Overview
The Symantec Endpoint Protection integration enables ThreatAware to collect data from Symantec Endpoint Protection, providing enhanced visibility and security controls.Connection Method: API
Setup Time: 15 minutes
Access Required: Administrator account
Setup instructions
Authorization/setup steps
- Log in to ThreatAware:
- Access the ThreatAware dashboard and navigate to Settings → Integrations.
- Locate Symantec Endpoint Protection Manager (SEPM):
- Use the search bar to find Symantec Endpoint Protection Manager.
- Configure Firewall Rules:
- Set up an inbound rule to allow access only from ThreatAware’s current allowlist IPs, available in-product under Settings → Integrations → AWS Account / IP Whitelist Info
- Forward traffic from an external port (e.g.,
8446) to SEPM’s internal port for web services. - Use the external IP of the hosting location to forward traffic to SEPM’s internal IP.
- Create SEPM User Account:
- Log in to SEPM as an administrator.
- Navigate to Admin > Add an Administrator.
- In the General tab:
- Define the username, full name, and email address.
- Under Access Rights:
- Assign the role Limited Administrator.
- Specify the required permissions.
- Input Details in ThreatAware:
- Enter the following details in the integration form:
- Username: SEPM account username.
- Password: Password for the SEPM user account.
- External IP Address: Publicly accessible IP of the SEPM server.
- Forwarded Port: External port configured for SEPM.
- Enter the following details in the integration form:
Important notes and links
- The integration requires strict control over firewall rules to ensure secure access.
- For detailed permissions and setup guidance, consult the Symantec Endpoint Protection Manager documentation.
Input details
- Username: Username of the SEPM user account.
- Password: Password for the SEPM user account.
- External IP Address: Publicly accessible IP of the SEPM server.
- Forwarded Port: Port forwarded to the SEPM internal port.
Verification and troubleshooting
- Verification: Confirm that the Integration Status in ThreatAware displays as Active after completing the setup.
- Troubleshooting:
- Invalid Credentials: Verify the username and password for the SEPM user.
- Firewall Configuration Issues: Ensure that firewall rules and port forwarding settings are correctly applied.