Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

Definitions download but don't install?

$
0
0
I need a solution

Is it possible to set up symantec endpoints to download SEP updates and deffinitions but not install them on the the client until manually told?


Antivirus content don't want to update

$
0
0
I need a solution

Hello everyone. On SEPM, one of server has antivirus content out of date. I try to use "update content" option , but it did't work . Server is connected, and accepted other updates . Only this one remain out of date. . I change "pull""push" update option but still without any change.

Do you familiar with this problem ?How I can resolved it ?

Expired license

$
0
0
I need a solution

Our license has expired at the end of September. The company is looking to get it back on track. We've noticed SEPM wtill downloading and sending updates. How long will this download before finally stopping updates?

Web Attack: Fake Scan Webpage 29 attack blocked.

$
0
0
I need a solution

Die Anzeige der Seite www.dshield.org wird seit heute browserunabhängig gesperrt; die Meldung in den Security-Logs dazu (Beispiel): "[SID: 28847] Web Attack: Fake Scan Webpage 29 attack blocked. Traffic has been blocked for this application: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE".

Ist jemand zu informieren? Besteht tatsächlich Gefahr?

Mit der Bitte um Aufklärung

Peter Habermann

is this version 12.1.6 MP1 or MP2

$
0
0
I need a solution

I downloaded the following file from fileconnect

Symantec_Endpoint_Protection_12.1.6_MP2_Full_Installation_EN

SEPM installs version 12.1.6465.6200 which i understand is MP2

But client installation packages for windows are 12.1.6318.6100 (MP1)

is somting wrong with the package or is there not yet a MP2 client package

thanks

[SEPM] Certificate acknowledgement prompt at logon

$
0
0
I need a solution

Hi all,

I have upgraded 2 SEPM servers from 12.1 RU4 to RU6 MP1a.

Everything went ok, no problem.

Now I've exited the console and I want to logon again.

Before login, the console tells me that the certificate is not in the store and prompts me for the acknowledgement.

Where does this come from ?

I suppose there's no security problem but I don't understand why I'm prompted today ?

Last year I've upgraded from RU1 to RU4 and I don't remember having had this annoyance.

Thanks for your answers.

Luc

How to configure a smartphone as read only

$
0
0
I need a solution

Hi there,

I need know how can I configure a smartphone as read only.

I got the Device ID and I have configured in hardware device, but the rules are not working.

The smartphone is recognized as Portable Device.

Is it possible to configure with Application control? 

Ps: There is a rule to make all Device Storage as read only and block to write, and I tried to do same procedure, but it is not working.

Thanks for all.

Regards,

Lopes

SEP Installation Rollback on Windows 10

$
0
0
I need a solution

Hi

Trying to install SEP 12.1.5337.5000 on a new Win 10 Pro laptop (upgraded from Win 7, but then reset to barebones Win 10 using Windows Reset feature - got rid of all bloatware).

I am not installing the last 2 features of Proactive Threat & Network Threat protection from Custom Install.

The installation starts rolling back after the SEP service starts in the task manager.

The installation ends with a message "The wizard was interrupted before Symantec Endpoint Protection Client could be completely installed. Your system has not been modified. To complete installation at another time, please run setup again".

Need help in getting this installed.


SEP GUP

$
0
0
I need a solution

Hello everyone . I just wanted to confirm one thing. Can we make the GUP server download definations from the internet if it is unable to reach SEPM to get the content or for whatever reasons it cannot download definations from the SEPM server.

For a group if we have enabled all the options for LU , then precedence that clients use to grab content would be like this.

1) First try GUP ( whatever type is)

2) If can't reach GUP try SEPM

3) If cant download via SEPM try Internet

Now since GUP is also a SEP client having an additional GUP server role enabled and also part of the same group where the LU policy is applied and it is GUP for the same group . The above logic except point ( 1 )  doesn't apply to GUP ?

Thanks

FileConnect IE11 error "Access Denied, your browser is out of date"

SEP can't log/block port 25 ?

$
0
0
I need a solution

Hello,

I'm running SEP12 RU6 MP1 SEP client / SEPM. Trying to log (or block in future) all outgoing traffic to remote port 25 (SMTP).

I already try a lot before posting here, client doesn't want to log / block anything no matter what i'm doing...!!

Capture2.JPG

Capture3.JPG

Capture.JPG

Any idea(s) ?

Thanks

Host Integrity - Virus Definitions

$
0
0
I need a solution

I'm going to be putting a Host Integrity policy in place but the wanted me to test it first.  Therefore I moved my machine to a group by itself, assigned it a liveupdate policy whose server would not resolve.  I then went to remove my definition but after running smc -stop I could not completely delete the definition folder.  Then when i went to the registryand when down to hklm/software/symantec/shared defs none of the keys that needed to have their value removed were present.

So I went and restarted smc.  I got the warning that the host failed the HI check and when I went into the client management security logs saw that it did download the file from our internal liveupdate server but result was fail.  I'm just digging around trying to figure out why it failed.  Is it because the definitions are damaged instead of missing?  Is there another command that needs to process first?  Any direction would be appreciated.

