Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

SAV for Linux - Support for Ubuntu 12.10 (kernel v3.5.0.21)?

$
0
0
I need a solution

Will Symantec support the latest version of Ubuntu which is 12.10 with a kernel version of 3.5.0.21-generic?

If yes, when?

Thanks in advance for your reply.


Need example of SEPM firewall config for Domain Controllers

$
0
0
I need a solution

After migrating to SEPM 12.1 (finally) we have everything working except for the firewall.  We did not have a firewall configured with 11.x but need to implement one for 12.1.  I have tried several configs but a few hours after applying one, the DC's both stop serving out filesharing and log on requests.

Here is a copy of the draft config I have been working on; hopefully someone can post a working config they have running already.  I am not sure why communications are being cut off, I am allowing DNS / DHCP; any traffic from the other DC and blocking IPv6.  Can anyone point me in the right direction; either a policy they have running or to some documentation that would be helpful?

 

Cyber_Saiyan

Upgrading SEPMs to SEP 12 RU2 is TERRIBLE!!!

$
0
0
I need a solution

I am having a TERRIBLE experience upgrading our SEPMs to SEP 12 RU2

 

1. It took nearly 3 hours of attempts to copy the SEP 12 installation file from a share drive to our remote SEPM servers. Symantec finally provided a URL for direct download.

2. When I finally got the installation file copied onto the SEPM server, it would not let me install because it says I am not connecting to Remote Desktop using session 0. When I used the mstcs command Symantec gave, it did not work. I figured out another method on my own, Start > Run > type in "mstcs /v:IP_Address /admin"

3. When the SEPM seems to upgrade, it says it will upgrade the database schema. OK, that is fine. But I get errors and Symantec told me to run Symantec Helper and send them the output.

 

I am yet to hear from Symantec Engineer working on my case, and I have attached the output to the Symantec Helper. I am really at my wits end with this, someone please help!!!!!!!!!!!!

What folder/file exceptions should be made for Office Communications servers?

$
0
0
I need a solution

I have Symantec Anti Virus on the server now, I want to get SEP on it, I need to know what exceptions should be in place for this type of server. I do not want SEP sacking an important file that can bring down communications. Can you please provide me with a list of file/folder exceptions?

Thank you

The Server is a Windows 2003 Server, I want to install the Latest version of SEP.

Thank you

8133231
1356638333

Safe Mode system updation process

$
0
0
I need a solution

Hi

What is process to update the systems which are in Safe Mode?

GUPs not registering in 12.1.2

$
0
0
I need a solution

With the upgrade to 12.1.2 (12.1.2015.2015) we moved to a global configuration independent of Active Directory.  As a result, we also moved to a global GUP list, however, something appears ary.  When building the list, all GUPs we entered one time, however, now they appear in my GUP list more than once, most appear twice, but there are others that appear 4-5 times.

Thought it may have been a result of multiple IPs, but the system that appears 6 times only has one IP.  I also thought it might be a result of an entry for each SEPM I have, but I only have 3 SEPMs so that does add up either.

I have a feeling that this is causing my issue where GUPs are not getting their appropiate policy.  System that is supposed to be the GUP is installed, rebooted and shows online, but the SEPM shows false.  As a result there is no GUP for the clients to use and they are going out of date.  Is the fact that GUPs are appearing twice or more causing the issue or am I looking in the wrong place?

The fact that systems that are supposed to be the GUP display false is making me nervous, especially since we are making a major push to 12.1.2 because of the GUP issue that existed in 12.1 RU1MP1 that saw the SMC service just crashing on on the GUP...

Disabling Firewire

$
0
0
I need a solution

I would like to disable the Firewire port on my computers using Application/Device Control.   I'm using the built in class ID for 1394 FireWire Devices.  Its not working for me.   (In a Application and Device Control policy, click on Device Control, under blocked devices, click on add and select 1394 firewire devices).

this article http://www.symantec.com/business/support/index?page=content&id=HOWTO60964
states that Firewire controllers are whitelisted, so I can't diable them.

Why would symantec give me that option if they are going to silently not do it?
As currently configured will this disable all devices that connect to the 1394/firewire port, or will it just do nothing?

Is there any way I can get sep to disable firewire?

SAV for Linux - errors when installing it on Ubuntu 12.10

$
0
0
I need a solution

Hi guys,

I'm running Ubuntu 12.10, kernel version 3.5.0.21-generic, 64-bit, US English.

When I tried to install SAV for Linux version 1.0.14-13, I received the following messages at the terminal window:

-------------------------------------------------start of quote--------------------------------------------------------------------

sharon@sharon:~$ cd /home/sharon/savfl/deb

sharon@sharon:~/savfl/deb$ sudo dpkg -i sav-*.amd64.deb savap-*.amd64.deb savjlu-*.amd64.deb savui-*.amd64.deb

[sudo] password for sharon:

Selecting previously unselected package sav.

