Endpoint Protection

 View Only
Expand all | Collapse all

SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

Migration User

Migration UserJun 19, 2013 07:09 AM

ℬrίαη

ℬrίαηJul 16, 2013 12:35 PM

  • 1.  SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jun 19, 2013 06:33 AM

    Hi

    have a weird problem with our symantec endpoint protection (v 11.0.5002.333)

    When a user logs on, the SEP client is not enabled.  The user can open the client and click Fix All and everything will correct itself and enable SEP but need to sort this so it launches correctly

    thanks in advance

    Simon



  • 2.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Broadcom Employee
    Posted Jun 19, 2013 06:38 AM

    can you upgrade the client to latest version and let know if it resolves the issue



  • 3.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jun 19, 2013 07:02 AM

    Thanks for the reply Pete, sorry but I'm totally new to endpoint, where can I get the latest version from?

    :)



  • 4.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jun 19, 2013 07:09 AM

    upgrade to symantec 12.1 ru2 mp1 :)



  • 5.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jun 19, 2013 07:13 AM

    The latest version is 12.1 RU3, not RU2 MP1.

    You can download from https://fileconnect.symantec.com using your serial number.

    Also, check in the SEPM under the AV policy to make sure the lock icons are closed.



  • 6.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jun 20, 2013 04:19 AM

    Hi, I checked the AV policy and all the locks were open, so have closed those now.  What do they do?

    I'm having troubIe finding the serial number at the moment, is there a way of finding it from the server itself?  Thanks



  • 7.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Trusted Advisor
    Posted Jun 20, 2013 03:12 PM

    Hello,

    How many machines are you facing this issue on??

    Are all these clients installed, managed??

    In this case, we see, ProActive Threat Protection and Download Insight is Malfunctioning.

    Please check if the policies for ProActive Threat Protection (SONAR) and Download Insight are set correctly in SEPM?

    3_61.jpg

     

    4_39.jpg

     

    It seems this issue is happening only on 1 machine, correct.

    In your, case it clearly indicates that the SEP client is not installed properly or the installation is Corrupt.

    If we check the SEP clearly, 

    Download Insight Failure is caused because Proactive Threat Protection is not working properly, Proactive Threat Protection is not working properly because File System Protection is not working properly. All these Features are Inter-related.

    Check this Article: http://www.symantec.com/docs/HOWTO55268

    1_150.jpg

     

    Again, what happens if you move the cursor from 9 to 5 in the Download Insight Policies??

     

    2_99.jpg

     

    Also to note that the SEP client system must be rebooted after installation to completely activate all components.

    Or you may stop the SMC service by the command "smc -stop" followed by starting the service again with "smc -start".

    All the Locks on the policies should be locked, so that the policies  could not be changed on SEP client.

    In reference to the License, I would also recommend you to Contact the Licensing Department via:

    Website: http://symantec.custhelp.com

    Phone number: 1-800-721-3934

    Email: license@symantec.com

    https://licensing.symantec.com/acctmgmt/index.jsp

    For Renewals or view details of your Symantec support contracts visit our License Renewal Center.

    Hope that helps!!



  • 8.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 16, 2013 12:10 PM

    Hi, apologises for my delay in responding, I was having trouble finding the serial number. 

    I finally discovered that SEP had originally been installed by an engineer from one of our other offices and they hadn't left us the number.  I have now got a v12 serial number and installer but I have hit a different issue. 

    I am unable to run the installer as windows gives the error "Symantec Endpoint Protection Manager has detected that there are pending system changes that require a reboot".  I have rebooted several times and I also tried deleting the "PendingFileRenameOperations" registry key but no luck.

    Any ideas?  The server is a VM, running server 2008 R2 standard SP1, thanks

     

    Mithun - thank you for your response, as I have managed to obtain a newer version I'm going to get that on the server first before trying your suggestions, thank you though in advance



  • 9.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 16, 2013 12:18 PM

    Open regedit

    navigate to HKLM\SYSTEM\CurrentControlSet\Control\Session Manager

    look for a key called "PendingFileRenameOperations and delete it. Run the installer again.

    make sure to take a backup first!



  • 10.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 16, 2013 12:32 PM

    Hi Brian, as per my post, I have already tried this but thanks for your help  :)



  • 11.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 16, 2013 12:35 PM

    You didn't reboot after deleting right?



  • 12.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 10:49 AM

    That was the problem  :)

    I was rebooting and the system was recreating the key, have got the installer running now, thanks Brian



  • 13.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 10:54 AM

    That's great. If you reboot after deleting the key, it comes back on reboot.

    The trick is to delete than run the installer immediately (no reboot) :)



  • 14.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 11:32 AM

    SEPM is now upgraded to v12, I'm just waiting for it to pick up all the clients again, is there any way to speed this up?



  • 15.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 11:40 AM

    Clients report in based on their heartbeat setting.



  • 16.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 11:48 AM

    So it's a setting on each client?  Which I'm guessing means I need to go to each client if I wanted to get them to report in?



  • 17.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 11:53 AM

    You can set the heartbeat from the SEPM. Clients >> Policies >> Communication Settings

    You can force the client to check in by right clicking on SEP icon and selecting Update Policy. For this you would need to go to each client.



  • 18.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 12:11 PM

    They are trickling through, think I'll just leave this overnight and come back to this tomorrow.  Thanks Brian



  • 19.  RE: SEP clients disabled by default, multiple problems, AV & antispyware/proactive threat off

    Posted Jul 17, 2013 12:12 PM

    Glad to help. Check back in to update on status if you can.

    Take care,
    Brian