Unable to login SEPM via AD authenticaion post 14.2 RU1 upgrade, where as SEPM authentication is working fine.
Unable to login SEPM via AD authentication post 14.2 RU1 upgrade
Bluekeep RDP
Hello,
Do Symantec deffinitions protect aganst Bluekeep RDP ?
Remove Install Packages from all Groups?
Hello All,
Is there a way to easily remove the client install packages from all groups? Or does it require clicking on each group and deleting the install package?
I am at a loss: SEP client gets 404 when connecting to the manager
cve.log debug output:
[2019-Jun-06 18:27:39.405925] [DEBUG] Loading data.
[2019-Jun-06 18:27:39.405925] [DEBUG] Loading data.
[2019-Jun-06 18:27:39.405925] [DEBUG] Attempting connection to server $MANAGER
[2019-Jun-06 18:27:39.405925] [INFO ] CallOneServer: Heartbeat pass <1> for $MANAGER
[2019-Jun-06 18:27:39.405925] [DEBUG] Heartbeat status: [complete: false] [successful: false]
[2019-Jun-06 18:27:39.405925] [DEBUG] Attempting to get Index2.xml file.
[2019-Jun-06 18:27:39.405925] [DEBUG] Current syed while downloading ssstem proxy is:
[2019-Jun-06 18:27:39.405925] [DEBUG] Setting CURL to use system proxy =
[2019-Jun-06 18:28:00.687198] [DEBUG] Interruptction=12&hostid=$HOSTID&chk=$CHK&ck=$CK&uchk=$UCHK&uck=$UCK&hid=$HID&groupid=$GROUPID&ClientProductVersion=14.2.3332.1000&mode=0&hbt=600&as=4770&cn=[hex]$CN&lun=[hex]$LUN&udn=[hex]$UDN
Downloaded 0 and uploaded 0 bytes.
I have tried pushing a new syslink from the SEPM, using the import function from the troubleshooting menu, and using syslinkdrop program, no joy.
In the past, reimporting the syslink was enough to restore the connection, but not this time. I'm about ready to just do a nuke and repave on the clients that are having this problem, but would like to avoid the hassle of scheduling the downtime to do so.
Any ideas?
SEPM 14.x support Linux?
Hi all,
In the past the only way to recive virus signatures for Linux machine in using LU. Is this still the case with SEPM14.x ?
Do you still need LU?
GoldBrute Botnet Brute
Hello everyone,
Does SEP protect against this? Thanks
https://isc.sans.edu/forums/diary/GoldBrute+Botnet+Brute+Forcing+15+Million+RDP+Servers/25002/
Auto Protect Malfunctioning
hello everyone,
I have an issue with installing SEP Client on Linux .
as you can see I'm using CentOS 7.4 with kernel 3.10.0-693.el7.x86_64 , which according to the following article , is a valid kernel to install SEP Client on it :
https://support.symantec.com/en_US/article.INFO3983.html
the problem is when i install SEP Client on my linux , everything seems to work fine except Auto-Protect :
so i googled the issue , and found out that i have to complie the auto-protect files manually , so i tried it according to symantec article on the following link :
https://support.symantec.com/en_US/article.TECH132773.html
but i got another error :
so is there anyway to findout the problem ?
thanks in advance
Query Whitelisted Devices from Application device and conrol
Is there a way we could query the whitelisted devices aligned with computer names and group they are belong to?
Currently we have 8000+ clients and 100+ whitelisted devices.
We just want to generate a report that includes Computer Name , Log in user, Group Name and whitelisted devices.
Thank you!
Out-of-Date Clients Triggering Notification
On occassion we will have some clients either get stuck during a scan or the clients laptop is just turned off while they are on vacation and we will get an out of date client notification email. In the email it shows the computer, virus def and last download. I'm curious, what is the last download column represent. For instance, the vrus def date will show 5/31/19, but the last download column shows 2/05/19 so I'm just trying to figure out what this means. I'm going to upgarde the clients to the latest 14.2 because they are on 14.0 MP1 and apparently this is being caused by a bug (https://support.symantec.com/en_US/article.TECH235075.html), but I still would like to know what the last download column represents.
