Skip to main content

Overview

The Symantec Endpoint Protection integration enables ThreatAware to collect data from Symantec Endpoint Protection, providing enhanced visibility and security controls.
Connection Method: API Setup Time: 15 minutes Access Required: Administrator account

Setup instructions

Authorization/setup steps

  1. Log in to ThreatAware:
    • Access the ThreatAware dashboard and navigate to Settings → Integrations.
  2. Locate Symantec Endpoint Protection Manager (SEPM):
    • Use the search bar to find Symantec Endpoint Protection Manager.
  3. Configure Firewall Rules:
    • Set up an inbound rule to allow access only from ThreatAware’s current allowlist IPs, available in-product under Settings → Integrations → AWS Account / IP Whitelist Info
    • Forward traffic from an external port (e.g., 8446) to SEPM’s internal port for web services.
    • Use the external IP of the hosting location to forward traffic to SEPM’s internal IP.
  4. Create SEPM User Account:
    • Log in to SEPM as an administrator.
    • Navigate to Admin > Add an Administrator.
    • In the General tab:
      • Define the username, full name, and email address.
    • Under Access Rights:
      • Assign the role Limited Administrator.
      • Specify the required permissions.
  5. Input Details in ThreatAware:
    • Enter the following details in the integration form:
      • Username: SEPM account username.
      • Password: Password for the SEPM user account.
      • External IP Address: Publicly accessible IP of the SEPM server.
      • Forwarded Port: External port configured for SEPM.
  • The integration requires strict control over firewall rules to ensure secure access.
  • For detailed permissions and setup guidance, consult the Symantec Endpoint Protection Manager documentation.

Input details

  • Username: Username of the SEPM user account.
  • Password: Password for the SEPM user account.
  • External IP Address: Publicly accessible IP of the SEPM server.
  • Forwarded Port: Port forwarded to the SEPM internal port.

Verification and troubleshooting

  • Verification: Confirm that the Integration Status in ThreatAware displays as Active after completing the setup.
  • Troubleshooting:
    • Invalid Credentials: Verify the username and password for the SEPM user.
    • Firewall Configuration Issues: Ensure that firewall rules and port forwarding settings are correctly applied.