(Reading database ... 151630 files and directories currently installed.)

Unpacking sav (from sav-1.0.14-13.amd64.deb) ...

Selecting previously unselected package savap.

Unpacking savap (from savap-1.0.14-13.amd64.deb) ...

Selecting previously unselected package savjlu.

Unpacking savjlu (from savjlu-1.0.14-13.amd64.deb) ...

Selecting previously unselected package savui.

Unpacking savui (from savui-1.0.14-13.amd64.deb) ...

Setting up sav (1.0.14-13) ...

Setting up savap (1.0.14-13) ...

symap: not currently loaded

symev: unable to load kernel support module (UNSUPPORTED-OS-ub-ST-12-3.5.0-21-generic-x86_64)

invoke-rc.d: initscript autoprotect, action "restart" failed.

Setting up savjlu (1.0.14-13) ...

Processing triggers for ureadahead ...

ureadahead will be reprofiled on next reboot

Processing triggers for man-db ...

Setting up savui (1.0.14-13) ...

Processing triggers for bamfdaemon ...

Rebuilding /usr/share/applications/bamf.index...

Processing triggers for desktop-file-utils ...

Processing triggers for gnome-menus ...

sharon@sharon:~/savfl/deb$

----------------------------------------------end of quote-------------------------------------------------

How do I fixed those errors that I have highlighted in bold?

Thanks in advance for your help.


All SEP Client Show Offline

$
0
0
I need a solution

Hi All,

My company is using SEPM 11.0.7200.1147 Version which installed in Windows Server 2003 R2 Enterprise x64 Edition SP2 in VMware.

I have to upgrade the VMware Tools...

After VMware Tools upgraded, I cannot login SEPM.

I found that the Local Area Connection disapper on Network Connections suddenly.

After reinstall the VMware Tools, the network card apper on Network Connections automatically, but it called Local Area Connection 2....

Although I can login to SEPM now.

But...

All clients show offline nowcryinghow can I fix that?

Control Client communicate direct to SEPM Manager

$
0
0
I need a solution

Im controlling entire APAC where Singapore is the main Data Center where the SEPM Manager is located . Rest of the country is APAC is install with GUP Server . The communication will be between GUP Server and SEPM to get the definition update where the client will get the update from the GUP .

 

But There are certain client which able to communicate direct to SEPM Manager . Although policy has been assigned and firewall has been implemented . i unable to control the client by communicating . Please advice

SEP 11 RU6 MP3: Scan log shows 2019 instead of 2012 and still running...

$
0
0
I need a solution

Dear all,

Any idea of below scan log? Once clicked... it will say "please wait for the scan to finish completely...."

 

Client is on Windows Server 2008 Ent, SP 2...... SEP 11 RU6 MP3....

and no, we don't have a schduled scan for 2019!!!

 

8134971
1356686556

SEP client 12.1.2015.2015 communication troubleshooting problem

$
0
0
I need a solution

Hi all, happy New Year !

I had a problem with some client workstations.

In order  :

- install the client from the management server for a specific group.

- checking successful installation on the client system logs

- after installation make client workstation reboot

- client icon not displayed in SEP management console.

- I log on as administrator on client  workstation, start SEP client GUI, open tab Troubleshooting and see, that the client included in another group.

- but in SEP management console client icon not displaed in another group

- search client in SEP management database does not find

- I take SyLinkDrop and correct sylink.xml file. SyLynkDrop report - file replaced. But Troubleshooting tab displaed wrong group.

- I export policy and import on client. After import policy Trobleshoting tab display correct group and policy number and quickly return wrong group and policy number.

This sequence is independent of the operating system and it was fresh client installation or upgrade from version 11.0.6000.645

Any ideas...

Regards,

   Ub40

ccsvchst.exe et Cisco VPN

$
0
0
I need a solution

Bonjour,

Dans l'entreprise ou je suis, nous sommes sur Symantec EndPoint Protection 12.1.1101.401.

Dès que nous installons un client Cisco VPN 5.0.07.0410-k9 et que nous redémarrons le poste, nous avons le message d'erreur :

"ccSvcHst.exe - Erreur d'application

L'instruction à "XxXXXXXXXX" emploie l'adresse mémoire "XxXXXXXXXX". La mémoire ne peut pas etre "written".

Cliquer sur OK pour terminer le programme"

Le message apparait seulement 1 fois au premier arret ou redémarrage de la machine

Comment corriger ce probleme ?

