I have read a lot of documnet which are regarding to USB blocking that is full restricted, can anyone help me in usb with read only access policy.
Read only ADC policy
Android mobiles : internet pass-through not working with Endpoint protection
After connecting the Android mobile phone to laptop, we can enable the "Internet Pass-through" feature, which would allow the mobile phone to use the internet available in the laptop. In my laptop, this feature works only when i disable in the Symantect Endpoint Protection (11.0.6200.754). This is
- If Endpoint Protection is enabled, am not able to access the laptop internet in mobile phone
- If Endpoint Protection is disabled, am able to access the laptop internet in mobile phone
Any idea, if i need to set any configuration in Endpoint Protection (11.0.6200.754), so that i can have it enabled and also use internet on mobile.
Thanks for helping here.
SEP Issue
While logging off from Win 2K3 servers we are getting a prompt to End Program.. Network Activity. If we do end not Server will logoff from. if we try to close the window it will trigger an event ShutDown has been cancled.
We are facing this issue after we upgraded from SAV to SEP. Can some one please help with this?
SEPclientOnCluster
We have one Windows 2008 R2 two nodes cluster as file server and our SEP server runnning 11.7. Then both nodes have SEP client 11.5 was installed on them now we have upgraded to 11.7, now both nodes and we got the issue that any one of node do not join the cluster, means when one node join cluster and create cluster other cannot join the cluster, is there any issue with SEP 11.7 client on MS cluster
Thanks
Serila Number
Is it possible to check a Symantec serial number with which account it is being registered ?
svchost.exe traffic has been blocked by SEP Netowork Threat Protection
https://www-secure.symantec.com/connect/forums/tra...
I have been having a problem with my SEP Threat Detection. It seems that every 4 minutes I receive a notification from SEP that it has blocked svchost.exe.
This is a clean computer, I have scanned with antivirus software and antimalware software since this has happened. The problem arose when I decided to switch from Avast antivirus software to SEP as my school has allowed me to download the latest version of it.
I have a Windows 7 Pro, SEP version 12.1.1000.157 RU1.
The pop up notifications are annoying, and I know I dont have a virus. So I consulted https://www-secure.symantec.com/connect/forums/tra... They told me to disable ip6. I did. It seems like my problems are coming from IP4 as you can see by my threat log:
12/30/2012 8:37:56 AM Blocked 3 Outgoing UDP 239.255.255.250 01-00-5E-7F-FF-FA 1900 192.168.0.143 00-10-18-EA-74-75 1900 C:\Windows\System32\svchost.exe LOCAL SERVICE NT AUTHORITY Default 18 12/30/2012 8:36:54 AM 12/30/2012 8:37:00 AM Block UPnP Discovery
12/30/2012 8:37:00 AM Allowed 3 Incoming UDP 0.0.0.0 78-A3-E4-11-C5-87 68 255.255.255.255 FF-FF-FF-FF-FF-FF 67 Admin Argh0812 Default 1 12/30/2012 8:35:59 AM 12/30/2012 8:35:59 AM Allow BOOTP protocol
12/30/2012 8:37:00 AM Allowed 3 Incoming UDP 192.168.0.1 00-1B-11-56-C2-35 67 255.255.255.255 FF-FF-FF-FF-FF-FF 68 Admin Argh0812 Default 1 12/30/2012 8:35:59 AM 12/30/2012 8:35:59 AM Allow BOOTP protocol
12/30/2012 8:36:49 AM Allowed 3 Outgoing IP 239.255.255.250 01-00-5E-7F-FF-FA NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:35:48 AM 12/30/2012 8:35:48 AM Allow IGMP traffic
12/30/2012 8:36:49 AM Allowed 3 Outgoing IP 224.0.0.251 01-00-5E-00-00-FB NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:35:48 AM 12/30/2012 8:35:48 AM Allow IGMP traffic
12/30/2012 8:36:43 AM Allowed 3 Outgoing IP 224.0.0.252 01-00-5E-00-00-FC NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:35:42 AM 12/30/2012 8:35:42 AM Allow IGMP traffic
