Symantec
™
Endpoint Detection and Response 4.5 Installation Guide for the S550
appliance
Installation worksheet completed by:
Name: _______________________________________ Date: _________________________
Provided to:
EDR Administrator: _____________________________ Date: _________________________
About operating roles, operating modes, and network connections
You configure each appliance for Symantec EDR with an operating role and an operating mode. Together, these
determine how the device is connected to your network and how it functions to protect your network and to report threats.
|
Operating modes and network connections
Operating roles
You can deploy the appliance as a management platform, network scanner, or all-in-one device. You assign the operating
role when you run bootstrap on the appliance. These roles have the following functionality:
Management platform
If two or more appliances are installed, one should be deployed in the
Management platform
role.
A management platform hosts the EDR appliance console and displays incidents and endpoints at risk for
all connected scanners. The management platform presents a comprehensive view of malicious activity
on your network. The management platform also centralizes configuration, management, and reporting
functions.
The management platform does not scan network traffic.
Network scanner
If two or more appliances are installed, all devices except the management platform should be deployed
as network scanners. Each network scanner can monitor traffic on a different network and send its incident
data to the management platform. Depending on the operating mode, the network scanner may block
malicious traffic in real time.
A network scanner does not have the EDR appliance console. You configure and manage the network
scanner from the management platform. Its incident data is consolidated with the incident data from
other network scanners and reported from the management platform. When your network expands,
additional network scanners can be installed and connected to the management platform to protect the
new networks.
All-in-one
If only one appliance is installed, it should be deployed in all-in-one mode. An all-in-one device performs
the functions of both the management platform and network scanner role.
NOTE
An all-in-one device cannot function as a management platform for network scanners. Only an appliance that is
assigned the management platform role can manage a network scanner.
The roles you choose depend upon the throughput of network traffic. For small to medium-sized installations, you should
have one appliance running in the all-in-one role. For larger installations, you would install multiple appliances with one
acting in the management platform role and the remaining appliances acting as network scanners.
Running bootstrap to configure the appliance
To change the operating role of an appliance after initial installation, you must reinstall the appliance software.
Operating modes and network connections
The operating mode controls how your network traffic is processed. It also affects how the appliance is physically
connected to your network.
11
Summary of Contents for Symantec S550
Page 1: ...Symantec Endpoint Detection and Response 4 5 Installation Guide for the S550 appliance ...
Page 17: ...Symantec Endpoint Detection and Response 4 5 Installation Guide for the S550 appliance 17 ...
Page 18: ...Symantec Endpoint Detection and Response 4 5 Installation Guide for the S550 appliance 18 ...
Page 49: ......