Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

What's everyone using SEP fw for?

$
0
0
I do not need a solution (just sharing information)

I'm curious if anyone can share what they're using the SEP firewall for? The default rules are pretty basic and relaxed in 12.1. In testing, I've added a "Deny_all" rule as the last rule and a lot is blocked and my machine is bascially unable to function on a domain network.

Was wondering if anyone can share some thoughts or ideas on using the fw to lock down an environment yet still be able to function properly.

Thanks for reading. Any feedback is greatly appreciated.


SEP 12.1 RU2 no definition reporting

$
0
0
I need a solution

This is a clean installation of SEPM 12.1 RU2 on Windows 2008 R2 Standard Edition. All 25 test-clients including local SEP 12.1 RU2 installation fail to report to SEPM about their definition-status. There is no problem when I look on the SEP client itself, the definitions update through SEPM when in-house and through LiveUpdate when out-of-office. The SEP clients also fail to report last-scan status. All other reporting and communication seems to be ok though...

I have tried re-installing some clients and used sylink-drop on a few but neither helped.

 

Please help!

SEP Clients not connecting to SEPM.

$
0
0
I need a solution

I have approximately 700 systems in my organization. A few hundred of these systems are reporting as offline when I personally confirmed on the client itself that they are online, and convinced that they are connected and reporting to the right server.

We run Vist 32-bit and Win 7 32-bit. The vista systems are connecting without issues. 90% of the Win 7 systems are not.

I have tested replacing the sylink.xml file and connecting on the client through help - troubleshooting - connection status that solved nothing.

I have rebuilt the server, several times. I even rebuilt it and manually installed each of the 700 systems. That also solved nothing.

I have tried SEPM with an embedded database and with an SQL database. Neither made a difference. Currently we are remaining on the SQL database.

I have verified connections to the database and it works, which makes sense because all the vista systems are working.

I have tried installing SEP 12.1.1000.157, SEP 12.1.1101.401, SEP 12.1.2015.2015 and none of the successfully report.

Ghosting these systems is not feasible as there must be an actual solution and I cannot insist that a few hundred systems get rebuilt.

I have tried every solution in the SEP Clients Not Connecting  technical solutions page that Symantec put out.

I have tested the network and there are no issues within it that I can find.

I have tried linking it through active directory and it is still not locating those few hundred that are online, it is still linked to Active Directory.

I turned debugging on for one of the systems and returned this one interesting tidbit in the log:

2013/01/02 11:45:06.980 [3144:2388] <mfn_PostApplication>===SEND EVENT_SERVER_REQUIRES_CLIENT_APPLEARNING ===
2013/01/02 11:45:08.010 [3144:2388] AH: Setting the Browser Session end option & Resetting the URL session ..
2013/01/02 11:45:08.774 [3144:2388] <ParseHTTPStatusCode:>468=>468 Request not allowed<ParseHTTPStatusCode:>468=>468 Request not allowed

Also, my SEPM is currently 12.1.2015.2015 and this has been an issue even when it was on all the other versions listed above.

Looking for a solution. Thank you.
 

8147021
1357157679

Manually Managed Endpoint Protection Not Updating

$
0
0
I need a solution

I have Endpoint Protection 12.1 and it fails to update. I have no clue where to begin.

SEP user mode not switching users

$
0
0
I need a solution

We have all of our endpoints setup as user mode in order to deploy USB device restrictions, what we have recently noticed is that when a user is logged on, then logs off, and another user logs in SEP does not notice there has been a change of users and the active policy continues to be the policy of the first user.  The only way we have managed for SEP to recognize the change of user is by opening the SEP client from the task bar.  We have the clients require a password to open so as long as the user reaches the password prompt SEP recognizes the new user.  Without opening the client it remains as the old user even if a policy update is performed.  Anyone else experience this?  We are currently on 12.1 RU1.

Trying to make an exception to a folder in a user's windows account

$
0
0
I need a solution

I need to make an exception to my user's Google drive sync folder in SEP12. This folder is located by default in c:\User\username\Google Drive where username is the user's ID. I don't see the prefix variable for user directories, and I cannot use wildcards. Is there something I am missing here?

 

 

 

Live Update

$
0
0
I need a solution

Hello,

We have a problem on our SEPM , when we are going to start the luall.exe to download the definition , the process comlete successfully without error.

but nothing reflected on clients side. I couldn't find the new updates on these clients.

when I download the def. manually (jdb) file, and put it on the following path "C:\Program Files (x86)\Symantec\Symantec Endpoint Protection Manager\data\inbox\content\incoming"

I received an error in the same jdb and its name becomes as the following:

vd3c4228.jdb.err

I have SEPM 12.1 on windows server 2008 R2

Sep client service problem

$
0
0
I need a solution

Hello

I have a problem that when I'm trying to stop the client service, it doesn't ask for a password requirement despite the fact I've defined in sepm to require that

Can please somebody help me?


Linux endpoint protection

$
0
0
I need a solution

Hello everyone

I've over the last few days been fighting with Symantec endpoint protection manager.

And it is starting to take alot more time then expected in first place, and i really just want the solution now, after been googling alot without getting any clear solution.

 

So now im writing in hope of ya guys might be able to help.

Im trying to add the Linux package to the Protection manager, but when i do i get the error, Sylink.xml file is missing or corrupted in this package. But the funny thing is, there is no sylink.xml file in that zip file, not even when just downloaded from the site.

I read on a forum, that upgrading to the newest version of the protection manager would help, right now we are running on 12.1.1101.401, and the package i am trying to add is 12.1.2, can this be the reason why it isnt working?

 

Or is there something else?

Any help is appriciated,

Greetings

Mathias

DWH Files in Quantine

$
0
0
I need a solution

I was running into these issues with SEP 11, so I upgraded to SEP 12.1.2015.2015 and they are reappearing again. When I delete them they keep reappearing. I have looked through the various discussions started on this issue, and it always seemed as though it was fixed in previous versions with a new patch. Does anyone have a solution for 12?

Can/does SEP 11.0.5 collect detailed scan info (files)?

$
0
0
I need a solution

I can't find this info and a manager wants to know if a scheduled antivirus scan with SEP 11.0.5 logs every single file that it scans and if not, is that a configurable option, for troubleshooting?

Thanks,
Mark

8156621
1357317737

Symantec Endpoint Protection 12.1RU2, scans and finds threat in svchost.exe

$
0
0
I need a solution

We are having problems with some of our computers and I am trying to track down the exact cause and in doing so I ran across some things in the event logs of several computers that should not be there.  We are running SEP server and clients 12.1.2, Server 2008 R2 and Windows 7 Enterprise 64Bit clients. 
Every since we upgraded to this version, one by one people have complained that Outlook keeps locking up on them and other strange thing have happened like the machines will not get past the log off screen when they shutdown.  One computer will not show the Username and password fields for about 10-20 minutes after CTRL-ALT-DLT.  PS..We also deployed SEE Device Control and Removable Storage at the same time. 

1st,  I found this:  Security Risk Found!Hosts File Change in File: c:\windows\system32\svchost.exe by: SONAR scan.  Action: Leave Alone succeeded.  Action Description: The file was left unchanged. (application logs)  
This is showing up on a lot of machines so I don't think it is a virus. 

2nd I found this(could be another application other than SEP):  The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 

{69B37063-2BB6-43B5-A109-60E69A77840F}
 and APPID 
{CD11FAB6-1C0E-45E1-BA31-5C6008EF2607}
 to the user domain/username SID (S-1-5-21-790525478-920026266-842925246-8650) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
I am not sure where this APPID is.  I went through all of them and could not find the one with this APPID or CLSID.  
 
Any info will be greatly appreciated. 
 
8157161
1357333967

How to install SEPclient via GPO without msi package?

$
0
0
I need a solution

Hi everybody,

I've been searching for ways to install SEP clientes on almost 2000 desktops (XP and 7 mixed) in the past two weeks.
The problem here is that all these 2000 desktops have McAfee Enterprise installed, so I need to uninstall it before installing SEP.
This issue was solved by using SEPprep, exporting the package as multiple files, preparing sepprep.ini, renaming setup to sepsetup.exe and copy sepprep.exe over setup.exe. OK, it worked fine, but along all the desktops, at some branch offices many of them are turned off for weeks, maybe months and got ocasionally turned on by its users.

So, I need three deployment options:

1. Deploy using Deployment wizard in the main office where the SEP Manager is installed on a local server using the SEPpreped package. Done!
2. Deploy using PushDeploymentWizard in the branch offices to eliminate traffic between WAN links due to client package transfer. Done!
3. Deploy on demand using GPO in branch offices where the computers are always turned off and often turned on by its users. Not done...

So, my problem now is GPO deploy. These were the methods I tried:

1. Software deployment using setup.MSI file inside the exported package. This worked fine but when you use the setup.msi, it won't call the sepprep, so it won't uninstall the McAfee AV before. Ended with two AV installed. Not a suitable solution.

2. Tried to write a batch script and use it as startup script.

This is the script:

echo off
IF %PROCESSOR_ARCHITECTURE% == x86 (
GOTO Bit32
) else (
GOTO Bit64
)
 
:Bit32
Echo "This is 32 Bit Operating system" >> c:\temp\install32.log
reg query "HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection"
if %errorlevel% == 0 ( goto exit )
\\fs1\netlogon\runas.exe -u domain\username -p password \\fs1\netlogon\32bits-SEPprep\setup.exe
goto exit
 
:Bit64
Echo "This is 64 Bit Operating System" >> c:\temp\install64.log
reg query "HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection"
if %errorlevel% == 0 ( goto exit )
\\fs1\netlogon\runas.exe -u domain\username -p password \\fs1\netlogon\64bits-SEPprep\setup.exe
:exit
 
echo END

FS1 is my ad server. This worked almost perfectly, besides the fact that I would have a security issue by having an admin password in plain text inside a wide open file share like netlogon. The runas is a runas alternative that allow storing password at command line, not the windows runas.

