What methods are available to update virus definitions for Symantec Mail Security for Microsoft Exchange?
1. LiveUpdate for Certified definitions.
To schedule LiveUpdate to retrieve Certified virus definitions:
a. Open the SMSMSE console, and navigate to Admin -> LiveUpdate/Rapid Release schedule.
b. Ensure Enable automatic virus definition updates is checked and Use Certified LiveUpdate definitions is selected.
c. Under Schedule, set the schedule on which you would like LiveUpdate to run. Be aware only one set of certified definitions is available per day, so it is recommended to schedule only one update per day.
2. Rapid Release updates.
To configure Rapid Release updates:
a. Open SMSMSE console and navigate to Admin -> LiveUpdate/Rapid Release Schedule.
b. Check the box for Enable Automatic virus definition updates, and check the radio box for Use Rapid Release definitions
c. Under Schedule, set the schedule on which you would like Rapid Release to run. Multiple updates are available per day (appromately one release per hour), so you may want to set it to check every X hours. Rapid Release uses port 21 to download definitions, bypassing the need for port 80 access. Be aware that Rapid Release definitions are not tested as thoroughly as certified definition sets, but are updated more frequently.
3. Schedule the Intelligent Updater using the steps provided in How to update definitions for Symantec Mail Security for Microsoft Exchange using the Intelligent Updater.
4. Use an internal LiveUpdate Server.
Configure an Internal LiveUpdate server (LiveUpdate Administrator 2.x). Symantec Mail Security can be set to retrieve certified definition sets from an internal LUA 2.x server via LiveUpdate. To configure an internal LiveUpdate server and point SMSMSE to retrieve updates from that server, follow the steps provided in this document: Distributing Virus definitions for Symantec Mail Security for Microsoft Exchange via LiveUpdate Administrator.
Each of these methods can have advantages or disadvantages relative to one another, depending on the environment. Here are some factors to consider when deciding which method is correct for your environment:
Technical Information
This section provides information on where SMSMSE stores virus definitions on various operating system versions:
Hawking Structure | These are the virus definitions that are updated by LiveUpdate, as well as what is used by SAV/SEP for virus scanning. Any update method you choose will always update the Hawking structure first. Whenever this location is updated, an event ID 30 is observed in the event log from source "Symantec Mail Security for Microsoft Exchange" indicating that "Virus Definitions Update was successful" |
Windows 2003 32-bit | C:\Program Files\Common Files\Symantec Shared\VirusDefs |
Windows 2003 64-bit | C:\Program Files(x86)\Common Files\Symantec Shared\VirusDefs |
NOTE: Windows 2003 64-bit | If SAV/SEP is not installed on the system, this location does not exist with SMSMSE 6.0.9 and greater. See SMSMSE hawking structure below. |
Windows 2008 | C:\ProgramData\Symantec\Definitions\VirusDefs |
NOTE: Windows 2008 | If SAV/SEP is not installed on the system, this location does not exist with SMSMSE 6.0.9 and greater. See SMSMSE hawking structure below. |
SMSMSE Hawking Structure | On 64 bit systems, SMSMSE generates its own Hawking structure. LiveUpdate and other definition update methods update this directory. |
Whenever this location is updated, an event ID 30 is observed in the application event log from source "Symantec Mail Security for Microsoft Exchange" indicating that "Virus Definitions Update was successful" | |
SMSMSE 6.5.7 and later: | |
These are the definitions used by SMSMSE directly for virus scanning. SMSMSE will write an event ID 25 to the application event log indicating "Updated virus definitions". At this point SMSMSE will be using the latest virus definitions for scanning. | |
SMSMSE 6.5.6 and earlier: | |
This acts as a file repository, and is not used directly for virus scanning by any process. | |
Windows 2003 32-bit | N/A |
Windows 2003 64-bit | C:\Program Files(x86)\Common Files\Symantec Shared\SymcData\virusdefs32 |
Windows 2008 | C:\ProgramData\Symantec\Definitions\SymcData\virusdefs32 |
CSAPI | SMSMSE 6.5.7 and later: |
This directory below is no longer updated, but SMSMSE still relies on the files being in this directory. | |
SMSMSE 6.5.6 and earlier: | |
These are the definitions used by SMSMSE directly for virus scanning. After virus definitions are processed into the Hawking structure by your chosen virus definition update method, SMSMSE checks the Hawking structure every 10 minutes for updates, and when a new update is available, copies the definitions into CSAPI. After the definitions are copied to CSAPI, SMSMSE will write an event ID 25 to the application event log indicating "Updated virus definitions". At this point SMSMSE will be using the latest virus definitions for scanning. | |
Windows 2003 32-bit | C:\Program Files\Common Files\Symantec Shared\definitions\AntiVirus\VirusDefs |
Windows 2003 64-bit | C:\Program Files(x86)\Common Files\Symantec Shared\definitions\AntiVirus\VirusDefs |
Windows 2008 | C:\Program Files(x86)\Common Files\Symantec Shared\definitions\AntiVirus |