Quantcast
Channel: Symantec Connect - Products - Discussions
Viewing all 18527 articles
Browse latest View live

Importing Computer structure causes Ghost console to crash.

$
0
0
I need a solution

Hi,

I've run into an issue with our exported Computer file structure causing ghost to crast when importing. 

I've determine the root cause to the problem and a temporary workaround however this is not a solution.

We had a catastrophic failure on our ghost server after an upgrade in October 2019.  After a clean rebuild we started exporting the tasks and computer structure on a regular basis weekly\bi-weekly basis.  Our January export of the computers structure when imported crashes the console part way through.  After manually digging around I’ve determined the problem to be 4 systems in different containers have no NIC listed.  In the console it states that the NIC are disabled.  In the exported file they are identified by having “<nics/>” which basically indicates no NIC.

                                <name>aaaTNTLIB-104</name>

                                <computer_name>aaaTNTLIB-104</computer_name>

                                <serial_num>CY09aaaa</serial_num>

                                <uuid>{4C4C4544-aaaa-3010-8039-C3C04F305132}</uuid>

                                <UAC>1</UAC>

                                <nics/>

                                <grouppath>

                                                <group>aaaton</group>

                                                <group>Tlib</group></grouppath></computer>

If I remove them from the exported file, it will import properly.

For now, I deleted those system from the console and they added themselves properly with their working NIC’s.  Now the export file will import fine, however there is no dynamic group rule I could come up with to detect such systems before an export.

Has anyone run into this before? 

Using Symantec Ghost Suite Ver3.3 R3  (Build 2642)

Running on MS Server 2016.

Thanks,

  Ed White

0

Delete user-allowed applications exceptions from the SEPM

$
0
0
I need a solution

Hello,

In my current configuration, local admins can add their own exection on their SEP client. I want forbide this but first I would like to delete all exceptions already created on the clients. I can see them from the SEPM throught the Policies menu > Exceptions > clicking on an exception policy > on the Exeptions part, when I click on Add > Windows Exceptions > Application > then in the View list I select "user-allowed applications". But there is no way to remove them.

Does anyone know how to do it or I have to contact all my users one by one to tell them to remove their exceptions manually?

Thanks.

0
1580834238

WSS Agent

$
0
0
I need a solution

We have recently deployed the Web Security Service and deployed the Unified Agent 4.11 (Windows 7) and WSS AGent 6.1.1. However when we add domains and IP addresses to be bypassed on the portal, the rules dont appear to take effect with the domain names still appearing in the user traffic and the egress adddress still coming from Symantec. Is this standard behaviour for the agents or can anyone advise as to what we are doing wrong?

0

DLP Incident Issue

$
0
0
I need a solution

I implement Policies on DLP (15.5) and i specify this policies for Specific User Groub From Active Directory

and when i Did this i tested the policy and no incidents appeared to me eventhough there were alot of incidents before i use the User Group Rule To apply this policies to this Groups only,

what shuould i do and could any one faces this issue to tell me the reason and the solution ?

Thank you.

0

WSS not filtering in Chrome (.pac)

$
0
0
I need a solution

Hi All,

Hoping someone can shed some light on what is going on with WSS .pac file and Google Chrome.

Scenario;

Pac file URL is rolled out via GPO to all corporate PC's

Created an explicit block rule on abc.net.au

Using Chrome, if you directly type abc.net.au it gets blocked, but if you google ABC or Triple J the site is displayed and does not filter through the proxy. Found that if a manual HTTP proxy to proxy.threatpulse.com:8080 is used it correctly blocks.

Testing in Firefox the website is blocked fine in all instances.

So my question, is there a setting in chrome that is preventing the correct blocking of websites when using a symantec .pac file?

Thanks all,

Dylan

0

How to close account?

$
0
0
I need a solution

Hello,

I've created a security account to try it, without any subscriptions. Now, I receive many e-mails each days.

How can I close the account so I no more receive them?

Thanks in advance for the answer

0

Email not delivered in time or expired

$
0
0
I do not need a solution (just sharing information)

Hi,

I have an on going problem recieving emails from a client, this has really been an issue for at least 6months

Sometime they dont get there at all or sometime 1 week later.

I've done a search for my clients MX record and they are using messagelabs.com

Who can I contact for help, I tried sending an email with the ip address and bounce back details but the support email doesnt work anymore.

I can't open a ticket because I'm not a symantec client.

Thanks in advance.

0

Registry values to check status of Norton/Symantec AntiVirus

$
0
0
I do not need a solution (just sharing information)

This is a general question. I am trying to find information to determine TimeOfLastScanPatternFileRevision and PatternFileDate etc settings directly in the registry for Norton AntiVirus on Windows 10.

I believe most Norton AntiVirus values should be located under HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\..., but the latest Norton AntiVirus 22.19.8.65 trial version does not appear to have the same location in the Registry?

I can only see HKEY_LOCAL_MACHINE\SOFTWARE\Norton\... and HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\.... But I cannot find these values I want to check programmatically (Time of last scan and pattern file date etc).

