<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>954NETWORK BLOG! &#187; Endpoint 11 Review</title>
	<atom:link href="http://blog.954network.com/tag/endpoint-11-review/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.954network.com</link>
	<description>Information Technology Solutions Blog - Presented by 954Network, Inc.</description>
	<lastBuildDate>Thu, 08 Oct 2009 14:16:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Symantec Endpoint Protection 11 Review</title>
		<link>http://blog.954network.com/2008/11/05/symantec-endpoint-protection-11-review/</link>
		<comments>http://blog.954network.com/2008/11/05/symantec-endpoint-protection-11-review/#comments</comments>
		<pubDate>Wed, 05 Nov 2008 14:36:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Endpoint 11 Review]]></category>
		<category><![CDATA[Symantec Endpoint 11]]></category>

		<guid isPermaLink="false">http://blog.954network.com/?p=32</guid>
		<description><![CDATA[Recently, I had a customer who&#8217;s anti-virus subscription was about to expire. They had been running Symantec Anti-Virus Corporate edition 10.0, which was a great solution and worked well in their organization but they needed to upgrade as is always the case when renewing licensing and going forward as new technologies and threats emerge. As [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, I had a customer who&#8217;s anti-virus subscription was about to expire. They had been running Symantec Anti-Virus Corporate edition 10.0, which was a great solution and worked well in their organization but they needed to upgrade as is always the case when renewing licensing and going forward as new technologies and threats emerge. As their consultant, I was charged with recommending which direction they should go. I read many posts (angry posts) on the Symantec Forums regarding Symantec Endpoint 11 and decided to recommend this solution as an alternative to a few others, including Sophos. After days of debating the Pros and Cons, the customer decided to go with Symantec Endpoint 11 (Much to my amazement after all of the bad comments) with the assumption that Symantec is the best. Luckily, according to some of the posts as well as Symantec&#8217;s web site and docmentation, the newer MR2 release was supposed to resolve some of the issues I had read in all of the Angry posts.</p>
<p>After purchasing and downloading Symantec&#8217;s product, I began reading all of the manuals (Like a good I.T. Guy) and eventually started deploying the product. Up until this point, I was convinced that I would be in for an overnight-er but surprisingly it was relatively easy to install. I used the SQL approach as the database engine as apposed to the built in database option as I had heard horror stories about this configuration. Servers running out of resources (Mainly Disk Space), shares being inaccessible and servers having to be re-booted daily or more.  Once I had the management console installed, I decided not to install the client on the server due to, you guessed it &#8211; more horror stories. Instead, I left Symantec Enterprise 10.0 on the server and upgraded all client machines with the built-in upgrade push available from the management console. All in all it went smooth.</p>
<p>After a few days of playing around with the management console and the client, I noticed a few major issues including a great deal of communications between the Management Console (Server) and the Endpoints (Clients) so I began to investigate. After sniffing packets and reading (and a few cups of coffee) I determined that the traffic was being caused by the server &#8220;Pushing&#8221; communications as well as the constant checks for updates. To alleviate this, I set all clients to &#8220;Pull&#8221; updates every &#8220;X&#8221; hours, I also deleted the default update policy and created a new one that dictated that the server should only check Live Update for new content every 2 hours between 6:00 P.M. and 6:00 A.M. daily. This drastically reduced the amount of network traffic.</p>
<p>So, after sorting out the network saturation issue mentioned above, I was faced with the large consumption of resources that the Management Console was putting on the server. This was a relatively easy issue to resolve. I simply limited the amount of memory that the SQL server was allowed to consume to 256 MB and wrote a small batch script that restarts the Symantec Services each day at 6:30 A.M. and 5:30 P.M. as to not interfere with the update schedule. Once I had observed this configuration for a few days, I was satisfied with the results and so far all has been operational with a relatively low impact on the server.</p>
<p>Along with the Anti-Virus, Anti-Spy-ware and network protection features included in this product, there is also the capability to disable removable storage devices such as Flash Drives. This particular client was very interested in this feature as they are in a highly sensitive industry. That being said, I created a policy for select clients that prohibits the use of removable media devices and I must say, it works well.</p>
<p>Some of the things that I have noticed to be annoying is the new interface of the client as well as the Management Console. Symantec has switched from an MMC format as seen in earlier versions of their Corporate Anti-Virus to a web/java based interface. This thing is CLUNKY. Descovery of unmanaged clients usually takes longer than the login timeout so it never completes and the reporting functionality is sub-par. I do, however like the Active Directory integration features as well as the informational dashboard.</p>
<p>This configuration was put in place about 6 months ago now and I have not seen any major bumps in the road. The system seems to work well and is doing what it is supposed to with regards to protecting the client machines against harmful applications. All in all, after discovering a happy medium and wrangling this application into working properly, it is a decent solution. It provides a cost effective way to efficiently manage endpoint antivirus and security despite it&#8217;s early (Glaring) flaws, although I do not think that I will be recommending it to any future clients given the time and effort it took to get the thing working in the first place. I hear that there is an MR3 release, which I will be deploying at a new client (They had already purchased the license before my time). Hopefully the new version will not be such a pain to get working.</p>
<p>Jason (Digitalkid)<br />
<a href="http://www.954network.com">www.954network.com</a></p>
<div><table> <td><iframe src='http://digg.com/api/diggthis.php?w=new&amp;u=http://blog.954network.com/2008/11/05/symantec-endpoint-protection-11-review/&amp;t=Symantec+Endpoint+Protection+11+Review&amp;s=compact' height='18' width='120' frameborder='0' scrolling='no'></iframe></td> <td><iframe src='http://www.reddit.com/button_content?newwindow=1&amp;url=http://blog.954network.com/2008/11/05/symantec-endpoint-protection-11-review/&amp;title=Symantec+Endpoint+Protection+11+Review&amp;t=1 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><script type="text/javascript"><!--yahooBuzzArticleHeadline=Symantec+Endpoint+Protection+11+Review;//--></script><script type="text/javascript" src="http://d.yimg.com/ds/badge2.js" badgetype=small-votes></script></td></table></div><!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	-->]]></content:encoded>
			<wfw:commentRss>http://blog.954network.com/2008/11/05/symantec-endpoint-protection-11-review/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
