Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

Cant upgrade Clients on Win XP from 11.x to 12.1 RU2

$
0
0
I need a solution

I have problem upgrading my client because the deployment to xp client doesnt work . The rest of OS ( Win7 , Vista ) the upgrade run without problems. i Dont  wanna upgrade all my xp client manually because i have 4k of them. Someone can help.

 

A few xp client show this error:

Symantec Management Client service. Error code returned 0x8007041d

 

 

 


Older SEP 11.06 Allow All Other IP Traffic Firewall Rule

$
0
0
I need a solution

I'm looking for information on the default firewall rule set for SEP version 11.06.  We are in the process of migrating to 12.1, and using the firewall policies for that version.  So going forward it shouldn't be an issue. However the question is: What was the purpose of the "Allow All Other IP Traffic" rule?  It was enabled by default, and was followed by a Block All Other Traffic rule, lower in the stack. 

There has been concern that systems running this firewall rule may have been unprotected from network threats, and we are trying to better understand the purpose of this rule...and the impact to client systems.  Also what is the impact of disabling this setting?  Any information would be appreciated.  Thanks 

8109491
1355953955

I pushed SEP 12 to two Win XP, they refuse to communicate with SEPM

$
0
0
I need a solution

This thread is an offshoot of

 

https://www-secure.symantec.com/connect/forums/unable-push-sep-12-package-win-xp-7-computers

 

I have a test SEPM server running SEP 12 (Version 12.1.2015.2015).

I have two test Windows XP workstations that were previously running SEP 11 RU7 and were checking into another test SEPM server running SEP 11 RU7

Yesterday I was able to remotely deploy SEP 12 installation package to these two Windows XP workstations. I decided to check how things are this morning

1. When I check the SEPM server running SEP 12, these two workstations do not appear

2. When I check the SEPM server running SEP 11 RU7, these two workstations no longer have a green dot, but they still appear

3. When I check the SEP clients on the workstations themselves, they have been upgraded to SEP 12 ~~~BUT~~~ status says offline

 

When I remotely deploy SEP 12, I expect that these two workstations will (1) upgrade to SEP 12 and (2) check into SEPM 12 console.

How to make it such that when I remotely push SEP 12 to workstations, they upgrade AND check into the SEPM 12 console.

 

Help!!!

change sql server from sep manager

$
0
0
I need a solution

Hello All..

 

I have 2 SEPM servers, and 2 SQL servers.

I have configured those SEPMs with load balance... It is running fine!!!

Well, my sql server configuration isn't cluster. We are using log shipping for replication. One is Read-Write and other is Read-Only.

Of course, this moment, both SEPMs are connecting in Read-Write SQL server.

My doubt is: We need to become that Read-Only as Read-Write. It is easy for our team, but I need to know how to change my SEPMs to connect in that new Read-Write. I dont have an easy way/option to change it in SEPM Console.

How can I do it?

Thanks,

 

Diego

8112921
1356019527

How to allow mobile data card traffic in SEPM through firewall rules?

$
0
0
I need a solution

Hi,

We have SEPM 11.0.5 running with over 10.000 clients. Some of these clients are running SEP 11.0.5, other 11.0.7 and other v12.1.

Until recently, we have had not problem with any provider of mobile data cards in the world. The traffic being generated by them was not being blocked. But recently, some of our users in India have had problems with some newly purchased mobile 3G data cards, as their traffic is being blocked by SEP Network Threat Protection firewall component.

The problem I have is that, in the firewall log, the ETHERNET header is always different (sometimes it's 0xAAe, others it´s 0xA0B, others it's 0xA82, etc). So I can't create a policy based on the Ethernet header.

Can anyone suggest any other way of doing it?

 

 

Thanks!

Definition update on SEP clients.

$
0
0
I need a solution

Hi,

I'm a little confused about something... It seems the only way for my SEP clients to pickup new definition files is through LiveUpdate.

So although I have both "Use the default management server" and "Use LiveUpdate" checked on our SEPM server, definition files don't seem to be updated using the default management server.

Is there a way I can manually test definition file updates through the management server?

Thanks.

 

error in client

$
0
0
I need a solution

Facing the error in few clients. below is the snapshot.

 

 

 

GUP Creation

$
0
0
I need a solution

How to create the Remote client as a GUP(distribution point)?


HOW TO determine what port clients are communicating with SEPM on

$
0
0
I need a solution

Our production SEPM is running RU7 MP1.

What report will show what port clients are communicating with the SEPM on?

We are trying to troubleshoot an issue to determine which clients are communicating with SEPM on port 80, rather than then recommended port of 8014.

 

 

System Requirements for LiveUpdate Administrator 2.3.2

$
0
0
I need a solution

Where could I find the System Requirements for LiveUpdate Administrator 2.3.2?

I've found the ones for 2.3 and 2.3.1 versions but not for 2.3.2?

 

Suggestions? :-)

 

Thanks!

manually defintion update

$
0
0
I need a solution

Hello,

What is the link to download the defintion?

