Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all 10484 articles
Browse latest View live

Cisco Radius Server Connection issue

$
0
0
I need a solution

Preface – We have deployed CISCO ISE (Radius services) in the Irving Campus (Texas).   CISCO ISE is configured to pre-authenticate devices using 802.1x prior to getting on the wired network.  The client device requirements before getting access on the network is 1. Must be joined to ISC domain, 2. Must have a machine cert trusted by ISE  3. Must be configured to use 802.1x per CISCOs specification (basically authentication configuration on the NIC).

Issue– Since deploying ISE last October, we have random users getting disconnected from the network each day averaging about 5-10 users at one point.  It is very random, the clients somehow loses network connectivity and is unable to re-authenticate with the Radius server.

Troubleshooting– after months of troubleshooting with Cisco and Microsoft, Microsoft recently found in network traces that the EAP request/response from Radius were getting blocked by the DOT3SVC service.  DOT3SVC is the service called “Wired Autoconfiguration” on Windows machine.  This service is responsible for 802.1x authentication.  Microsoft has indicated that this service can be impacted by a filter driver commonly used with Anti Virus software.  SEP Network Threat Protection is running on all client machines.

Symantec Assistance– Please help us with troubleshooting the Symantec portion of this overall issue.  We need help in analyzing the Symantec Network protection logs as it pertains to EAP (802.1x) communication, we need suggestions from Symantec to help capture if Symantec is playing a role in this interruption or not, and also need to see if Symantec has any issues like this in the past that they can share their experience and resolution when deploying SEP with Radius server.

0

Issues after KB4055269 .NET security only update

$
0
0
I need a solution

Environment:  Windows 7 Professional SP1 64-bit, .NET 3.5.1, 4.5.2, SEP 14 MP2

Has anyone noticed any issues with the 2018-01 .NET Security Only Update (or the 2018-01 .NET Rollup)  specifically KB4054172 which is the security patch containted the the 2018-01 .NET Security Update, et. al.?   https://support.microsoft.com/en-us/help/4055269/security-only-update-for-net-framework-3-5-1-4-5-2-4-6-4-6-1-4-6-2-4-7

We don't know as of yet if it impacts SEP 14 MP2.  There is language in the Microsoft KB4055269 referencing the registry entries to be provided by the antivirus vendor similar to that needed to install the Meltdown/Spectre patch in the Windows 2018-01 Security Only (and rollup) for Windows.  We are assuming that the potential is there to cause issues with the .NET patch like the Windows Meltdown/Spectre patch(es).

The current issue that we have specifically is that after installing KB4054172 a machine won't successfully RESTART.  It will go through Logoff and Shutdown and then go dormant, like it was in Sleep mode, but unable to wake up.  The only way to revive a machine is to manually power it off and back on.  We've checked the KB4054172 install logs and don't see any installation errors.

We are unaware of any SEP issues at this point.  We stopped pushing out the .NET maintenance until we can figure out what's going on.

KB4056897 containing the Meltdown and Spectre patch is installed with no apparent issues, SEP 14 MP2 or otherwise.

0

Bigfix VS SEP

$
0
0
I need a solution

Hi All,

have a 2008 r2 server with SEP and bigfix for Patch management.

SEP tamper protection is advising bigfix is trying to modify SEP processes and is blocking it, is this normal? has anyone had this experience?

im trying to find out from the BigFix admin to make sure the AV component isnt turned on.

0

SEP 14 Compatibility

$
0
0
I need a solution

Need some clarification if SEP 14 would be supported on the below Os?

Windows 7 Enterprise Edition
Windows 7 Professional Edition
Windows 7 Ultimate Edition
Windows 8.1 Professional Edition
collapse;width:227pt" width="303">
Windows Server 2015 Standard Edition
0

Attack: Data Execution Protection - Execution of Non-Executable Memory

$
0
0
I need a solution

Hi Team

With SEP 14 RU 1 a group of computers is showing the following event: "Detected Attack: Data Execution Protection - Execution of Non-Executable Memory, SEP will terminate ... and the applications are iexplorer or  java.

Based on the description provided by Symantec at Security Response Attack Signatures I have the following doubts in terms of event response.

1. The event is reoccurring frequently but the logs just shows the application name so how the IT Security Team could identify the root cause and try to avoid future events like that?

2. How could be identified a false positive?

Best Regards

0

Change Blocking traffic interval for Intrusion prevention detected

$
0
0
I need a solution

If an Intrusion prevention threat detected on a client, it blocks the traffic coming from this IP address for a time interval (10 minutes a i think). 

i need to know if this time interval is adjustable or not? i.e. block traffic for 3 minutes instead of 10 minutes

is it possible ?

0

finding the software files for excluding WebEx, GoToMeeting, etc.??

$
0
0
I need a solution

This highlighted policy, IF it is activated and enabled, is preventing people from using WebEx, GoToMeeting, etc.

Does anyone know the names of the executables that I must *exclude* from this policy?? for these kinds of applications??

Or any "easy" way to find them??

We don't have time or ability to wait for people to find out that WebEx does not work, then work backwards to figure out how to enable it. 

Thank you, Tom

App Control Policies
Caption

0

Migrating SEPM to another server, with remote database

$
0
0
I need a solution

Hi all,

we are running SEPM 14 RU1 in a Windows 2008 R2 server, with a remote database in a SQL Server 2016. Our plan is to 'refresh' the OS of the SEPM server to Windows Server 2012 or 2016, installing the same SEPM version on it. Since they are virtual machines, I think my wintel colleagues will create a new instance of Windows Server 2016 with a different hostname and different IP for the new SEPM to be installed on it, and when the migration is completed, the old one will be decommissioned.