So, I went after other tools that could allow to encrypt passwords within the command line. None of them worked when called from a startup script via GPO. Tried CPAU, lsrunas, runasspc. I edited the script above to only execute setup.exe without runas thing, wrote a second script named callinstall.bat with these lines below and set it as startup script:

echo off
\\fs1\netlogon\cpau.exe -dec -file \\fs1\netlogon\instalasep.job -lwp **** (this job is configured to execute in c:\temp, that is mandatory when using UNC paths) ****
exit

This job file contains a command line that calls the main script (the one that executes setup.exe) with administrative credentials, so it has to work. But no.
This not worked as startup script, when the OS startup nothing happens. It shows the CTRL+ALT+DEL too early and after logon I can't see any setup.exe or msiexec.exe running at task manager.

So, If I go to \\fs1\netlogon\ myself and execute callinstall.bat it will them provide the admin credentials, call the main script, detect the architecture (32 or 64) and setup SEP pretty well. The desktop computers are in the correct OU inside the AD users and computers and the GPO is linked correctly to this OU. Its worth to say that this problem seems to be particular to Windows 7 desktops. Windows XP work fine even if I set main batch script without runas or cpau command.

Really don't know what to do. It's driving me crazy.
Please help.

 

Henrique
 

Is SEP causing this change in ping behavior?

$
0
0
I need a solution

We updated from 12.1.14 or .11 to 12.1.2 about a month ago.  Maybe it was that or a recent update of another kind.

A simple ping is behaving differently.

Before I got...

Destination port unreachable.        after sending a ping to a machine that's not on.

 

Now/today I get...

Reply from (my local computer's ip address): Destination host unreachable.

 

Nothing with Windows updates.  We've figured that out.

Two computers without SEP on it behave the old/normal way

One comupter without SEP gives me the old/normal ping results from I ping from another comupter and the targe/non-SEP computer is off.  Weird.

 

All the computers are on our subnet.  I'm wondering what's changed recently.  We used to have 'dest port unreachable.'  I have read several pages online that say if it's on your subnet, it's only one hop, and the pinging computer knows the device isn't there and just displays 'dest host unreachable.'

 

It's a problem because I've got several batch files monitoring machines.  If it's on, it pings back and error level is 0.  Today if it's off, I get 'dest host unreach' and still the error level is 0.  The batch file responds as if it were on.  The old way gave me either a time out (which I read shouldn't happen, but it was and that's ok) or a 'dest port unreachable' with an error level of 1.  That was fine.  I used the error state, 0 or 1, to control whether alerts are sent out, etc. 

 

 

Is anyone else using SEP having issues with pings not working 'normally?'

 

Dectecting Unmanaged Devices

$
0
0
I need a solution

For my SEP 12.1 RU2 environment, I'm not getting any results in the Unknown Device list. I have followed Symantec documentation to enable a Managed Detector, and set up notifications. However, on the main SEP Manager console page, under details, I have yet to see any Unknown Devices. And I know there are at least a couple out there. Any suggestions on how to troubleshoot, or what I may be missing? Thanks! 


ips on server

$
0
0
I need a solution

Can we install ips on server?

sep components on server

$
0
0
I need a solution

Can we install all components on server?

SEP 12.x Client and Proxy Server

$
0
0
I need a solution

Is getting a SEP 12 client to work (unmanaged and goes through a Blue Coat proxy server) more of a challenge than with SEP 11?  Even with all of the proxy server URL exceptions specified in TECH162286, it appears every 12.x version I've tried thus far has difficulties downloading anything via LiveUpdate beyond the catalog listing.

For newer versions like the latest SEP 12.1.2, I usually first install an unmanaged client on a test VM to see how things go.  The 12.x client not being able to update its virus defs from the get-go is very disconcerting to me.  In contrast, unmanaged SEP 11 clients required no modifications on our proxy servers and worked straight off to get their virus defs.  Yah...I'm still running SEP 11.0.5 in our environment and was hoping to upgrade to 12.1.2 since it's supposedly compatible with Win8 but this issue just makes me lose confidence in going further.

If an unmanaged SEP 12.x client has difficulties getting its virus defs, I wonder if the SEPM server will do any better?  I would think many of you are running behind proxy servers for Internet access so figured I must be missing something in our environment.  Just can't figure out what.

After installation of SEP client are showing corruption of Definition

$
0
0
I need a solution

Hello Frndz,

I have installed SEP 12.2 succesfully, after installation all clients having issue they r getting definition corupption or missing issue.

Can any one help me urgently..

No internet access

$
0
0
I need a solution

Hi,

 

Inorder to completely uninstall Symantec Antivirus for installing newer version , i used Cleanwipe tool as recommended by Symantec. The Symantec Antivirus was uninstalled succesfully but now there is no network connection. The ip address has been set properly but unable to access internet from that node. Please suggest.

 

Regards,

Anish

Viewing all 10484 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>