Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

SEP 14 - Testing Generic Exploit Mitigation

$
0
0
I need a solution
Hello,
I am working on a user acceptance test for a customer.
 
Are there any tests that I can run to test the generic exploit mitigation functionality in the SEP 14 client?
 
Cheers
Cameron Mottus
0

Upgrading SEPM 12.1 to 14

$
0
0
I need a solution

Hi everyone,

Somebody can help me please?, currently i have SEPM 12.1 RU6 MP7 but i want to upgrade to version 14, but i wondering if there is not some problem because I have some clients with version 11.x

0

Sylink file

$
0
0
I need a solution

Hi,

Situation is there are communication problem on sub OU example on Workstations.

What we will do is to export the sylink on Workstations OU.

Question on exporting Sylink can we do it on Admins or even the parent OU which is the A(cover with whitebox)?

Does it affect the policies (blocking of USB/GUPs setup/etc) if we will do it on Parent OU rather than specific OU?

0
1496694900

12.1.6 MP8 Install failure: "A digitally signed driver is required"

$
0
0
I need a solution

I'm attempting to install MP8 on a Win10 (anniversary update) machine, and I'm getting the following two pop ups:

SEP Install Error.JPG

Sadly, the install will not complete, and keeps asking for a reboot (yellow excalmation on the shield). I checked the install log, and no "Return value 3".

Seems like this a Microsoft issue, so I temporarily disabled the requirement for driver signing...no change.

Did I miss a memo somewhere?

Thanks,

-Mike

0

Device Control issue with Device IDs different between Windows 7 and Windows 10

$
0
0
I need a solution

Everyone,

I am trying to implement a Device Control policy (on SEP 14 MP1) to block all USB Mass Storage devices. While I have it mostly working I have come across a small issue.

In my policy I am blocking USBSTOR*

Clients are a mix of Windows 7 and Windows 10 (as well as some Macs but that is another issue for a separate forum post).

During my testing I inserted a Seagate USB Drive and it was not blocked on the Windows 10 laptop but it was on the Windows 7 laptop.

DevViewer on Windows 7

[guid]: {4d36e967-e325-11ce-bfc1-08002be10318}
[device id]: USBSTOR\DISK&VEN_SEAGATE&PROD_EXPANSION&REV_0707\NA866CZF&0

DevViewer on Windows 10

[guid]: {4d36e967-e325-11ce-bfc1-08002be10318}
[device id]: SCSI\DISK&VEN_SEAGATE&PROD_EXPANSION\000000

Why are the Device IDs different between the Windows versions and is there an easy way around this? 

Regards

Dean

0

How to enable "Disabling SEP" - when logged in SEP Client?

$
0
0
I need a solution

Hi!

How to enable the "Disabling SEP" option, only for users logged in?

Right-click shield > Open "SEP"> Type password > Disable "SEP"

or

Right-click shield > Disable "SEP"> Type password

?

0

Need to download SEP 14 for testing

$
0
0
I need a solution

Hi All. I need to download SEP14 so i can put it on a test server. At the moment we use 12.1.X. Is there a full functioning time limited version available at all for SEP14? Any download links etc. I have Symantec flex but that will only allow me access to versikon 12.1.X

Cheers

PaulC

0
1496762311

SEPM 12.X to SEPM 14.X On new Server

$
0
0
I need a solution

Hello, 

I am trying to upgrade SEPM 12.X on Windows 2008 32-bit to SEPM 14.X on a new server running Windows 2016. Can someone provide how-to please? 

Thanks!

0

Windows XP and Windows 7 clients not getting update from SEPM

$
0
0
I need a solution

Most SEP clients update the definitions as expected but a few hundred clients (windows XP and windows 7)won't update at all.

SEPM and client version:12.1 RU6 MP5

Trouble Shooting so far:

  1. Clearing corrupt defs as described in this artical:     

    http://www.symantec.com/business/support/index?page=content&id=TECH103176&locale=en_US#

  2. Restart the SMC (smc -stop...)
  3. Uninstall and reinstall SEP client manually
  4. Unistall SEP client then push out SEP client from SEPM 

After performed above steps,issue has been resolved but practically it is not possible to perfom this steps on each client system.

Please help,around 102 sep clients (windows XP and windows 7) are out of date showing error visrus definitions are coruupted or missing.

0

Perform Live Update remotely

$
0
0
I need a solution

How can I perform LiveUpdate remotely to large number of clients?

0

Insecure Browser Setting

$
0
0
I need a solution

I was asked about a security setting in IE this morning: Access data sources across domains is Enabled by GPO it appears. In doing a bit of research, there was a blurb about that setting being required by Symantec Endpoint. Is that still the cases?

https://www.securitysift.com/cross-origin-request-forgery-pt-2-exploiting-browser-security/

You might say “If same-origin/cross-domain security is such a fundamental component of today’s web security why would anyone enable this setting?”  For starters, there are several enterprise products that may require this security setting to prevent errors, including IT Analytics for Symantec Endpoint Protection, LexisNexis Pay@Work, IBM Tivoli, Oracle’s Siebel Business Analytics, and others. 

