Quantcast
Channel: Symantec Connect - Products - Discussions
Viewing all 18527 articles
Browse latest View live

restrict users from adding restrictions even though they are local admins on machine

$
0
0
I need a solution

Hi

Is it possible to restrict usrs from making exceptions (files / folders) even though they are local admins on a machine and only allow a few users (AD group) to make exceptions?

ie. we dont want general public to be allowed to make exceptions only deskside team

John

0

SEP: New Clients Slow to Download Virus Definitions

$
0
0
I need a solution

This has been bothering me for a little while.  When I install a client for SEP, it will show that it found the server, but it will take a while for the icon to get the green circle, and in the meantime, it will say it's malfunctioning.  Eventually, it usually will, but it can be anywhere from 5 minutes to an hour (maybe more) before that happens.  From the point of view of my supervisor using SEPM, everything appears to be in good working order once this happens.  What bothers me is that in the debug.log, there are messages saying "ERROR cve.SignIf Verify signature failed."  Running "sav manage -h" triggers more of these messages.

Ideally, I'd like to know a way to get it to a working state faster.  I'd also like to know if the error I'm getting (since it seems to be somewhat connected) is due to anything I'm doing wrong or could be doing differently.

Can anyone help?

0

SEP 14 Question

$
0
0
I need a solution

Does SEP 14 has Anti-Ransomeware Feature?

0

SEPC 22.11.2.7 Removal from Windows Server 2016

$
0
0
I need a solution

Hi there,

I need a bit of a hand from the Symantec experts. I have installed the Symantec Endpoint Protection Cloud agent on a server running Windows Server 2016. I need to remove the app, but I'm having trouble.

I have tried:

  • Removal from Windows Settings - System - Apps & Features - Uninstall. Results in an error message stating "Windows cannot access the specified device, path, or file. You may not have appropriate permissions to access the item.". Screenshot attached. I've checked the file path (as much of it as is shown in the window title), and I have permission to the entire path.The install is only a couple of months old, so it's not as if it's a very old install. Liekwise, the server hasn't had much work in the way of installing or mucking around with things - it's running at a client site, so I deployed the server and set it up for them, and it's just been ticking away ever since with no modifications. 
  • CleanWipe. I've downloaded and run Cleanwipe, and it's completed successfully. Unfortunately the SEPC app is still working perfectly, but it looks like Cleanwipe has removed LiveUpdate. Now the SEPC app is complaining that it can't update. The app itself still seems to be running fine though.
  • CEDAR. I've downloaded CEDAR on the server, but it says it's related to Endpoint Protection Small Business Edition, which I believe is a different product to what has been deployed. 

Being a server, I don't want to leave it in a half-broken state.  

I've googled for further instructions, but all the manual-removal KB articles seem to relate to SEP ver 12.x - considerably earlier than the current version. The other articles I've found only reference Windows Server 2008 or 2012, or Windows 7, 8, or 10.

Can anyone give me some advice as to how best to proceed? 

Thanks in advance for helping out. I appreciate it. 

Cheers,

Matt

0

....messagelabs.com Connection timed out

$
0
0
I need a solution

Hello,

like some others, I have a problem with messaging via messagelabs.com.
 

connect to cluster1.eu.messagelabs.com[193.109.254.67]:25: Connection timed out
connect to cluster2a.eu.messagelabs.com[85.158.139.103]:25: Connection timed out
connect to cluster3.eu.messagelabs.com[85.158.137.67]:25: Connection timed out
connect to cluster4a.eu.messagelabs.com[85.158.139.103]:25: Connection timed out
connect to cluster8.eu.messagelabs.com[85.158.140.211]:25: Connection timed out

Our mailserver with IP 138.201.200.181 is not on the blacklist.
What can i do to resolve this problem?

regards Ralf

0

ProxySG Access Log - Real Time Filtering

certification associate

$
0
0
I need a solution

Hi , 

I recently have achieved a certification of SEP and i have changed my company and i got a new partner ID for symantec . iwant to associate my certification with newly joined company ? what do i need to do ?

0

MS december security update KB4054518 breaks opening office documents

$
0
0
I need a solution

After installation of the december KB4054518 (Monthly Rollup), opening office documents from a encrypted fileshare is broken.

0

Policy Trace

$
0
0
I need a solution

Is there any other way on doing the policy trace.

It would be nice to have a page put in some parameters like the destination IP address / URL then run it against the policy, tool would show you the policies that it hit. Is there such a tool somewhere?

Honestly the policy trace tool is not efficient , going through the policy trace log is not that efficient as well.

0

Remote Uninstall

$
0
0
I need a solution

Hi,

Is it possible to remotely uninstall SEP from client workstations? I have ~40 machines where I need to remove SEP however cannot find an option in the console. If not, are there any alternate solutions which would work asides from manually logging onto each machine? 

Thanks in advance

0

DLO 2010 storage change

$
0
0
I need a solution

We are using symantec DLO 2010 (looking into replacement) I'm replacing our nas so I need to move the storage location to the new nas.
This has been setup by my predecesor and from the console you can't configure the storage location on a nas.

I think it should be posible to change this in the sqldb itself but i'm not entirely sure how to go about it.
Is there anyone here that has experience with this and might be able to explain to me how to do this?

Best regards, 
Max.

0

Protection Egine for NAS ICAP not responding

$
0
0
I need a solution

Hello,

I work at a large Dutch hospital where we are looking for an antivirus solution for our file-based storage. Using the white paper below, I installed Redhat and Symantec. The filelist is created and tries to hand it over to the Symantec ICAP. The ICAP does not respond.

https://www.ibm.com/developerworks/community/wikis/home?lang=en#!/wiki/General%20Parallel%20File%20System%20(GPFS)/page/Antivirus

I have installed below:

Red Hat Enterprise Linux 7.3
Symantec Protection Egine for NAS 7.9.0.1

The ICAP does not answer a telnet, but with ssecls the files are scanned. Does anyone have any idea what goes wrong?

