Hi,
I have tried to run GUP Monitor tool on SEPM Server (Windows 2012) and never worked, any advise.
Thanks
Hi,
I have tried to run GUP Monitor tool on SEPM Server (Windows 2012) and never worked, any advise.
Thanks
Hi.
I'll try to explain my scenario as easy as possible:
We have several clients which can't communicate with our SEPM-server because of complicated network issues.
However, these clients got network communication with some of the other clients which again got connection to our SEPM, hence I have chosen to try to setup one of these as GUP.
What I've been doing:
I've created a client group for this purpose and created a non-shared LiveUpdate Settings Policy for this group where server X is GUP.
(Server X got communication with SEPM)
I've also moved server X into this group and it seems to be accepting the role of GUP.
Problem:
These clients have never been in contact and recognized by our SEPM-server, thus is not listed in SEPM.
How do I update the policy on these servers and add them to the group in SEPM which use the GUP-client as update source?
Do I have to export an installation package for this specific group or something like that?
If so, how?
I feel like I'm banging my head against the wall, fearing I'm going about this the completly wrong way..
All help appriciated!
Hi
I've installed the 12.1 RU4 version in some Macintosh clients and I presented the problem: http://www.symantec.com/business/support/index?page=content&id=TECH212506#.
I tryied to run the LiveUpdate, as the article recomends, using the LUTool, but I get the following message:
Good Morning:
Some days ago, this problem appears in my Symantec Endpoint Protection Manager console. Next liveupdate time shows a previous date than the last liveupdate time. I tried to update manually and the .jdb file converts into .jdb.err file. I tried some solutions from this forums and i can't fix it.
Hello,
Simply put, we are currently running SEP and MalwareBytes Free version without issue, but MB Enterprise gives a console version, making deployment of scans, updates, etc. easier than going to every system individually.
My question is will SEP and MalwareBytes Enterprise run together without conflicting with eachother? MBE will be ran as an Anti-Malware, not overtaking the AV abilities of SEP.
Hi all,
I have a lot of clients that still have SEP version 12.1.1 and we are now at 12.1.3. We have deepfreeze on all our machines so it's hard to update them during the day while students are using them. Is there anyway to have symantec push out the updated client version without some one at the PC? I can push them from our symantec server but I wanted to do this at night when nobody is here. Any information will be helpful. Were also using a GUP so this would help with that too.
Thanks!!!!
Next Liveupdate Time shows a previous date than the Last Liveupdate Time. And SEPM is not updating for this reason, i Think, HEELP, please.
Attach file.
Before we upgraded our management console to SEP 12 RU4, we organized our GUP policies the following way
1. One group called GUPs has all the servers from each site --- they serve as GUPs and are defined as GUPs based on the registry key value
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink\CurrentGroup
where the value is equal the group name, i.e My Company\Servers\GUPs
2. Multiple groups for each site. Each group would have a separate LiveUpdate policy that said, "Your GUP is 10.10.10.100 server at this site". Because there are about 1,000 sites, I had to create indivial LiveUpdate policies, which took several week.
Now, I am told there is a MUCH easier way to implement GUPs and that I only need one LiveUpdate policy for the entire SEPM because of "Explicit Group Update Providers for roaming clients"
BUT here is the problem --- at each site, the network address 10.10.10.0 / 255.255.240.0 is separated into Virtual LANs (VLANs). The GUP 10.10.10.100 is on a separate VLAN 0, and the clients are on different VLANs 1 through 10.
I ignored the fact that there are on VLANs and followed Symantec's directions for creating Explicit GUPs for roaming clients.
Policies > LiveUpdate > GUP Policy > Server Settings > Group Update Provider > Configure Explicit Group Update Provider List > Add
Client Subnet Network Address: 10.10.10.0
Type: IP Address
IP Address: 10.10.10.100
Port: 2967
After waiting several hours, I go to Monitors > System Logs > Client Activity > Event Source: SYLINK
And the only clients that receive AV defs from GUP 10.10.10.100 is the GUP itself. In other words, the log shows that GUP 10.10.10.100 receive AV definitions from 10.10.10.100.
I'm testing 5 GUPs and they all show this same result, i.e. GUP receives AV definitions from itself!!!!
How to simplify the creation of GUP policies so that I don't have to create individual GUP policies for each site!!!!!!
Hi..
Was wondering if there was a way we could prevent all users...including those with local admin access on their Mac from disabling antirvirus and spyware protection.
