiveness

     

    Can you please clarify if symantec is using vshield integration once and for all?  I have been trying to get this answer for weeks now and its been most frustrating.



  • 9.  RE: vshield, Agent-less SEP?

    Posted Feb 05, 2013 03:34 PM

    in order to manage the guest virtual machine clients am i required to install the SEP12.1 RU2 client on the VM

    if using vmware view linked clones am i required to install the sep12 client on the base vm prior to pool deployment?

    i am able to get everything running except i can't seem to find any way to link the client GVM to the sep12 management server

    i can see all my SVAs deployed and online with zero clients...

     

    i'm running esxi 5.0 U2 and vshield 5.1 with latest tools



  • 10.  RE: vshield, Agent-less SEP?

    Posted Feb 05, 2013 04:36 PM
    Yes, to both of your questions. There is no agent-less SEP, SEP vshield integration is more or less a gimmick (or at least not how the other AV vendors implemented it).


  • 11.  RE: vshield, Agent-less SEP?

    Posted Feb 05, 2013 04:46 PM
    Yes I've had numerous discussions with our account reps and basically the statement that SEP integrates with vmware using vshield is a total joke. All the integration provides is a shared storage (on a virtual appliance) that keeps track of what files were scanned so every virtual machine doesnt scan the same files. Great, but you still need a full client on each VM which is not how true vshield integration is supposed to work. Not that we needed another reason to stop using symantec but this has been the last thing which caused us to move to another vendor.