Enabling Mac and Linux clients to download LiveUpdate content using the Apache web server as a reverse proxy
search cancel

Enabling Mac and Linux clients to download LiveUpdate content using the Apache web server as a reverse proxy

book

Article ID: 181483

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

For Symantec Endpoint Protection (SEP) 14.1.x and newer, you have two main options for distributing LiveUpdate (LU) content to Mac and Linux clients. (Note: Linux client support requires SEP 12.1.5 or later). This article will cover how to set up and configure the Apache Web Server as a reverse proxy (Option 2).

Option 1: Symantec LiveUpdate Administrator (LUA)

Option 2: Apache Web Server as a Reverse Proxy

  • You can configure the Apache web server (included with Symantec Endpoint Protection Manager, or SEPM) as a reverse proxy. This allows SEPM to locally download and cache new Mac and Linux LU content. This should only be used for small installations that do not have the capability to set up a LUA.

Important Limitations of the Reverse Proxy Method:

  • Unofficial Support: Installing and configuring a reverse proxy is beyond the scope of what support can assist with, this article is provided as-is to show an example of how it can be achieved
  • SEPM Upgrades: Upgrading the SEP Manager may reset or overwrite the configurations outlined in this article. After any SEPM upgrade, ensure the changes made to httpd.conf are checked and corrected.
  • Caching Only: In this setup, SEPM acts strictly as a cache. Unlike Windows definitions, it does not process Mac or Linux definitions into .dax files.
  • No GUP Support: This configuration does not enable Mac or Linux clients to receive updates through a Group Update Provider (GUP).

Resolution

Step 1: Configure the Apache web server in Symantec Endpoint Protection Manager

  1. Stop SEPM Services
    • Open Services.msc and stop the following services:
      • Symantec Endpoint Protection Manager Webserver (semwebsrv)
      • Symantec Endpoint Protection Manager (semsrv)
  2. Create the Cache Directory
    1. Navigate to the apache folder in your SEPM installation directory (referred to below as [SEPM_Install])
      • Default 64-bit path: C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager
      • Default 32-bit path: C:\Program Files\Symantec\Symantec Endpoint Protection Manager (12.1.x only)
    2. Create a folder called cache-root ([SEPM_Install]\apache\cache-root)
    3. Ensure that the account running Symantec Endpoint Protection Manager Webserver service has Full Control of this new folder.
  3. Verify Apache Modules
    1. Check [SEPM_Install]\apache\modules for the following files
      • mod_cache.so
      • mod_cache_disk.so (12.1.5 and later)
      • mod_proxy.so
      • mod_proxy_http.so
      • mod_setenvif.so
    2. If the files are not present, copy the files from the downloaded installation folder or DVD from \Tools\Apache-ReverseProxy to SEPM_Install\apache\modules. Refer to the section Security and Compatibility below for more details.
  4. Backup and Edit the Configuration File
    1. Navigate to [SEPM_Install]\apache\conf\ and make a backup copy of httpd.conf.
    2. Open the original httpd.conf in a text editor
    3. Comment out the following line by adding a # at the beginning, as shown:
      #AsyncSendFile anydirectory
    4. Uncomment the following lines by removing the #. Replace SEPM_Install with your actual installation path, using forward slashes (e.g., C:/Program Files (x86)/Symantec/Symantec Endpoint Protection Manager/):
      AsyncSendFile givendirectory
      ForceAsyncSendFile "SEPM_Install/Inetpub/content"
    5. (Optional): Enable cache logging. Find this line:
      LogFormat "%h %l %u %t \"%r\" %>s %b" common
      And replace it with:
      LogFormat "%h %l %u %t %{cache-status}e \"%r\" %>s %b" common
    6. Add the following code block to the very end of httpd.conf. Replace [SEPM_Install] in the text below with the actual path of your Symantec Endpoint Protection Manager installation. For 12.1.5 and Later: Red text indicates file names that have changed from the version of Apache included with 12.1.4. If you previously implemented this functionality for 12.1.4, you only need to update the changed file names in httpd.conf.
      # SEPM_APACHE_AS_PROXY_START Preserve this line to maintain configuration across SEPM upgrades
      LoadModule proxy_module modules/mod_proxy.so
      LoadModule proxy_http_module modules/mod_proxy_http.so
      LoadModule cache_module modules/mod_cache.so
      LoadModule cache_disk_module modules/mod_cache_disk.so
      LoadModule setenvif_module modules/mod_setenvif.so
           
