Symantec
™
Endpoint Detection and Response 4.5 Installation Guide for the S550
appliance
Service
Protocol
Port
From
To
Description
Active Directory
LDAPS
636
Management
platform or all-in-
one appliance
Active Directory
server
This connection allows
Symantec EDR to integrate
with Active Directory for user
authentication.
Security Analytics link
HTTPS
TCP/UDP
443
Management
platform or all-in-
one appliance
Symantec
Security
Analytics
appliance or
virtual appliance
This connection lets Symantec
EDR integrate with Symantec
Security Analytics to provide
a link on individual log events
to navigate users to additional
information on related network
motion.
¹ Port 8443 is only available if you were using this port on previous versions of Symantec EDR and have since updated. If
you are installing Symantec EDR for the first time, this port is not available.
Where to place the appliance in your network for best results
Proxy recommendations
The following are Symantec's proxy recommendations:
Network scanning
Proxy deployment options are as follows:
•
Deploy Symantec EDR between the internal network and the proxy.
This deployment configuration is recommended.
When customers deploy Symantec EDR between the internal network and the proxy, it gives
Symantec EDR full visibility of endpoint information.
You must deploy Symantec EDR when you are load balancing proxies between the internal
network and a farm of proxies. This information ensures Symantec EDR can failover to the proxy.
In this scenario, the LAN port of the proxy is the good place to plug in Symantec EDR inline.
•
Deploy Symantec EDR between the proxy and their firewall.
When customers deploy Symantec EDR between the proxy and their firewall, customers must
enable to the X-forwarded-for feature on the proxy. The firewall must have the ability to strip out
the X-forwarded-for tag. Customers should see the documentation for their firewall for instructions
for how to remove this tag. The disadvantage of this deployment is that it requires more effort to
configure.
Management traffic from
Symantec EDR to Symantec
back-end servers
This proxy traffic does not support SSL interception. If the proxy server has SSL interception enabled,
customers must create a policy to let Symantec traffic bypass. Such a policy prevents the proxy from
inspecting Symantec traffic, thereby reducing resource demands.
Symantec EDR platform support matrix
Use the matrix below to verify that your current installation of Symantec EDR meets the system requirements to support
Symantec EDR's features.
23
Summary of Contents for Symantec S550
Page 1: ...Symantec Endpoint Detection and Response 4 5 Installation Guide for the S550 appliance ...
Page 17: ...Symantec Endpoint Detection and Response 4 5 Installation Guide for the S550 appliance 17 ...
Page 18: ...Symantec Endpoint Detection and Response 4 5 Installation Guide for the S550 appliance 18 ...
Page 49: ......