12/30/2012 8:36:43 AM Allowed 3 Incoming IP 192.168.0.1 00-1B-11-56-C2-35 NA 224.0.0.1 01-00-5E-00-00-01 NA Admin Argh0812 Default 1 12/30/2012 8:35:42 AM 12/30/2012 8:35:42 AM Allow IGMP traffic
12/30/2012 8:35:09 AM Allowed 3 Incoming UDP 192.168.0.1 00-1B-11-56-C2-35 1900 239.255.255.250 01-00-5E-7F-FF-FA 1900 Admin Argh0812 Default 42 12/30/2012 8:34:07 AM 12/30/2012 8:34:13 AM Allow UPnP Discovery from private IP addresses
12/30/2012 8:34:41 AM Allowed 3 Outgoing IP 239.255.255.250 01-00-5E-7F-FF-FA NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:33:39 AM 12/30/2012 8:33:39 AM Allow IGMP traffic
12/30/2012 8:34:41 AM Allowed 3 Incoming IP 192.168.0.102 A4-EE-57-4E-D4-A6 NA 224.0.0.252 01-00-5E-00-00-FC NA Admin Argh0812 Default 1 12/30/2012 8:33:39 AM 12/30/2012 8:33:39 AM Allow IGMP traffic
12/30/2012 8:34:35 AM Allowed 3 Outgoing IP 224.0.0.251 01-00-5E-00-00-FB NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:33:34 AM 12/30/2012 8:33:34 AM Allow IGMP traffic
12/30/2012 8:34:35 AM Allowed 3 Incoming IP 192.168.0.1 00-1B-11-56-C2-35 NA 224.0.0.1 01-00-5E-00-00-01 NA Admin Argh0812 Default 1 12/30/2012 8:33:34 AM 12/30/2012 8:33:34 AM Allow IGMP traffic
12/30/2012 8:32:38 AM Allowed 3 Outgoing IP 224.0.0.252 01-00-5E-00-00-FC NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:31:37 AM 12/30/2012 8:31:37 AM Allow IGMP traffic
12/30/2012 8:32:38 AM Allowed 3 Outgoing IP 239.255.255.250 01-00-5E-7F-FF-FA NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 1 12/30/2012 8:31:37 AM 12/30/2012 8:31:37 AM Allow IGMP traffic
12/30/2012 8:32:33 AM Allowed 3 Incoming IP 192.168.0.122 68-A8-6D-B7-37-A9 NA 224.0.0.251 01-00-5E-00-00-FB NA Admin Argh0812 Default 1 12/30/2012 8:31:31 AM 12/30/2012 8:31:31 AM Allow IGMP traffic
12/30/2012 8:32:33 AM Allowed 3 Incoming IP 192.168.0.102 A4-EE-57-4E-D4-A6 NA 224.0.0.251 01-00-5E-00-00-FB NA Admin Argh0812 Default 1 12/30/2012 8:31:31 AM 12/30/2012 8:31:31 AM Allow IGMP traffic
12/30/2012 8:32:33 AM Allowed 3 Incoming IP 192.168.0.1 00-1B-11-56-C2-35 NA 224.0.0.1 01-00-5E-00-00-01 NA Admin Argh0812 Default 1 12/30/2012 8:31:31 AM 12/30/2012 8:31:31 AM Allow IGMP traffic
12/30/2012 8:30:36 AM Allowed 3 Incoming UDP 192.168.0.148 00-17-A4-6F-1A-F0 1900 239.255.255.250 01-00-5E-7F-FF-FA 1900 Admin Argh0812 Default 10 12/30/2012 8:29:34 AM 12/30/2012 8:29:34 AM Allow UPnP Discovery from private IP addresses
12/30/2012 8:30:36 AM Allowed 3 Incoming IP 192.168.0.102 A4-EE-57-4E-D4-A6 NA 224.0.0.252 01-00-5E-00-00-FC NA Admin Argh0812 Default 1 12/30/2012 8:29:34 AM 12/30/2012 8:29:34 AM Allow IGMP traffic
12/30/2012 8:30:30 AM Allowed 3 Incoming TCP 192.168.0.1 00-1B-11-56-C2-35 28983 192.168.0.143 00-10-18-EA-74-75 2869 C:\Windows\system32\NTOSKRNL.EXE Admin Argh0812 Default 1 12/30/2012 8:29:29 AM 12/30/2012 8:29:29 AM Allow SSDP from private IP addresses
12/30/2012 8:30:30 AM Allowed 3 Incoming IP 192.168.0.146 00-25-00-3A-C8-2E NA 224.0.0.251 01-00-5E-00-00-FB NA Admin Argh0812 Default 1 12/30/2012 8:29:29 AM 12/30/2012 8:29:29 AM Allow IGMP traffic
12/30/2012 8:30:30 AM Blocked 3 Outgoing UDP 239.255.255.250 01-00-5E-7F-FF-FA 1900 192.168.0.143 00-10-18-EA-74-75 1900 C:\Windows\System32\svchost.exe LOCAL SERVICE NT AUTHORITY Default 18 12/30/2012 8:29:29 AM 12/30/2012 8:29:34 AM Block UPnP Discovery
12/30/2012 8:30:30 AM Allowed 3 Outgoing IP 224.0.0.22 01-00-5E-00-00-16 NA 192.168.0.143 00-10-18-EA-74-75 NA Admin Argh0812 Default 12 12/30/2012 8:29:29 AM 12/30/2012 8:29:29 AM Allow IGMP traffic
Please help me find a resolution ASAP! Thank you so much for your time. I am brand new to Nortion, so please go into descriptions if you find a solution. Thank you!