Just noticed at the end of the below error it says user delayed remediation but I didn't so I'm not sure.

Actual error:

Requirement name: "Week Old Antivirus Definitions".
--- Start checking requirement conditions ---.

Rule type: Antivirus enforcement.

Condition: Antivirus is running.
Result is pass.
Condition was checking "Symantec Endpoint Protection".

Condition: Antivirus signature file is up to date.
Result is fail.
Condition was checking "Symantec Endpoint Protection".
Error: file not found.
[Details: Invalid signature date. Probably software is not installed or is running an update]

Processing remediation actions.
Condition: File download complete.
Condition was checking "http://SSEPLUPP014001.msnyuhealth.org:7070/clu-test".
Result is fail.
Error: user postponed remediation.
[Details: 10/15/2015 10:50:21]

Requirement name: "Week Old Antivirus Definitions".
Result is fail.

Exceptions getting overrided on OS X client.

$
0
0
I need a solution

Hello!

I'm currently testing the Symantec Endpoint Protection product but we hit a roadblock that would prevent us from using the software.

On the Windows client, when I change the exceptions on SEPM admin console, the user-defined exceptions stays in place. On OS X, the whole list get overrided by the server, which I don't want to happen. Is it normal behaviour? The OS X version I have of SEP on OS X is 12.1.6168.6000. 

Thanks!

Path to most important logs for analysis on SEPM and client

$
0
0
I do not need a solution (just sharing information)

Hi everybody,

I´m seeking help to find out the paths to important logs that can be analyzed in case of malfunction or audit on the sepm and clients.

I´ve tried my best to find, for example, the liveupdate.log on a client that doesn´t update definitions but had no luck.

Also would need to know the name and place to find the log that shows all transactions made on the sepm.

Finally if someone can make a list of the most important logs and their location, will be very appreciated.

I understand that a lot of the information can be found straight from the sepm console but I think that being able to read straight from the log is much better.

Thank you very much!!

Security Virtual Appliance.

$
0
0
I need a solution

Bonjour tout le monde.

J'ai besoin d'aide sur la partie installation de security Virtual Appliance.

lors de l'exécution de la commande java -jar Symantec_SVA_Install.jar -s pathname/SVA_InstallSettings.xml,

L'outil me demande:

Enter the vCenter password for [root]:*******

aprés l'introduction du mot de passe voici ci-dessous le message d'erreur:
Unable to install SVA: Unable to connect to vCenter. 

Merci d'avance pour votre aide.


Need Symantec AntiVirus run on an Instrument with Windows OS

$
0
0
I need a solution

Gentlemens,

I need a solution to perform the SAV on our manufacturing product - Oscilloscope. The Oscilloscope is using ATX Motherboard & HDD by running GUI on a Windows XP OS. We need to create a SAV check point for Oscilloscope. Can you provide a suggestion on how to do that? 

I have problem with VDI

$
0
0
I need a solution

Hello, 

SEPM gives notifications about NETWORK VIRUS DEFECTED and source of this virus are THIN clients and they haven't installed SEP Client, because of low disc space I can't install CLIENT soft for them and I'm interested if there is any solution if I can instal there any SEP agent or something like this to scan these virtual computers without installing full SEP client.

Clients using WIN7

SEP version is 12.1.5 RU2

Also I have situations where SEP icon shows that "There are multiple problems (2)" and I cant identify what problems there are.

Symantec Endpoint Protection

$
0
0
I need a solution

How much time it takes for the Symantec to update the identified event to be inserted in DB.  Does it do it immediately (or) it takes time?  If it takes time how long it takes?

Find MAC addresses in SEPM

$
0
0
I need a solution

Hi All,

          The4 data in SEP is really useful and in soime cases can be quicker to search than other systems. We really need to search on MAC addresses of machines as this will always tie down the correct machine as aopposed to an IP which can ofcourse get released. Is there any way to quickly search for MAC addresses in SEPM without having to still use the round about solution from 2011 below?

""  The only way I know to search for a client by MAC address is in a round about way.  The MAC address for the client will show up in an exported 'Computer Status' log.  Go to:

  1. Monitors
  2. Logs
  3. Log type:  Computer Status
  4. Choose the appropriate other settings to your needs
  5. View Log

You can then export the list and there will be a MAC address column.  Using excel to open it is the easiest.  You could then find any other information about the machine that you can use to find the machine using the built in search function in the SEPM.

Hope this helps, but I know this is not exactly ideal. Like it was said above, the ability to search by MAC address in the SEPM does not currently exist (to my knowledge).   """"

Cheers

PaulC

1445004460

Co-locate SEPM and SharePoint Protection Engine

$
0
0
I need a solution

Can you install the SharePoint Protection Engine scanner on the same server as the SEP management is on without degradation to either service?

1445009225
Viewing all 10484 articles
Browse latest View live


Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>