[root@sn-tst-02-01 bulkantivirus]# telnet 127.0.0.1 1344
Trying 127.0.0.1...
Connected to 127.0.0.1.
Escape character is '^]'.
OPTIONS icap://127.0.0.1:1344/reqmod ICAP/1.0
Connection closed by foreign host.

[root@sn-tst-02-01 bulkantivirus]# /opt/SYMCScan/ssecls/ssecls -server 127.0.0.1:1344 /gpfs-test/smb/test/test01/test-scan/

    Virus scan process began : Thu Dec 14 14:45:05 2017
Virus scan process completed : Thu Dec 14 14:45:10 2017

        Defs Version = 20171213.019
 Commandline Scanner = 7.9.0.1

         Total Bytes = 648891555 (Mbytes 618.8312)
             Elapsed = 4.5800
           Scan Rate =  135.12 (Mbytes/sec)

      Files Excluded = 0
       Files Scanned = 101
 Directories Scanned = 1
Directories Excluded = 0
       Files Skipped = 1
    Files Scan Error = 0
      Files Infected = 0

Data based metering parameters:
Data Scanned in bytes=-1
Total files scanned=-1

No error was found during the scan
0

MessageLabs - connection timing out

$
0
0
I need a solution

We are having issues sending emails to customers that are using Message Labs. 

[{LED=451 4.4.395 Target host responded with error. -> 421 4.4.1 Connection timed out };{FQDN=cluster1a.us.messagelabs.com};{IP=216.82.251.230};{LRT=12/11/2017 1:16:48 PM}]

We are sending emails from 198.49.0.3.  We are not marked as blacklisted on any websites too.

Can somebody help with this please? Thank you!

0

Excluding Heur.AdvML. alerts completely

$
0
0
I need a solution

Is there a way to exclude Heur.AdvML.A  alerts completely?  All files it is finding are false positives, and although we could submit those files to Symantec, or exclude them ourselves, we would be doing this for hundreds of files individually in numerous folders.

We just need to basically stop these alerts from doing anything at all until we can figure out a more permanent solution since we are getting spammed with false positive alerts.

0
1513290604

[APPLICATION] has changed since the last time you used it.

$
0
0
I need a solution

I have an unmanaged client for SEP 14.0 MP2.  I do not have the licensing information.

I get the following message repeatedly:

"[APPLICATION] has changed since the last time you used it.

Name: [APPLICATION]

Application: [FILE NAME]

Do you want to allow it access to the network?"

Where [APPLICATION] is an application on the computer and [FILE NAME] is the executable file for that application.

There is an article about this on the Symantec website but the solution is not applicable to my situation since it is an unmanaged client.

https://support.symantec.com/en_US/article.TECH123331.html

When enableing and disabling Network application monitoring, I keep getting notifications every 5-10 minutes that Symantec has blocked svchost.exe until Symantec is reinstalled.

I have seen this issue in Windows 7, 8.1, 10.  32bit and 64bit.

0
1513291864

WSS - Allow especific URL

Help on disabling the CAN NOT SECURE MESSAGES

$
0
0
I do not need a solution (just sharing information)

I have Symantec Encryption Desktop, Everytime I boot up it gives me a message saying it can not secure messages (email) and wants to know what 3 options..... DONT SECURE or SECURE and one other one...

Is there a way to TOTALLY DISABLE this even from popping up ? I DO NOT CARE or DO NOT USE PGP to secure my email and this is a BIGTIME NUISANCE....

I only use encryption desktop to encrypt a whole drive. Thats it ! thanks in advance.

0

[PGP] PGP Commandline does not run on Redhat Server 7

$
0
0
I need a solution

Hello everyone.

We're not able to make PGPCommandline version 10.4.2 run on any Redhat or Centos server version 6 and 7.

Any ideas what could be the cause of this behavior? RPM package has installed correctly.

This version of PGPCommandLine on Windows works great.

Thanks

0

Browser intrusion prevention is malfunctioning - Firefox

$
0
0
I need a solution

I just updated Firefox to the latest version (57.0.2, 64-bit).  Now, whenever I open Firefox, I get a notification message that reads, "Browser Intrustion Prevention is malfunctioning.  Check the System logs for details."  The message also appears every time I open a new tab.  I'm running SEP verison 14.  I ran a Live Update and the problem still occurs.

0
1513290385

Scheduled report including IP, Host Name, and Definitions date

$
0
0
I need a solution

Hi All,

I have seen some older posts stating that this isn't possible to schedule but I figure it may have changed since these were posted and it couldn't hurt to ask.

What I'm trying to accomplish is an automated version of the monitors logs that contains Computer name, IP, OS, etc. Ideally it would have all of this information but minimum I need the Computer name, IP, Virus definitions, and the group name.

I've built out a powershell script that will run NLTest against all machines in the CSV exported through monitors and create a new CSV comparing the site from NLTest to the Group name. I'd like to turn this into a scheduled task to run every night and send out a list to my teams email distribution showing what machines are outdated by 30+ days. In order to do this I need to find a way of automating the process of generating the computer status logs and exporting them as a CSV and so far I haven't seen any method of doing this in the scheduled repots section. I know it would be possible to do something similar by creating a script to pull all of our machines by from our SQl DB and then comparing the dates associated witht he virus definitions but at the moment that is well outside of my skill level. I was wondering if anyone had a method of automating this process or could point me in the right direction. If any other information is needed please let me know. Thanks. 

0
Viewing all 18527 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>