8135681
1356707691

Suspicious file submission closed - SEP still doesn't detect trojans

$
0
0
I need a solution

I have submitted malware file today. Tracking number #27534670. I've got email, that my submission was closed and no malicious files were found. So, what else can i do to convince Symantec to do their job?! Maybe this

https://www.virustotal.com/file/9efdfb3c58c9a4087c...

Startup entry was created in user's registry pointing to this file, so this is not just a leftovers after virus elimination. I demand updating your definitions to detect and delete such files. Also waiting on another submissions:

Tracking #27525536

Tracking #27525537

Tracking #27525538

I had to divide thi submission into 3 parts (fighting with unreadable captcha, hewn you can't tell apart I and l ..), because surprise surprise, you can't submit more than 10 files. Maybe Symantec is living only on donations from generous people and i'm not paying thousands of dollars for my licenses? These 3 submissions are waiting for human analysis. Some of them already marked as not malicious (it seems Symantec is only considering ones with exe extensions as possibly malicious). Yet one of those files was also sitting in the registry and hijacking user's connection to e-bank site, maybe even stealing his credentials. Again, majority of other engines on Virus total detect those files as trojans.

Should i mention that i must make exceptions for some legitimate software so it won't be deleted by SEP, or new versions of SEP occasionally breaking my network connectivity or SMB protocol support, etc.

Endpoint Protection blocking internet connection.

$
0
0
I need a solution

I have a user that gets blocked from the internet periodically due to a setting within Endpoint Protection.  The warning he gets is similar to: 

Traffic from IP address 192.168.1.1 is blocked from 11:53pm to 12.03am.
Denial of Service is logged.

Has anyone heard of this before, or have any insite as the where the problem may lie?  I checked the Endpoint Protection logs, but I was unable to find any blatent issues.  The user states that it generally happens with malformed URL's, but I am unable to reproduce it at our helpdesk.


Email Scanning

$
0
0
I need a solution

Which application/antivirus is used for Email Scanning in Symantec?

SEP 12.1.2015.2015 & LiveUpdate Administrator

$
0
0
I need a solution

Hello:

Since upgrading to 12.1.2015.2015 in my test environment, test clients have not received updates from our LiveUpdate Server.  In the LiveUpdate Administrator, I currently have Symantec Endpoint Protection v12.1 selected in My Symanted Products.  Does 12.1.2015.2015 require another product selection such as v12.1 RU2 or v12.1 (Beta)?

If this is the case, can I remove Symantec Endpoint Protection v12.1 from My Symantec Products?

Thank you,
Anthony
 

GUP and Endpoint Status for Off-Network Clients

$
0
0
I need a solution

We are in the process of migrating our clients from Sophos to Symantec Endpoint Protection (12.1.2015.2015) and are trying to configure how laptops that are not always connected to the network receive their updates when off-site.  With Sophos, this was achieved through an update policy that stated to use the internal update manager as the primary location and to use an update repository that was located on a server in our DMZ as the secondary location.

Will we need to do something similar when using Symantec Endpoint Protection Manager or is the recommended method outlined in this article?  If we need to do something similar, where do we find documentation to accomplish this?  If the article is the recommended method, then we have followed that and created the policy, the location and assigned the policy.

Is there a way to find out the status of systems that are not on the network very often to ensure they are receiving updates and are not infected?

Thank you.

ClientSideClonePrepTool for SEP 11.X

$
0
0
I need a solution

Hello,

Does anyone know how i can download the correct version of "ClientSideClonePrepTool" for Symantec EndPoint Protection 11.X?

The version of the "ClientSideClonePrepTool" that I have is "Version 1.0.0.1" which does not work on Symantec EndPoint Protection 11.X. Also, when I run this utility I get an error that reads "Failed: Incorrect version, SEP 12.1 or higher is required"

Can anyone please help me as I'm trying to create an Image of Windows 7 with SEP 11.X, and LANDesk installed on it prior to running sysprep.

Your help is greatly appreciated in advance. Thanks

Need to uninstall Symantec Endpoint Protection

$
0
0
I need a solution

I have an iMac running 64-bit Windows 8 Pro through Parallels Desktop 8. I tried to install a Windows 7/Vista/XP version of Symantec Endpoint Protection (64-bit client), but found out that it wouldn't install because it doesn't work under Windows 8 (so much for backward compatibility). So I gave up and purchased/downloaded Norton Internet Security, but it won't install until I uninstall SEP.  I've tried uninstalling SEP through the Control Panel numerous times, restarting the computer as well.  SEP is still there and NIS still won't install. Chatting with "Nathan" didn't help as the Norton Removal Tool told me I had to uninstall "Symantec Antivirus 9 or later". Trouble is SEP is the only Symantec/Norton product listed as being installed, which as I mentioned earlier, refuses to uninstall. I sure hope someone can tell me how to get out of this mess.

8138481
1356800855
Viewing all 10484 articles
Browse latest View live