Have Symantec changed the design and Registry location for Norton AntiVirus at some point in the past? Or is the usual location missing because I am using the trial version?

Can someone please clarify why HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\... is no longer visible in the latest version of Norton (Symantec) AntiVirus?

Thank you.

Trevor

0

ADFS 4.0 (Windows Server 2016) and Symantec VIP

$
0
0
I need a solution

Hello!

We I trying integrate our ADFS farm and Symantec VIP Manager for push authenication via JavaScript integration. I am using this guide (I have done all steps from chapter 4), but when I try to put correct login and password I get the following error in log file:

06.02.2020 10:41:59 : Log File Path : C:\Program Files\Symantec\ADFS\
 06.02.2020 10:41:59 : VipService Authentication URL: https://userservices-auth.vip.symantec.com/vipuserservices/AuthenticationService_1_4
 06.02.2020 10:41:59 : Vip Services Timeout: 10000
 06.02.2020 10:41:59 : Vip Certificate Path: C:\Program Files\Symantec\ADFS\vip_cert_12-26-2019_12-16AM.p12
 06.02.2020 10:41:59 : Automatic Business Continuity: False
 06.02.2020 10:41:59 : Javascript Integration : True
 06.02.2020 10:41:59 : IpAddress Fetched:192.168.20.71
 06.02.2020 10:41:59 : Fetched VIP service settings successfully
 06.02.2020 10:42:33 : Exception while signing the username : System.ArgumentOutOfRangeException: Length cannot be less than zero.
Parameter name: length
   at System.String.Substring(Int32 startIndex, Int32 length)
   at SymcVIP.AuthenticationAdapterWindowsAccountName.SignUserName(String vipUser)
 06.02.2020 10:42:52 : Certificate chain count: 3
 06.02.2020 10:42:53 : User a.ivonin Authentication failed, Request ID: ADFS_9_9_0_192_168_20_71_34501. Invalid Security Code
 06.02.2020 10:42:53 : Exception while signing the username : System.ArgumentOutOfRangeException: Length cannot be less than zero.
Parameter name: length
   at System.String.Substring(Int32 startIndex, Int32 length)
   at SymcVIP.AuthenticationAdapterWindowsAccountName.SignUserName(String vipUser)

But if uncheck the tick Enable VIP Java Script Integration in VIP Integration Settings - Security Code works properly. 

Could anybody help me?

0

blacklisted again anda again only on symantec

$
0
0
I do not need a solution (just sharing information)

Please help me i cannot find any problem this is a fresh server 

IP 51.38.53.28
no spam , spf + dkim , PTR

i also hire specialist IT it tolds me my server is ok 
no other blacklist block me only symantec
i go again and again in this blacklist
please help
i wrote a mail to investagation no1 reply me 
i am frustrated

0

SYMANTEC DLP SIZING

$
0
0
I need a solution

Hi All,

We are currently running DLP 14.6 & want to upgrade to 15.0.

CURRENT SERVER CONFIGURATION:

DLP SERVER & NAMEDrivesCPU/CoresMemory
    
Enforce ServerC: 50GB;D:100GB212
Network Prevent for Email-1C: 50GB;D:100GB28
Network Prevent for Email-2C: 50GB;D:100GB28
Network Prevent for Email-3C: 50GB;D:100GB28
Network Prevent for EmailC: 100GB;E:180GB216
Network MonitorC: 100GB;E:180GB116
Network MonitorC: 100GB;E:180GB116
Network DiscoverC: 50GB;E:90GB28
Endpoint Prevent/ DiscoverC: 50GB;E:90GB28
Network Prevent for WebC: 50GB;D:100GB28
Network Prevent for Email CloudHost

 As per best practices what can be the recommended configuration as we are running 22000 users.

Regard's

Muhammad Bilal Raza

0
1581090864

Site Server - Task Service: "Installed, inactive"

$
0
0
I need a solution

Hi there

We're running SMP 8.1 RU4 and I've just had to setup a new site server for one of our sites as the old site server was on Server 2008 R2 and needed to be retired.

The new site server is on 2012 R2.  Having battled at length to get get the IIS pre-reqs setup and the right .NET version installed (server kept auto updating via Windows update to 4.8), I finally got the SMP console to allow me to install the Task Service.  It also has the Package Server role.

However...  Although now the Task Servic is apparently installed, it's showing in the console as "Installed, inactive".  I've no idea why.

Any ideas please?

0

Need help :Message not transmitted DLP Email Prevent SMTP_MESSAGE.5300

$
0
0
I need a solution

Hi,

We use DLP in our company, we have problem with email prevent showing on the log that a message is not transmitted.  we have an Error on the log :

SMTP_MESSAGE.5300 Error while processing

I have found a link below talking about this, but i didn't understand where to put configuration? MTA or in our DLP prevent mail server. And which configuration do i have to add ?

https://support.symantec.com/us/en/article.tech219387.html

https://support.symantec.com/us/en/article.tech219387.html

Best regards

0

I would like to add a password to VIP Access app on android

$
0
0
I need a solution

I would like to add a password to VIP Access app on android. Is it possible? I can't find where.

thanks

0

Can ProxySG Generate TLS Key Log File

$
0
0
I need a solution

When collecting packet capture files from the ProxySG, is there a way to decrypt them to be able to view the content?  With the use of Forward Secrecy, having the private key for the certificate installed on the Proxy is no longer good enough to be able to decrypt the packet capture using Wireshark, since they use ephemeral keys which are temporary.

A key log file can be created on the client machine, but for the case where there are many client machines, it is better to be able to do this at the central point, which is the ProxySG.

Any suggestions, other than only allowing the proxy to negotiate only with ciphers that do not use ephemeral keys?

Thank you,

-rb

0

SEMS Fileshare 3.4.2. Questions

$
0
0
I need a solution

Hello all,

We have the below questions about SEMS Fileshare:

  1. In case we have 1000 users/agents, what are the suggested Server requirements Specs (cpu, ram, disk)?
  2.  What is the logs retention period? Is there any way to change the predefined period?
  3.  If I have 2 completely different SEMS infrastructures (PGP Encryption Command line and File Share Encryption) in the same domain network, may a conflict occur?
  4.  What will happen to users, keys, etc. if SEMS (in Server Key Mode) get down?
  5. SEMS Fileshare has an embedded database?
  6. After the initial installation, is it possible to change the configured IP and hostname?

Thanks,

S.

0

New ghost image package keeps retrying to site servers on 8.5RU3

$
0
0
I need a solution

I have just create a new image with ghost throught the console with Prepare/Capture Image tasks for the first time since upgrading to 8.5. I am on Release Update3. The image uploaded to my local site server that has package servcies installed, and it is set to replicate the image only to three total site servers. One of the three is the local site server that it uploaded to and the other two site servers have not received the image packages from the last two days. The agent shows 'Retrying Download'.

Below is a sample of the data inside of Log.xml. "No Server Found" has my attention. I expect to see the server name MVCHQALTSS03.fqdn; that is where the image was uploaded to.Never had this issue prior to 8.5.

<Log id="{98B3EFFE-65A4-4A9A-ADF9-EC7781F968E6}" downloadEvent="57" transferBytes="0" transferRate="0" attempts="57" successes="0" attemptTime="2020-02-07 16:49:11" downloadFailureTime="2020-02-07 16:49:11">
<History>
    <Download version="0" status="retrying" statusDescr="No server found" nextRetry="2020-02-07 12:48:55" transferBytes="0" packageSize="0">
        <Session startTime="2020-02-07 12:24:54" endTime="2020-02-07 12:24:55" source="" transferRate="0" transferBytes="0" transferCache="0" result="-2147467259"/>
    </Download>

0

I don't receive email from a specific domain

$
0
0
I do not need a solution (just sharing information)

Good afternoon, I followed all the steps in the link https://support.symantec.com/us/en/article.TECH855....
In the audit lod does not display e-mail and some e-mails appear without content. I increased the timeout from 60 seconds to 5 minutes in inbound, outbound and delivery, I also disabled reverse dns, restarted messaging, without success. I checked at the firewall and there are no blocks. In smg there are no restrictions on bad senders domain, help me please.
Note: I contacted the recipient and they informed me that the messages are being delivered to the company where I work, but the m-emails do not arrive here.

0

ScanEngine's performance when scanning a large file (~1-2GB)

$
0
0
I need a solution

I'm having issues with ScanEngine when I send a file that is about 1-2 GBs in size. I'm using the following code in C#, as per the documentation:

            var requestManager = new ScanRequestManager();
            requestManager.PrepareForScan(new List<ScanEngineInfo> { new ScanEngine(HOST, PORT) }, TIMEOUT, 20);

            try
            {
                var streamScanRequest = requestManager.CreateStreamScanRequest(Policy.SCAN);
                var binaryReader = new BinaryReader(fileStream);

                streamScanRequest.Start(filename, null);
                var chunk = binaryReader.ReadBytes(CHUNK_SIZE);
                while (chunk.Length > 0)
                {
                    streamScanRequest.Send(chunk);
                    chunk = binaryReader.ReadBytes(CHUNK_SIZE);
                }

                var scanResult = streamScanRequest.Finish(Stream.Null);
                return scanResult.fileStatus;
            }
            catch (ScanException ex)
            {
                // Logging
                return FileScanStatus.SCANNING_PROBLEM;
            }
            catch (Exception ex)
            {
                // Logging
                return FileScanStatus.SCANNING_PROBLEM;

            }

This can take about 10-20 minutes for the while loop to finish and even more time for the Finish() function to return a result. It usually hangs.

What's the best approach when dealing with such large files? Compressing them? Is there another API for this sort of situation?

Thank you

0

User list not fully populated

$
0
0
I need a solution

We have users on several domains active in DLP, but the User list under Incidents>Users>User List is not populated with all of them.  In particular, users from one of the domains are completely absent.  Even though I can see the agents in the agent list, get incidents for the agents and their info is populated via AD in attributes, they still don't show up in the user list.  Any suggestions on where I should look to resolve this?

0
Viewing all 18527 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>