Sangfor Endpoint Secure Offline Update

Newbie668999 Lv1Posted Mar-16-2026 19:18

We are currently operating Sangfor Endpoint Secure in a secured environment where the servers do not have Internet access.

We would like to inquire whether there is an official procedure to download and install updates (including antivirus signatures, vulnerability databases, and system/service updates) in an offline environment.

Note: We are currently using SASE based enviorenment.

Since manual/offline imports are not supported for this deployment, we are exploring the possibility of whitelisting the necessary traffic on our firewall to allow the ES Manager to reach Sangfor’s update servers.

Could you please provide a comprehensive list of the FQDNs (URLs) and Ports that must be opened to allow the system to successfully download:
•        Vulnerability database updates
•        Signature database updates
•        System/Engine patches

Please also specify if these require specific protocols (e.g., HTTPS on 443) or if there are specific IP ranges we should be aware of.


Brando has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Yes, there is an official procedure for updating Sangfor Endpoint Secure in an offline environment:

For antivirus signatures and vulnerability databases:

You can manually download the offline antivirus database and vulnerability database update packages from the official Sangfor community download links.
For example, for versions from Endpoint Secure 3.2.8 up to 6.0.2R4, the antivirus database offline package can be downloaded from the Endpoint Secure offline antivirus database link, and the vulnerability database offline package can be downloaded from the Endpoint Secure offline vulnerability database link.
After downloading, you can load the antivirus database update package in [System]-[System Updates]-[Signature Database Update], and the vulnerability database update package in [System]-[System Updates]-[Vulnerability Database].
The behavioral feature database can also be updated offline by using the offline virus database package in the same way.
For patch updates:

Use the vulnerability patch offline download tool available in [System]-[System]-[Tools] to download vulnerability patch packages.
After offline downloading, import the patch packages into the internal patch server or the Endpoint Secure Manager platform.
Then, configure the endpoints/servers to download patches from the internal patch server or the Manager by placing the internal patch server or control center IP at the top in the patch download settings.
The patch packages can be loaded in [System]-[System Updates]-[Vulnerability Database] to complete the upgrade.
Note that the Endpoint Secure platform itself does not come with vulnerability patch packages; you need to use the offline download tool to obtain them.
Also, patches not included in the official offline download tool are not supported for import.
For system/service updates:

You can download the Endpoint Secure installation package, software upgrade package, and patch package from the official Sangfor community download site.
Agent updates:

The Endpoint Secure agent supports automatic online updates when connected to the internet.
However, manual offline import of antivirus databases by the agent is not supported.
This procedure ensures that even in a secured environment without internet access, you can keep your Endpoint Secure platform and endpoints updated by manually downloading and importing the necessary update packages
Is this answer helpful?
Newbie517762 Lv5Posted Mar-18-2026 11:27
  
HiHi,

Endpoint Secure has network connectivity requirements. Please find the attached information from the Sangfor Endpoint Secure Deployment and Installation Guide V6.0.4.
Network Connectivity Req.pdf (328.39 KB, Downloads: 101)

Installation Package Download Link:
Brando Lv5Posted Mar-19-2026 00:53
  
Yes, there is an official procedure for updating Sangfor Endpoint Secure in an offline environment:

For antivirus signatures and vulnerability databases:

You can manually download the offline antivirus database and vulnerability database update packages from the official Sangfor community download links.
For example, for versions from Endpoint Secure 3.2.8 up to 6.0.2R4, the antivirus database offline package can be downloaded from the Endpoint Secure offline antivirus database link, and the vulnerability database offline package can be downloaded from the Endpoint Secure offline vulnerability database link.
After downloading, you can load the antivirus database update package in [System]-[System Updates]-[Signature Database Update], and the vulnerability database update package in [System]-[System Updates]-[Vulnerability Database].
The behavioral feature database can also be updated offline by using the offline virus database package in the same way.
For patch updates:

Use the vulnerability patch offline download tool available in [System]-[System]-[Tools] to download vulnerability patch packages.
After offline downloading, import the patch packages into the internal patch server or the Endpoint Secure Manager platform.
Then, configure the endpoints/servers to download patches from the internal patch server or the Manager by placing the internal patch server or control center IP at the top in the patch download settings.
The patch packages can be loaded in [System]-[System Updates]-[Vulnerability Database] to complete the upgrade.
Note that the Endpoint Secure platform itself does not come with vulnerability patch packages; you need to use the offline download tool to obtain them.
Also, patches not included in the official offline download tool are not supported for import.
For system/service updates:

You can download the Endpoint Secure installation package, software upgrade package, and patch package from the official Sangfor community download site.
Agent updates:

The Endpoint Secure agent supports automatic online updates when connected to the internet.
However, manual offline import of antivirus databases by the agent is not supported.
This procedure ensures that even in a secured environment without internet access, you can keep your Endpoint Secure platform and endpoints updated by manually downloading and importing the necessary update packages
Brando Lv5Posted Mar-19-2026 00:55
  
Update Server Addresses and Ports:

For Endpoint Secure standard versions 3.2.9 and later, the Manager updates the vulnerability patch database, signature database, and virus database from the domain: http://download.sangfor.com.cn
The ports to allow are 53 (DNS), 80 (HTTP), and 443 (HTTPS).
There is currently no specific fixed IP address; it is recommended to allow the domain name to resolve and communicate.
Protocols:

HTTP (port 80) and HTTPS (port 443) are used for downloading updates.
DNS (port 53) is required for domain name resolution.
Agent Update Ports:

The Endpoint Secure agent updates the antivirus database from the Manager mainly using ports 443 and 8083.
Notes:

The Endpoint Secure interface does not currently support testing server communication.
If you need assistance testing server communication, you can contact tech.support@sangfor.com.
In summary, to enable the Endpoint Secure Manager to download vulnerability database updates, signature database updates, and system/engine patches, you should whitelist the domain http://download.sangfor.com.cn and allow outbound traffic on ports 53, 80, and 443. For agent updates from the Manager, allow ports 443 and 8083. Since there are no fixed IP addresses, domain-based whitelisting is recommended.
Brando Lv5Posted Mar-19-2026 00:59
  
Answer as above.

I Can Help:

Change

Moderator on This Board

2
1
0

Started Topics

Followers

Follow

1
1
0

Started Topics

Followers

Follow

941
192
97

Started Topics

Followers

Follow

Trending Topics

Board Leaders