Is it possible with SEPM to discover the machines without SEP in the network
Is it possible with SEPM to discover the machines without SEP in the network
USBDeviceBlock
Hi
We have SEP 11.7 and we have device block policy we are blocking USB devices on SEP clients, now it is working fine on XP windows that all type of USB devices USB hard disk or USB stick is blocking, But on Windows 2008 this device block policy is not working we can connect USB hard disk on Windows 2008 why it is not block on Windows 2008
Thanks
Symantec Bench mark on Number of Viruses on Customer basics
HI All,
Greetings of the day!!!
Is there any default Symantec Bench mark on Number of Viruses on Customer basics?
WE are utilizing SEP 12.1 RU1 MP 1 on a Software development Company having 5000 clients across Globe and the no of clients are expected to grow by 5000 by another one month and as of now we found Symantec action taken ~1 Billion incidents.
If yes please Share.
Thanks and Regards
Ajin
Notification of autothorized Download are incomplete
Hi all, I have receive a notification of authorized download by a user :
But the notification didn't tell me which computer or which user have authorize this download.
I can't find a report on SEPM to tell me that.
Where can I see which computer have download this app ?
Thanks.
Auto Upgrading Clients through HFS-https
Dear All,
Am Upgrading my Symantec Endpoint version at my remote Site by making one machine as a web server using HFS tool.
It got sucessfull in some machine's. and in some machines it gave BFE(Base Filter Engine) error, i started the Service manually.
In HFS-HTTP its showed me the package has been Downloaded to few machines.
I Just want to know where the package is copied/Downloaded on the target Machine.
Speculate the end of XP support within SEP
Hi, just after a hint if and when SEP will end support for Windows XP? Anytrhing in the pipeline yet?
New Feature SEPM 12.2
HI,
What's new feature in SEPM 12.1.2
Problem with sep firewall and dameware mini remote access
I have a problem between sep firewall and dameware mini remote.
I've allowed port 6129 in the firewall and when I try to remote to the pc it waits at authenticating for around two or three minutes before I can get a remote desktop. So something else is not working correctly.
If I disable firewall everything working fine. No delay when remoting in. The remote pc is a special purpose machine which only have sep firewall on it no other components. Only certain traffic will be allowed and all else is denied. It is unmanaged obviously.
persistance de Trojan.Dropper parc informatique
Bonjour,
Je suis en train de faire une analyse compléte pour les PC de mon parc informatique avec symantec client alors je procéde comme suit:
1- j'isole le PC cible du réseau
2- j'effectue une analyse compléte
3-Si symantec détecte toujours des fichiers infecté j'effectue une autre analyse en mode sans echec
4- Finalement je vérifie la base de registre du système en se référrant aux technical details relative à chaque virus
Aprés avoir effectuer les étape mentionné ci-dessus la majorité des threat sont éliminés (Bloodhound.Exploit.343, W32.Sality.AE, Backdoor.Trojan) mais il y a toujours le trojan Trojan.Dropper qui est détecté par Auto-Protect.
Je voulais savoir si il y a un tool particulier pour traiter ce genre de Trojan ou bien une méthode particuliere.
Merci d'avance pour votre aide.
Cordialement,
Installing Symantec Endpoint Protection
I am getting this error as I am trying to install Symantec Endpoint protection 11.0
"To continue the installation, make sure that the Internet Information Services (IIS) World Wide Web Publishing Service (W3SVC) is installed and running. On computers that run IIS 7.0 or later, the following IIS role services must alsobe installed: ASP.NET, CGI, and IIS 6.0 Management Compatibility."
I do not know how to check to see that these things are installed or running.
Thanks.
SEPM L1/L2 interview
Anyone have SEPM L1/L2 interview related question and answer for prepation?
track the USB
any possibility to track the USB throughout symantec endpoint management server.
ADC policy is configured. If it is possible then please share the steps.
thanks in advance.
Presentation
I have to represent the following things to our clients. please help me with power point documents or any other documents ( slide show,screenshot etc) . Please............
- Current infrastructure for SEP (both H/W and VM)
- Dependency/Challenge with existing infrastructure
- SEP Migration for version up gradation (from 11.x to 12.x)
- Any challenge from SEP end for endpoint that are under VM environment
- Minimum recommended server configuration for SEP (need clear proof/reference document from Symantec)
- Support matrix (with detail workflow diagram mentioning activity escalation flow to Symantec)
- AOB
Going from Symantec Endpoint Unmanaged to Using SEP Management Console
We currently have Symantec installed on each workstation unmanaged and would like to purchase, install, implement Symantec Mangement Console. What would be the best way to accomplish this? Can we simply install the management console and have the existing client converted to being managed?