smplist

Smart Protection Source List

Clients send queries to smart protection sources when scanning for security risks and determining a website’s reputation.

IPv6 Support for Smart Protection Sources

A pure IPv6 client cannot send queries directly to pure IPv4 sources, such as:

Similarly, a pure IPv4 client cannot send queries to pure IPv6 Smart Protection Servers.

A dual-stack proxy server that can convert IP addresses, such as DeleGate, is required to allow clients to connect to the sources.

Smart Protection Sources and Computer Location

The smart protection source to which the client connects depends on the client computer’s location.

For details on configuring location settings, see Computer Location.

Smart Protection Sources by Location

Location

Smart Protection Sources

External

External clients send scan and web reputation queries to Trend Micro Smart Protection Network.

Internal

Internal clients send scan and web reputation queries to Smart Protection Servers or Trend Micro Smart Protection Network.

If you have installed Smart Protection Servers, configure the smart protection source list on the OfficeScan web console. An internal client picks a server from the list if it needs to make a query. If a client is unable to connect to the first server, it picks another server on the list.

  • Assign a standalone Smart Protection Server as the primary scan source and the integrated server as a backup. This reduces the traffic directed to the computer that hosts the OfficeScan server and integrated server. The standalone server can also process more queries.

You can configure either the standard or custom list of smart protection sources. The standard list is used by all internal clients. A custom list defines an IP address range. If an internal client’s IP address is within the range, the client uses the custom list.

  1. Click the Internal Clients tab.

  2. Select Use the standard list (list will be used by all internal clients).

  3. Click the standard list link. A new screen opens.

  4. Click Add. A new screen opens.

  5. Specify the Smart Protection Server’s host name or IPv4/IPv6 address. If you specify an IPv6 address, enclose it in parentheses.

  6. Select File Reputation Services.

  7. Clients send scan queries using the HTTP or HTTPS protocol. HTTPS allows for a more secure connection while HTTP uses less bandwidth.

    1. If you want clients to use HTTP, type the server’s listening port for HTTP requests. If you want clients to use HTTPS, select SSL and type the server’s listening port for HTTPS requests.

    2. Click Test Connection to check if connection to the server can be established.

  8. Select Web Reputation Services.

  9. Clients send web reputation queries using the HTTP protocol. HTTPS is not supported.

    1. Type the server’s listening port for HTTP requests.

    2. Click Test Connection to check if connection to the server can be established.

  10. Click Save. The screen closes.

  11. Add more servers by repeating the previous steps.

  12. On top of the screen, select Order or Random.

  13. Perform miscellaneous tasks in the screen.

  14. Click Save. The screen closes.

  15. Click Notify All Clients.

  1. Click the Internal Clients tab.

  2. Select Use custom lists based on client IP addresses.

  3. (Optional) Select Use the standard list when all servers on the custom lists are unavailable.

  4. Click Add. A new screen opens.

  5. In the IP range section, specify an IPv4 or IPv6 address range, or both.

  6. In the Proxy Setting section, specify proxy settings clients will use to connect to the Smart Protection Servers.

    1. Select Use a proxy server for client and Smart Protection Server communication.

    2. Specify the proxy server name or IPv4/IPv6 address, and port number.

    3. If the proxy server requires authentication, type the user name and password and then confirm the password.

  7. In the Custom Smart Protection Server List, add the Smart Protection Servers.

    1. Specify the Smart Protection Server’s host name or IPv4/IPv6 address. If you specify an IPv6 address, enclose it in parentheses.

    2. Select File Reputation Services.

    3. Clients send scan queries using the HTTP or HTTPS protocol. HTTPS allows for a more secure connection while HTTP uses less bandwidth.

      1. If you want clients to use HTTP, type the server’s listening port for HTTP requests. If you want clients to use HTTPS, select SSL and type the server’s listening port for HTTPS requests.

      2. Click Test Connection to check if connection to the server can be established.

    4. Select Web Reputation Services.

    5. Clients send web reputation queries using the HTTP protocol. HTTPS is not supported.

      1. Type the server’s listening port for HTTP requests.

      2. Click Test Connection to check if connection to the server can be established.

    6. Click Add to the List.

    7. Add more servers by repeating the previous steps.

    8. Select Order or Random.

    9. Perform miscellaneous tasks in the screen.

  8. Click Save. The screen closes.

  9. The list you just added appears as an IP range link under the IP Range table.

  10. Repeat step 4 to step 8 to add more custom lists.

  11. Perform miscellaneous tasks in the screen.

  12. Click Notify All Clients.

See also: