• Not Answered

Virus Definition File Update

 Hi, I am looking for a simple procedure for downloading and updating virus definition files on DeltaV workstations. Any help would be appreciated.

6 Replies

  • Have you tried using a managed installation of SEP?
     
    I’ve tried many methods of automated the patch management, using scripts and command files, but the best way I’ve found is to use SEPM (Symantec Endpoint Protection Manager) and push the def files that way.  It’s not too difficult to setup.
     
    From: Mike Londt [mailto:[email protected]]
    Sent: Friday, August 29, 2014 3:37 AM
    To: [email protected]
    Subject: [EE365 DeltaV Track] Virus Definition File Update
     

     Hi, I am looking for a simple procedure for downloading and updating virus definition files on DeltaV workstations. Any help would be appreciated.

  • In reply to AdrianOffield:

    There is a kind of support issue though. Symantec Endpoint Protection is by default only supported in unmanaged mode. If you need assistance from Emerson support with regards to your managed SEP installation, you need to opt for Advanced Services, which normally costs extra.

    If you want to avoid managed mode, downloading the virus definitions from Symantec's webiste and installing them manually is your best option. It's about 300 megabytes which you would need to download maybe each month or so.

    You can check KBA AP-0400-0004 and AP-0800-0025 for more info.

  • From the KBA:
     
    Unmanaged and Managed Mode
    UNMANAGED mode means that each workstation must have its virus definition files updated manually by an administrator. On the other hand, MANAGED mode means that the Symantec virus definition files of the client workstations are automatically updated by the machine on which the management component is installed.
    MANAGED mode implementation of Symantec Endpoint Protection is tested in DeltaV v9.3.1, v10.3.1, v11.3.x and v12.3 using the Symantec Endpoint Protection Manager (SEPM) software. Customers interested in implementing Patch Management should contact Emerson’s Advanced Services for consultation. Managed mode deployment of Symantec Endpoint Protection is not part of the standard Foundation/Guardian Support. Symantec Endpoint Protection implementation in UNMANAGED mode remains as the standard supported setup and is best suited for DeltaV systems with few workstations.
     
    If you’re dealing with a large number of workstations, the simplicity and ease of SEPM far outweighs the risk of no guardian support for SEPM.
     
     
    From: István Orbán [mailto:[email protected]]
    Sent: Friday, August 29, 2014 8:12 AM
    To: [email protected]
    Subject: RE: [EE365 DeltaV Track] Virus Definition File Update
     

    There is a kind of support issue though. Symantec Endpoint Protection is by default only supported in unmanaged mode. If you need assistance from Emerson support with regards to your managed SEP installation, you need to opt for Advanced Services, which normally costs extra.

    If you want to avoid managed mode, downloading the virus definitions from Symantec's webiste and installing them manually is your best option. It's about 300 megabytes which you would need to download maybe each month or so.

    You can check KBA AP-0400-0004 and AP-0800-0025 for more info.

  • In reply to AdrianOffield:

    I would agree with Adrian on the benefits.  I setup SEPM to provide up to date definition files for around 50 PCs and 10 servers several years ago.  I didn't use automatic deployment of the application, but used SEPM to create an install package pointing back to the a server for definition file updates.  

    SEPM can be used to deploy the installation of SEP, keep the virus definition files up to date, and give a summary of the status on each PC.

    - The SEPM software allows you to create an install package for SEP with all the correct settings as noted in the Emerson documentation.  (PULL vs. PUSH, Email off, Network Threat Protection, etc.)

    - Multiple different install packages can be created.  This was useful as we used for non DeltaV PCs with different SEP settings.

    - The installation on the workstations is much simpler at this point as the correct settings have already been predefined.

    - The SEPM console manager gives a summary of installs, status of anti virus protection, status of firewall, date of virus definition signature file, etc.

    You may not be able to call the GSC for step by step instructions on setting up, but I found the technical support through Symantec very good.  I also talked with someone at our Local Business Partner office to get a few pointers before getting started.  

    Michael

  • Emerson has an Automated Patch Management solution that will provide a system for the automatic identification, download, and distribution of patches and hotfixes for Microsoft, DeltaV, and Symantec.  If you contact your LBP/FSO, they should be able to provide you with more information about the solution and the options it provides you.

  • The automated patch management service uses SEPM to distribute the antivirus defs and is a prerequisite to using APMS, therefore, I would still recommend using SEPM.
     

    Service Prerequisites

    Automated Patch Management Service prerequisites:

    n DeltaV systems set up as a domain, running v9.3 software or higher.

    n Enrollment in Guardian Support Service

    n Annual purchase of the Automated Patch Management Subscription Service.

    n A license to use Symantec Endpoint Protection Manager and clients (customer’s responsibility).

    n Support contracts from Symantec and Microsoft for WSUS and SEPM are recommended (customer’s responsibility).

    n A server class computer licensed for Microsoft Server 2003 or Server 2008, to be installed as a non-DeltaV node (Downstream Server) on the DeltaV control network.

    n An Internet accessible server class computer licensed for Microsoft Server 2003 or Server 2008 (Upstream Server) to host applications that require Internet access.

    n Customer-managed network infrastructure that allows the Downstream Server to securely access the Upstream Server.

     
     
    From: Brian Atkinson [mailto:[email protected]]
    Sent: Friday, August 29, 2014 9:30 PM
    To: [email protected]
    Subject: RE: [EE365 DeltaV Track] Virus Definition File Update
     

    Emerson has an Automated Patch Management solution that will provide a system for the automatic identification, download, and distribution of patches and hotfixes for Microsoft, DeltaV, and Symantec.  If you contact your LBP/FSO, they should be able to provide you with more information about the solution and the options it provides you.