0

Cannot open SEPM

$
0
0
I need a solution

Hi,

I did Migrate from SEPM 12 to 14, i restore DB from SEPM 12 to SEPM 14 and run well, but after some days, i cannot enter SEPM even with admin. anybody know how i enter SEPM 14

0

Any limitations to upgrade path for SEP 14.2?

$
0
0
I need a solution

I see SEP ver 14.2 is out now.

https://support.symantec.com/en_US/article.TECH154...

Most of my users are on 12.1.7061.6600.

Some are still on 12.1.6168.6000. but that's the earliest.

Are there any limitations for the upgrade path to ver 14.2 in terms of upgrading either ver 12 type to ver 14.2?    I'm wondering if these 12.1.6168.6000 machines can go straight to ver 14.2 or if they have to be upgraded to 12.1.7 or maybe 14.1 first, and then on to ver 14.2.

0

Scanning on BIOS level

$
0
0
I need a solution

Hi Guys,

May I know if SymDiag/Threat analysis tool can do scanning BIOS level on workstation.

Or does Symantec have a specific tool to scan BIOS level of a workstation.

Thanks!

0

Windows Firewall and SEP are both turned off message on Windows 10

$
0
0
I need a solution

Hello all,

We found following issue (or maybe fake alarm) on Windows 10 machines only. When user login to the machine following popups appear (on some machines firstone  on some other second one):

2017-06-07_10h51_12.png

2017-06-07_10h51_43_0.png

As you may see SEP is working ok (with green dot), so it seems like a fake alarm. 

We use SEP version 12.1.6 MP5. We have full package installed on or machines: with Proactive Threat Protection and Network Threat Protection (including firewall and IPS). 

Have anyone saw this popups and know why they appear if SEP is working properly? Does someone know how to fix it to not show this messages to our users?

thanks in advance 

Best regards

0

SEPM 14 MP2 forcing reboots

$
0
0
I need a solution

Hi All, 

Just upgraded our SEPM 14 console from 14.0.1904.0000 to 14.0.2415.0200

As soon as the update was complete it started pushing out the old 14.0.1904.0000 client to all of our servers (which they already have installed) causing them all to want to reboot. 

Has anyone come across this behavior before? is this something off with our setup? or something I missed in the documentation about MP2 pushing out any available install packages as soon as it's installed? 

Does anyone know how to stop a forced SEP reboot? 

Appreciate any thoughts! 

0

disable email alerts for a specific client

$
0
0
I need a solution

Hi

we are a software company that tests malware.

we have symantec endpoint protection installed on all of our windows clients, some also install on station that we always downloading viruses and malwares for testing purposes. for this stations i want to disable the email alerts that sent from "symantec endpoint protection manager" with the title "new risk found"

how can i acomplish that?

0

WiFi Hot Spot Registration Mode with SEP

$
0
0
I need a solution

Hi,

I have a SEP 12.x setup with multiple loacations.  When devices are off the corporate network the are in the exteral location.  The firewall is enabled within NTP and this blocks inbound and outbound connections with a few exceptions.  In order to allow users to be able to register to open wireless networks at hotels, airports etc. I have given users the ability to disable the firewall within the SEP GUI but this is just to difficult for some users so I am looking for an easier way.

I tried creating a script to use SMC.exe -disable -ntp but this requires the users to have admin rights in order to complete which they dont have.

Has anyone any other work arounds for this?  Is there a location rule where if the device is external and cannot talk to the internet then the firewall is disabled but when the internet is detected (after they log into the WiFi portal) then the firewall will enabe itself.

Thanks

0

SEP 14 MP2 Win 10 client error

$
0
0
I need a solution

Hi im am running into errors while installing SEP14 MP2 client on a windows 10 computer after creator's update. Error message was "Symantec endpoint protection dosen't work on this version of computer, An update might be required"

i've did some researched online and per suggest device guard for windows 10 is the culprit, i've since disable it but still showing up same error.

any comments might be helpful.

thanks.

0

SEP Client Definitions gets corrupted frerquently

$
0
0
I need a solution

Good Morning,

There is an issue on some of the server machines, where the virus definitions get corrupted frequently, due to which the clients on the server machine stop downloading defiitions from Live Update Administrator Server, GUP and SEPM.

However if we repair the client on the Server machine it starts taking update for some days and then again the same issue persist. Servers include 2000/2003/2008/2012.

Please can anyone provide a permanent solution for this issue, as repairing clients everytime is not possible.

Thanks and Regards.

0
Viewing all 10484 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>