      <IfModule mod_proxy.c>
        <IfModule mod_cache.c>
          <IfModule mod_cache_disk.c>
            <IfModule mod_setenvif.c>
              SetEnvIf Request_URI "/luproxy/" dolog
              SetEnvIf Request_URI "/luproxy/.*_livetri.zip" no-cache
              CustomLog "|| bin/rotatelogs.exe logs/access-%Z.log 25M" common env=dolog
            </IfModule>
            ProxyPass /luproxy/ http://liveupdate.symantecliveupdate.com/ retry=0 smax=0 ttl=60
            CacheRoot "cache-root"
            # CacheRoot is a path defined relative to [SEPM_Install]/apache/
      
            CacheEnable disk /luproxy/
            CacheDirLevels 1
            CacheDirLength 5
      
            # directives to override any caching prohibitions in LiveUpdate content headers
            # see TECH230862
            CacheStoreNoStore On
            CacheIgnoreCacheControl On
            CacheStoreExpired On
            CacheIgnoreHeaders Cache-Control Pragma
      
            #allow downloads up to 1 GB
            CacheMaxFileSize 1000000000
          </IfModule>
        </IfModule> 
      </IfModule>
      # SEPM_APACHE_AS_PROXY_END Preserve this line to maintain configuration across SEPM upgrades

       

    7. Save and close the file
    8. Return to Services.msc and start:
      • Symantec Endpoint Protection Manager Webserver (semwebsrv)
      • Symantec Endpoint Protection Manager (semsrv)

Optional: Adjustments if using an internal LiveUpdate Administrator (LUA) as source instead of public LiveUpdate

Make the following adjustments if you are using an internal LUA as the source instead. 

  1. Update the 'ProxyPass' line to point to the LUA instead. You can use either clu-prod or clu-test, depending on the preferred distribution option.   ProxyPass /luproxy/ http://<LUA IP>:7070/clu-prod/ retry=0 smax=0 ttl=60
  2. To test that the proxy server is running by downloading an LU file, click Start > Run, and then enter http://localhost:8014/luproxy/minitri.flg (masttri.zip is only hosted on public LiveUpdate servers, not LUA). 

Optional: Routing Through a Forward Proxy

By default, the reverse proxy requires a direct outbound connection to Symantec's servers. It will fail to download content if your environment restricts outbound traffic and forces it through a standard (forward) proxy. Note that the Apache reverse proxy entirely ignores any proxy settings configured in the SEPM server properties or Windows Internet Options.

To work around this, you can use the ProxyRemote directive in your Apache configuration to route this traffic through another proxy.

  • Important Limitation: This workaround will only function if the forward proxy does not require authentication.

Step 2: Testing the configuration

  1. Click Start > Run
  2. Enter the following URL: http://localhost:8014/luproxy/masttri.zip
    • If your SEPM Apache web server uses a port other than 8014, replace it with your actual port number
    • LUA users: Use minitri.flg instead of masttri.zip, as the latter is only hosted on public servers).
  3. If the download is successful, then the configuration is working.

Important Testing Note: Although you are requesting the file via a local URL, the request is actually passed through to Symantec's public LiveUpdate servers. Ensure your SEPM server has the appropriate network access to successfully reach the LiveUpdate web domains (refer to article 151267.)

Step 3: Update LiveUpdate policy for Mac and Linux clients to point to new LiveUpdate server

Take the following steps to update your LiveUpdate policy for Mac and Linux clients for your desired groups. Once the policy is updated, these clients will point to the newly configured Apache web server for downloading LU content.