8114231
1356034305

Port Scan from a Networked Printer

$
0
0
I need a solution

Hello,

I have some customers who can't access their networked printers because SEP 11.0.7200 is blocking due to what NTP believes is a Port Scan attack.

See below:

 

Event Description:

 

Somebody is scanning your computer. Your computer's TCP ports: 56902, 56899, 56901, 56900 and 56897 have been scanned from IP.

Attack Type:

 

Port Scan

Network Protocol: TCP

Traffic Direction: Inbound

Send SNMP trap: 1

Remote Host Name:

Hack Type: 0

Application Name:

 

I found a couple articles, one suggested disabling the Dell Advanced Networking Service (sadly this service does not exist). Another suggested an issue with UPnP (is there a way to disable UPnP on the printer).

**I do not want to bandaid this by adding an exception for that printer or adding an Intrusion Prevention exception (I found those suggestions as well).

I'd like to figure out what the issue is and either make a global change on the SEPM (that does not leave me unprotected by NTP) or determine if this is a printer configuration issue, and have the field techs remediate all the printers.

Any thoughts from you brilliant SEP/M experts??

Thanks,

-Mike

P.S. Upgrading to SEP 12.1.2 is also an option if it is a suggested fix.

auto protect off

$
0
0
I need a solution

At server almost 50 systems are reflected where auto protect off. how to repair?

Symantec blocking wake on lan magic packet?

$
0
0
I need a solution

Searching for a cause....

 

Not sure if it's Symantec or what.  We recently updated servers from 12.1.11 or .14 to 12.1.2.

 

Has anyone reported problems with SEP 12.1.12 blocking wake on lan magic packets? 

 

Symptoms....

The server that sends out magic packets doesn't seem to be getting them to the machine.

The machine wake fine from the exact same software on other computers.  So the machines are ready, no problems on the receiving side.

 

Our set up, in part, is like this.

Host server with SEP.

VM-1 server running on Host server, also with SEP.   Both are updated.

Other VMs on the host server.   Say VM-2, -3, etc.

SEPM is running on its on VM on another Host machine, completely separate.

 

We use VM-1 to send out magic packets.  That stopped working recently.  Not sure exactly when. 

VM-1 won't get magic packets to the machines.

Tried the Host server.  Same thing.  Magic packets don't get out.

However... VM-2 and VM-3 will send out magic packets.  Strange.

 

That makes me think it's not Symantec.  Agree?

 

We also tried....  (And we don't use the Symantec firewall on anything.  It's not installed on anything here.  We didn't want to mess with Symantec firewall settings on servers when we already had the Windows ones tweaked and working.)

We disabled the firewall completely on VM-1 and the host server.   Still no luck.

Tried uninstalling Symantec, SEP, on VM-1.  Still no luck.  However... We can't restart that server right now.  We were thinking the 'no restart' option meant we wouldn't have to restart the machine to complete the install/uininstall.  I'm think that only applies to the delayed restart option.

 

So it was working fine before.  We've made a few changes on servers, including moving to SEP 12.1.2 on everything.  We don't use the Symantec firewall so that shouldn't be a factor.  Nothing with firewalls should have changed.  Even with all firewalls off, magic packets still don't work on some VMs.  But other VMs do work for sending out magic packets.

 

Any thoughts?  I'd like to restart servers, but that's not possible right now.

Enable packet logging

$
0
0
I need a solution

How can I enable packet logging under NTP settings in sep 12.1?

We need to do some deeper troubleshooting...

thanks!!

km

8119241
1356119924

Modify an installation package

$
0
0
I need a solution

Hello,

I manually created an installation package from the 12.1.2 file downloaded via fileconnect.  However when I extracted the files from the zip from fileconnect, I accidently left out a few folders.  I would like to rebuild the installation package I created, so that it will contain all the files it's suppose to. SEPM won't let me delete or modify the package I created because it is "the latest version".  Is there any way around this?

Thank you,

 

Steven

Account lockout

$
0
0
I need a solution

Is it possible that Trojan Horse/Virus get lockout the Domain ID?

 

DBA password

$
0
0
I need a solution

What is Symantec Database username password?

How to get this information?

Version - 11.0

Database - Sylink/Embedded.

Endpoint 11.0.7300.1294 to 12.x

$
0
0
I need a solution

i believe i miss read the upgrade paths for 11 -> 12, and thought i had to make sure i was on the latest version of 11 (11.0.7300.1294) to upgrade to version 12.1.1000.157.... only to read somewhere else that this version doesnt upgrade inline?

did i put myself between a rock and a hard place?

when i attempt to run an inline upgrade the first part runs fine, but when it says its going to start the upgrade wizard thats where it never starts. im able to roll back to just before my upgrade, but no further....

any direction would be greatly appreciated!

Ways to uninstall SEP client

$
0
0
I need a solution

HI,

I want to know how many ways to uninstall sep client .

8120181
1356157271
Viewing all 10484 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>