Symantec EDR exclusion recommendations for Symantec VIP servers
search cancel

Symantec EDR exclusion recommendations for Symantec VIP servers

book

Article ID: 441190

calendar_today

Updated On:

Products

VIP Service

Issue/Introduction

Are there any recommendations from Symantec VIP regarding specific files, folders, and processes that should be excluded from EDR scanning to prevent any performance impact?

Environment

Symantec VIP Service

Resolution

To ensure optimal performance and avoid any service disruption with the Symantec VIP Enterprise Gateway, we recommend configuring the following exclusions in EDR solution.

To implement this, please follow the steps below:

Folder Exclusions:
Exclude the main installation directory along with all its subdirectories. By default:
C:\Program Files\Symantec\VIP_Enterprise_Gateway\

Temporary Directories:
Ensure that the following directories are excluded from real-time scanning:

  • ...\VIP_Enterprise_Gateway\logs
  • ...\VIP_Enterprise_Gateway\server\work

Application Exceptions:
Add exceptions for the following executables and processes:

  • Validation Server executable:
    ...\Symantec\VIP_Enterprise_Gateway\Validation\bin\VSValidationServer.exe
  • Java executables within the VIP installation path (e.g.,):
    ...\Symantec\VIP_Enterprise_Gateway\jvm\bin\java.exe
  • Symantec Self Service Portal Service:
    ...\Symantec\VIP_Enterprise_Gateway\server\bin\wrapper.exe
  • Health Check Service:
    ...\Symantec\VIP_Enterprise_Gateway\tools\healthcheckservice.exe
  • LDAP Sync process directory:
    ...\Symantec\VIP_Enterprise_Gateway\LdapSync\bin

After applying these exclusions, monitor the EDR logs to ensure no components are being blocked or quarantined during or after installation.