  1. Within Symantec Endpoint Protection Manager, click Policies > LiveUpdate. On the LiveUpdate Settings tab, double-click the LiveUpdate Settings policy that applies to your desired groups.
  2. Click Use a specified internal LiveUpdate Server under Mac Settings > Server Settings (or Linux Settings > Server Settings) and specify the name "SEPM HTTP LU Proxy," with the corresponding URL: "http://ServerIP:8014/luproxy" or "http://ServerName:8014/luproxy"
    Where ServerIP or ServerName represents the IP number or name of the server that hosts Symantec Endpoint Protection Manager. If the Symantec Endpoint Protection Manager Apache web server uses a different port that 8014, replace 8014 with your actual port number in the above URL.
  3. Enable download randomization under Mac Settings > Schedule (or Linux Settings > Schedule). If the option is not greyed out, check Randomize the start time. This prevents the Apache web server from getting overloaded at certain times in a day.

Additionally, on SEP 12.1.x clients for Linux, edit the liveupdate.conf file and set serverlogging=false. SEP For Linux 14.0 does not require this setting. See article 162031.

Additional Information

Managing cache file size

To manage the size of your cache file, take the following steps.

  1. Verify if the htcacheclean.exe file is present in the following folder:
    SEPM_Install\apache\bin
  2. If the file is not present in the mentioned location, copy htcacheclean.exe from the \Tools\Apache-ReverseProxy folder on your DVD to SEPM_Install\apache\bin
  3. Enter the following command while logged in with an account that has full access rights on the cache-root folder:
    htcacheclean -n -t -d1440 -l1024M -p"SEPM_Install/apache/cache-root"

This will run the htcacheclean tool in daemon mode. The cache cleaning will be done on a daily interval. The maximum cache size allowed on disk is 1 GB.

To automatically start the htcacheclean daemon every time Windows starts, take the following steps.

  1. Hold down the Windows key on your keyboard and press the letter R to open the Run dialog. Type taskschd.msc, and then click OK.
  2. In the Task Scheduler, in the right pane, click Create Basic Task.
  3. Name the new task with a description such as Manage Apache Cache Size, and then click Next.
  4. To set the task to run every time Windows starts, in the Task Trigger pane, click When the computer starts, and then click Next.
  5. In the Action dialog box, click Start a program, and then click Next.
  6. Enter the full path to htcacheclean into Program/script:
    SEPM_Install\apache\bin\htcacheclean.exe
  7. Enter the following arguments into Add arguments (optional), and then click Next.
    -n -t -d1440 -l1024M -p"SEPM_Install/apache/cache-root"
  8. To complete adding the scheduled task, click Finish.
  9. In the Windows Task Scheduler library, right-click the task you created, and then click Properties.
  10. In the Settings tab, click to deselect Stop the task if it runs longer than, and then click OK.

Since the task does not run until you restart the system, you can run it now. In the Task Scheduler, right-click the task you created, and then click Run.

Note: Ensure that the user account running the task has full control on the folder SEPM_Install\apache\cache-root.

Performance and scale

This configuration is designed for small numbers of Mac and/or Linux clients. You should only use this setup if there are only a few Mac and/or Linux clients and the network connecting clients and Symantec Endpoint Protection Manager has good bandwidth throughput. Assuming that each client downloads roughly 500KB of LU content on daily basis, 2000 Mac or Linux clients will result in a download of approximately 1 GB of LU content daily from the Apache web server. For configurations having large numbers of clients, you should consider an alternative like Symantec LiveUpdate Administrator.

Logging

The LU download requests to the Apache web server are logged in a separate log file, located in SEPM_Install\apache\logs\access-%Z.log.

Security and compatibility

Symantec suggests the use of only Symantec-signed binaries for Apache modules that are mentioned in this article. These signed binaries are available on the Symantec Endpoint Protection downloaded installation file. Note that the required binaries also get installed along with Symantec Endpoint Protection Manager for versions 12.1.4 and later.

For Symantec Endpoint Protection 14:

  • The downloaded full installation file, \Tools\Apache-ReverseProxy

Because new vulnerabilities may be published after the publication of this article, please check the vulnerabilities published by the Apache project for the appropriate version of Apache web server: http://httpd.apache.org/security/

Caching Failures