I found this article: https://www.symantec.com/connect/articles/how-move-sepm-one-server-another-server  , the point 3.2 looks suitable for our case, but it deals with embedded database, not a remote database. How to proceed in our case? Is there any specific actions or measures having into account the remote database?. I do not know if using the recovery file, I still need to provide some database information during the installation process.

Cheers!

0

Installing in User mode, or change once AD synchronised

$
0
0
I need a solution

I'm trialing SEP as a potential replacement for our current system, and have a quick query regarding the change from Computer to User mode.

Once I've imported an OU from AD, I am unable to change the endpoints to User mode; is there a way around this, or is there a way of installing the client so that it defaults to User mode?  For my current installation I could just delete the AD directories and change the client mode, but I'm considering how new clients will be handled down the line.

Cheers in advance!

0
1519405682

SEP Intrusion Prevention Policy block false positive traffic

$
0
0
I need a solution

We enabled the the Intrusion and Prevention policy for all the managed client. The problem is that users start to complain about not being able to connect to their home wifi and cannot authenticate to the office wifi, which use a radius server. Also, someone report it blocks ZOOM conference traffic. 

What is the best practices for the Intrusion Prevention? We already added all some common class C IPs, Radius IP, and access points IPs in the Excluded Host list. 

What are my options?

0

Block sites

$
0
0
I need a solution

I need to block multiple sites, does anyone have a list with several social media sites, games?

Is it possible to import list with multiple sites?

Is it possible to put a blocking message? Company logo

0

Migration SEP 12.1.6700 to 14.0.3897

$
0
0
I do not need a solution (just sharing information)

Hello, After a migration of SEPM 12.1.6 MP7 to 14.0.1MP1, I wanted to migrate the sep clients to a newer version (SEP 12.1.6700 to 14.0.3897). When I make the autoupgrade on Windows 10 clients works correctly. On Windows 7 clients, the upgrade doesn't work. the package files is visible in C:\ProgramFiles (x86)\Symantec\Symantec Endpoint Protection\14.0... but nothing is launched in services or in the taskbar. The event viewer also indicates that the source for Symantec Antivirus can't be found.... Could you give me the process to update the packages on the client s ? Best Regards. 

0

Message "There are problems" after changing a policy

$
0
0
I need a solution

After changing an antivirus policy I get the message "There are problems" with red background on all clients affected by this change.

I must avoid this behavior because there isn't any problem, moreover, our notebook are checked by it manager when we go into our customer's network and is not easy to explain them the reason of this message.

0

SEP 14 risk about install without rebooting

$
0
0
I do not need a solution (just sharing information)

Hi all

I'd like to know if is possible to install SEP for installation or upgrade without reboot ASAP.

Are there any problem about stability of the windows system server?

Because the major problem is the rebooting of the system, If I can install quitely and safetly the SEP on server and doing the reboot after 6 months without any BSOD/problem, It will be more easy to patch them.

Maybe it is a standard and very easy question, sorry about it but I can't find a specific article of it.

Any suggestion will be very appreciate.

Thank you.

0

Proxy Pop-up

$
0
0
I need a solution

Hi,

Some of our users are reporting a proxy dialogue box appearing randomly.
Version v14.0.3752.1000

If the users enters their login details the box fails, if they click cancel the box closes and then shows again, you have to click cancel two or three time for the box to be dismissed.

Any idea why we are seeing this box and how can we stop it.

0

Application Inventory - Discovery Process

$
0
0
I need a solution

Hello everyone,

I am in discovery process, I need to prepare application inventory/lists.  Please help me, How to capture this using SEP?

Note: Once I craete applications list used in my orgnization, I will be able to know what type of exceptions I need to create.

Thanks in advance,

Azeem

0

sep 14.1 cloud "unknown reputation"

$
0
0
I need a solution

I am getting a lot (for the few number of pilot systems) of alerts about "unknown reputation" files from the SEP cloud connector that I enabled in SEPM 14.1. We have a ton of vertical vendor software and in house software around here so how should I handle this? Unknown status to me seems vague and meaningless. Why should I not just disable this out of box alert altogether?

0

License Question

$
0
0
I need a solution

My license has expired as of february. We are currently running 12.x and soon will be upgrading to 14 as well.

My question is,

why should i purchase a new license when all my clients and SEPM are getting its definition?

Will there be any impact if i do not renew my license but still continue to use the product? (without upgrade)

0

Possible to configure SEPM v14 for Smart Card access on Windows Server?

$
0
0
I need a solution

This article gives me a little hope, but...

https://support.symantec.com/en_US/article.DOC9334...

... as noted, but... it speaks of using IIS which isn't used with SEPM v12 of v14.  Instead, SEPM uses Apache.

Is it possible to configure my installation to use Smartcard login for an SEPM v14 installation on a Windows Server?  I would sincerely hope so since this is a requirement in my organization, but if not possible, need documentation that would note this "restriction" as well.

0

Cleanwipe unattended execution command line options

$
0
0
I need a solution

Our company previously used Symantec Endpoint protection.  The Symantec uninstaller left pieces of SEPP on around 50% of the workstations.  Microsoft detected the presence of some of the unsupported Symantec EP registry keys/programs/files and would not make the Meltdown/Spectre security patches visible to the affected machines, even though we have a supported AV installed and the QualityCompat registry key is present.

I've used the Symantec "CleanWipe" utility on a few workstations to clean up the items left behind from the Symantec uninstaller.  After running CleanWipe, the workstations were able to see the Microsoft patches.

The problem is I have over 200 workstations that cannot recieve the Microsoft security patches due to fragments of SEPP still being present after the uninstall.

I'm attempting to build a Solarwinds patchmanager package to perform an unattended execution of the CleanWipe utility.  What are the command line options/switches available for an unattended execution?

Dave

0
Viewing all 10484 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>