Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Display the notification area icon question

Updated: 21 May 2010 | 10 comments
Brian81's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

What exactly does this mean?

Does it mean that the user will not get notifications in the bottom right hand corner from the SEP client icon? Such as Please restart or traffic blocked notifications??

discussion Filed Under:

Comments

Rafeeq's picture
17
Mar
2010
0 Votes 0
Login to vote

hi

This will pop up when you disable symantec endponit protection

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Brian81's picture
17
Mar
2010
0 Votes 0
Login to vote

Is that only when you disable

Is that only when you disable SEP or for all notifications from SEP?

Rafeeq's picture
17
Mar
2010
0 Votes 0
Login to vote

hi

its for all notifications

Display the notification area icon

Displays the client's notification area icon and its right-click menu.

 Note: Unchecking that would not display the client icon too.

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Grant_Hall's picture
17
Mar
2010
0 Votes 0
Login to vote

Rafeeq is exactly right. We

Rafeeq is exactly right. We gave admins this option so they could restrict users access to SEP via the system tray. Please look at the guide below if this is what you are trying to accomplish

How to restrict users from making configuration changes to the Symantec Endpoint Protection client.
http://service1.symantec.com/SUPPORT/ent-security....

Cheers
Grant

Please don't forget to mark your thread solved with whatever answer helped you : )

Brian81's picture
17
Mar
2010
0 Votes 0
Login to vote

My main objective was to stop

My main objective was to stop users from getting any notification such as "please restart your PC for application and device control policy to take affect" or "Traffic Blocked from ..."

I don't want users to see any of these as they panic and flood the helpdesk.

Grant_Hall's picture
17
Mar
2010
0 Votes 0
Login to vote

Well then checking this

Well then checking this should stop that notification from happening. Personally I think all admins should check this box anyway because it stops their users from having access to the icon in the system tray (thus making it harder to right click and select "disable symantec endpoint protection".

However I am assuming you are seeing this message on your users machines: "Traffic has been blocked from this application: NT Kernel & System (ntoskrnl.exe)". If this is the case you should be able to att ntoskrnl.exe as an exception and it will stop the message from being shown. 

How to add a TruScan exception:
 
Open Symantec Endpoint Protection
Select Change Settings in the left pane
Click the Configure Settings button across from Centralized Exceptions
In the User-Defined Exceptions tab, select Add...
Select TruScan Proactive threat Scan Exception
Browse to  C:\WINDOWS\system32\
Select ntoskrnl.exe 
Choose the desired action from the Action drop down menu
Note: For testing purposes choose "Log only"
Click Add
Close the Centralized Exceptions window.

How to add a Firewall rule:
 
Open Symantec Endpoint Protection
Click the Options button across from Network Threat Protection
Select Configure Firewall Rules...
Click Add...
Type in a rule name
Under Action select Allow this traffic
Click the Applications tab
Click Browse...
Navigate to  C:\WINDOWS\system32\
Select ntoskrnl.exe 
Click Open
Click OK
Highlight the rule in the list
Click the up arrow button to move the rule to the top of the list
Click OK

Test both of the above on a client and see if the error goes away. OR check the box to disable notifications.

Cheers
Grant

Please don't forget to mark your thread solved with whatever answer helped you : )

Brian81's picture
17
Mar
2010
0 Votes 0
Login to vote

I will likely uncheck the

I will likely uncheck the "Display notification area icon" Just need to test it out to make sure it's what I want. Thanks.

Rafeeq's picture
17
Mar
2010
0 Votes 0
Login to vote

hi

When you uncheck it wont display the icon in system tray, and thats how  all notifications wont be displayed. 

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Nel Ramos's picture
17
Mar
2010
0 Votes 0
Login to vote

Just got another question

Just got another question with regards to that.
Having the SEP out of the systray will keep users from disabling SEP.
But my problem is that some of my admin users would just get into services.msc and disable SEP from there.
Is there something to over ride this?
many thanks.

Nel Ramos

Rafeeq's picture
18
Mar
2010
0 Votes 0
Login to vote

hi

you can use require a password to stop sep services.
as you can see , they cant stop symantec management client service.
there wont be an option to stop /start.

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq