Endpoint Protection

 View Only
Expand all | Collapse all

SEPM HI Policies

Migration User

Migration UserDec 12, 2014 01:59 AM

Migration User

Migration UserDec 17, 2014 12:41 PM

ℬrίαη

ℬrίαηDec 17, 2014 12:42 PM

Migration User

Migration UserDec 18, 2014 02:17 AM

  • 1.  SEPM HI Policies

    Posted Dec 12, 2014 01:38 AM

    Hello all , I have created few HI polcies to check . I need to know do I also need SEP 12.1.5 for endpoints ? or HI policies will also work on SEP 12.1.4 or earlier version agents. Thanks



  • 2.  RE: SEPM HI Policies

    Posted Dec 12, 2014 01:59 AM

    Any 1 ????



  • 3.  RE: SEPM HI Policies

    Posted Dec 12, 2014 02:19 AM
      |   view attached

    Yes it's working on earlier version agents,You can check in test group.

     

    Attachment(s)



  • 4.  RE: SEPM HI Policies

    Posted Dec 12, 2014 02:29 AM
    You need have sep client with SNAC component.. Once you enable the HI policy SNAC will get enabled


  • 5.  RE: SEPM HI Policies

    Posted Dec 12, 2014 02:36 AM

    if the SNAC is not enabled in the endpoint UI then the policies wont trigger ?



  • 6.  RE: SEPM HI Policies

    Posted Dec 12, 2014 02:39 AM

    I have a SEP 12.1.4 endpoint on which HI policies are not triggering.

    Regards,



  • 7.  RE: SEPM HI Policies

    Posted Dec 12, 2014 02:42 AM

    See Chetan comment

     

    After doing an upgrade to RU5 Host Integrity policy will be added under default policies but it won't be assign to any group by default. Ground location count show '0'.

    If you assign Host Integrity policy to any group you may have to reboot the client to take necessary updates.

    https://www-secure.symantec.com/connect/forums/sep-1215-does-not-update-nac-definitions#comment-10591341



  • 8.  RE: SEPM HI Policies

    Posted Dec 12, 2014 06:28 AM

    The problem is, the HI license requirement was removed in 12.1.5. Prior to that, a separate license was required.

    Do they policies fire on 12.1.5 clients? If so, it looks like this only works on 12.1.5 clients due to the change that was made.



  • 9.  RE: SEPM HI Policies

    Posted Dec 14, 2014 02:15 AM

    Hello I have observed a strange thing when applying HI policies to a group in SEPM 12.1.5 the console simply hangs. so I'd to close it forcefully via taks manager. Why is it hanging ?

    Regards



  • 10.  RE: SEPM HI Policies

    Posted Dec 14, 2014 02:25 AM

    Please Check Java heap setting

    Tuning the Performance of the Symantec Endpoint Protection Manager console

    Article:TECH105179 | Created: 2008-01-18 | Updated: 2014-08-12 | Article URL http://www.symantec.com/docs/TECH105179


  • 11.  RE: SEPM HI Policies

    Posted Dec 14, 2014 02:35 AM

    James be value set it default. Should I increase it ? if yes then how much . Regards



  • 12.  RE: SEPM HI Policies

    Posted Dec 14, 2014 02:56 AM

    You can SET as per articles

     

    Set the following four registry values:
    HKLM\System\CurrentControlSet\Services\semsrv\Parameters\
    JVM Option Number 0=-Xms1024m
    JVM Option Number 1=-Xmx1024m
    JVM Option Number 2=-XX:MinHeapFreeRatio=40
    JVM Option Number 3=-XX:MaxHeapFreeRatio=70

    Tuning the Performance of the Symantec Endpoint Protection Manager console

    Article:TECH105179 | Created: 2008-01-18 | Updated: 2014-08-12 | Article URL http://www.symantec.com/docs/TECH105179

     



  • 13.  RE: SEPM HI Policies

    Posted Dec 14, 2014 08:41 AM

    You should enable FINEST debugging before you start making changes that may or may not fix the issue.



  • 14.  RE: SEPM HI Policies

    Posted Dec 16, 2014 02:51 PM

    Outrageous,

    It will NOT work, see here:

    Older versions of SNAC is not manageable with Symantec Endpoint Protection 12.1.5

    Article:TECH227131  |  Created: 2014-12-16  |  Updated: 2014-12-16  |  Article URL http://www.symantec.com/docs/TECH227131


  • 15.  RE: SEPM HI Policies

    Posted Dec 17, 2014 12:41 PM

    Thanks for your reply Brian its very helpful



  • 16.  RE: SEPM HI Policies

    Posted Dec 17, 2014 12:42 PM

    Happy to help, as always sir.



  • 17.  RE: SEPM HI Policies

    Posted Dec 17, 2014 12:42 PM

    Thanks for your reply Jeshrel its very informative no exisiting SEP 12.1.4/1.3 clients do not have any existing SNAC polcies in place nor SNAC was being used previously.



  • 18.  RE: SEPM HI Policies

    Posted Dec 18, 2014 02:13 AM

    SEP is a weird alien it's hard to predict what it does are it is going to do cause most of the time the documentation is just the opposite of whats happens. Sorry to spoil the thread.

     

    The documentation stated that it aint possible but i just moved client from 18 SEPM server and huge chunk of about 20000+ clients of which non on them where in version 12.1.5 always where below 12.1.4 majority in 12.1.2. I was able to use HI policy and move all of them to just one server.

     

    I did face issue with one server  and the issue can be seen in the follwoing thread

    https://www-secure.symantec.com/connect/forums/sep-1215-does-not-update-nac-definitions

     

    @Outrageous - For your question will SEP 12.1.5 Server be able to update HI policy to 12.1.4 or below client yes as per my experience and as per a tech in SEP support but if you have existing SNAC policy in place and if your gonna upgarde from 12.1.4 or older to 12.1.5, then its advisiable to contact support to find out what can be done.

    ~Edit~  



  • 19.  RE: SEPM HI Policies

    Posted Dec 18, 2014 02:17 AM

    Your welcome..:)