Symantec Endpoint LiveUpdate
Hi all,
I'm hoping someone here has successfully been able to set this up and can give me some pointers.
I'm running 6.0.4 on a 200E and need to allow Symantec LiveUpdate to run through the F/W.
The updates work when I allow all traffic from DMZ -> WAN, so I know the Symantec software is installed fine. However, when I block internet traffic, allow DNS lookup to pass through as LiveUpdate uses FQDNs and follow the Symantec tech article to allow it through the firewall, it fails every time.
The tech article in question can be found here: https://support.symantec.com/en_US/article.TECH102059.html
I've done some packet tracing when all traffic is allowed and it looks like LiveUpdate has multiple CNAMEs returned from the DNS. Should these CNAMEs be added to the policy as allowed or should the firewall be able to deal with them?
It's getting to the point where I'm considering setting up LiveUpdate to run once a day and to allow all traffic out to the internet for a 10 min widow while it does. However this is obviously not the preferred solution.
Thanks in advance for any help given :)