Application and device control, Blocking/terminating process attempts
Hi all,
We have got some file names and corresponding hash values to be blocked in our SEPM server. We have configured the same under Policies -> Application & Device Control -> Application Controls -> Application Control Rule Sets -> Add Application Control Rule Set -> Add Condition -> Terminate Process Lauch Attempts and then adding the hash values and File names under it.
We have even a set a message to be displayed under "actions" to notify user while attempting the same. But neither are we getting message nor the policy seems to work. Can you please guide us whether we are doing it correctly.
Regards,
Anishk
File Reputation Alerts - From months ago being reported today
I have been working with Symantec support on an explanation and resolution for seeing repuation alerts from months ago on alerts we receive for present day's alerts.
When checking the clients that reported issues from months ago, they are currently not having issues with File Reputation lookups and are completing these successfully.
My question is why are we seeing these alerts from the past and if they clients are performing these successfully, why are they even on the report?
Anyone having this same issue?
SEPM 14 reports Out of Date, yet Client is up to date.....
Good day!
We've recently update our SEPM to new version to 14.2 RU1, hoping to get fix our dashboard reporting "out of date" SEP client yet they're up to date...
Some "out of date" SEP Client are in "up to date".....
By the way we're in a secured environment (no internet).... so updates are being downloaded as *.jdb, later on uploaded via SEPM "incoming" folder.
We've remote site's, and per sites have configure 2 server's as GUP's..... updates are being propagate well.....Clients are updated.
The main problem is, I'm getting error of reporting.....
What I can only provide is printed, then scanned screen shots.....
I guess & hope, somebody have already passed & fix this issue....
In advance, thank you!
RonS of LARES
Bloquer un site web spécifique
Bonjour
j' aimerai savoir comment faire pour bloquer l' accès à youtube et facebook grace à la console SEPM 14
merci
SEPM 14.2 RU1 Not Updating Definations
hello everyone, I have a SEPM 14.2 RU1 which is not updating the definations since last month. I am attatching the log.liveupdate file and the output which I get when I try to run luall.exe manually.
Can you please tell me what is the cause and how can I fix this? Thanks
SEP blocking internet access on a single machine
SEP is blocking internet access on every browser/application on a single machine. It doesnt give me any error message or warning, internet simply doesn't work when the protection is active. I tried to check all the network and hosVersion 14t rules with another pc on wich internet is working just fine but all the settings are the same. Version 14 (14.0 RU1) build 3752 (14.0.3752.1000). Any idea on how to solve this?
How to locate the .slf file for download
Dear Members,
I bought a licence for the renewal of our SERP 14.0 and upon reactivating the new seria key, the process is asking for the .slf file which i didnt have as the the new seria key didnt come in a pack.
Please where can i downlaod the .slf file from the symantec site or what should i do?
Reply please.
DB Backup during upgrade
During the upgrade of the SEPM, in the wizard we will get an option to backup the database. My understanding is it will backup embedded db only and will not backup anything else. Please correct my understand.
IPv6 db IP_ADDR translation
Hello,
Does anyone know how to translate IP_Addr to readable IPv6 format?. There is a way to translate to readable IPv4 desribed here https://support.symantec.com/en_US/article.TECH175456.html but that doesn't apply to IPv6 and You will get wierd numbers.
XP/Legacy client and SEPM 14...
Greetings..
Cutting to the chase here..
I have 3 SEP environments to manage. One is 14.x, the other 2 are 12.1.x, and we are trying to decomm those. On both old servers, I have XP clients that can't have their OS upgraded due to application support for what they do.
Do I need to install a new SEPM 14 Legacy client to these XP devices, or can I simply send a Comm update and have them report and receive updates from the SEP 14 side with no other client changes?
Thanks..
Cannot find a computer on my console
hi friends, i have a trouble, i have a imac pc with symantec enpoint protection 14.1 and my problem is that i cant fint it on my symantec manager console but if i search on the group that i have create it i can see the pc