Experience shows that even if it is disabled, server policy will enabled it once again automatically, but wanted to check if there is a way to keep it from getting disabled altogether.
Any thoughts?
Thanks!
-A
Has Symantec published any communication on Microsoft Security Advisory 2916652 Released?
Hello
I am wonder is it posible enabling location awareness for a user which belong to group eg local administrator.
for example administrator can read writte on usb but normal user only read.
(every location have different police ADC )
I can assign location for user but i must know login this it is in registry
In same case especial in big envirometr is difficult to implement this so i think abut assign for group
But I haven't idea how to achive.
I am re-structuring how our clients receive AV defs from GUPs. Where do I specify that Mac OS clients receive definition from GUPs. Some of our branches have 90% Mac OS computers.
For some hours now (12/10/13 15:00 UTC to 19:00 UTC) it's impossible for me to download jdb files. It doesn't matter if I use a company PC via proxy or my private laptop with a completely different provider. I tried some certified jdb files and some Rapid Release files, HTTP or FTP. The download always failed after about 5 or 6 MB. Even specialized download programs failed.
Is there a known issue at the Symantec side for the time being?
Thanks!
In the last month we have seen a significant decrease in bandwidth following the SEP 12.1.3 upgrade. The problem did not exist in 12.1.2 and no policies have changed. I found that if i disable the Network Threat Protection the problem is alleviated, but this is not a valid long term solution.
So far I've tried:
-adding host exceptions in the IDP policy
-adding process exceptions in the virus scanning
-adding process exceptions
I have upgraded the backup server to 12.1.4, as well as a test destiantion client but that did not seem to make much of a difference.
I was hoping there would be a recommendation or suggestion on how to get BackupExec to work well with 12.1.3
at our organization we have a good web gateway url filtering and antivirus solution.
for antivirus solution we are using sep 12.1.4
do we need to enable Advances download and browser IPS features or will they just waste PC resources?.
thanks
Received the attached error on Manual install of 12.1.RU2.
Anybody has suggestion(s)on this?
Hi All,
First I would like to thank you for reading.
My problem is that we have workstations in a domain and daily operation of those workstations are run using a limited domain user account.
We found out that the symantec tray icon has disappeared in that account while it is normal in the administrator account.
We concluded it could have been domain policy problem in which the tray could be blocked by the app locker. We know that the Symantec client itself is online by checking in the server that the client is alive and kicking.
Thus I would like to know the exact path for the tray icon .exe (if there is one) so we could allow this to be accessed by the account in the domain policy.
Grateful if anyone could provide any alternative solution.
Thank you again for your time!
We don't use NTP, and we won't, ever(due to a long history of it causing major headaches). So unamanaged detectors will not work.
So without NTP, how do I find unmanaged computers in 12.x? Please don't refer me to the "Client Deployment Wizard" it does no detection of any kind to see if a client is managed or not, I have thousands of clients and don't have time or patience to check each one manually.
I have noticed when I delete an object from SEPM, i.e. Group, Policy, etc, it stays in the MS SQL Database.
This is a problem because let us say I create test policy "ABC LiveUpdate GUP Policy" with the 5 GUP IP addresses. I apply the policy, and then delete it from SEP Management Console.
Now, I want to create an actual policy "ABC LiveUpdate GUP Policy", but let us say that I add 20 more GUP IP Addresses that are GUP servers. I then apply this policy, but the clients only use the the IP addresses of the 5 GUPs from the old "ABC LiveUpdate GUP Policy".
Then, I go into the SQL database and run the query
SELECT * FROM IDENTITY_MAP
WHERE NAME LIKE '%ABC LiveUpdate GUP Policy%'
and it outputs TWO instances of ABC LiveUpdate GUP Policy (only the ID is different). Then I have to delete ABC LiveUpdate GUP Policy.
DELETE FROM IDENTITY_MAP
WHERE NAME LIKE '%ABC LiveUpdate GUP Policy%'
Why does this happen? When I delete something from the SEP Management Console, I expect it to be deleted from the SQL Database the first time around.
I should be able to create a policy, delete it, then create a new policy with the same name without worrying about whether it will work or not.
Can someone shed some light on this? Is there a workaround for this? Is Symantec aware of this issue?
We have SEP 12 RU4 Client but cannot find LiveUpdate in Control Panel. Where is LiveUpdate located?