Endpoint Protection Small Business Edition

 View Only
  • 1.  endpoint protection exceptions HELP!!

    Posted Mar 12, 2012 03:43 PM

    I am currently using endpoint protection small business. I also use contiuum/zenithinfotech for network management and monitoring. I thought I had set exceptions for the saazod folder to allow the services to ping in to check the system information but they are still being blocked by the AV. The Event Viewer keeps showing the processes as being blocked almost every minute of everyday as a intrusion prevention. Can someone PLEASE tell me what I am doing wrong or just how to set it the right way? Thank you for your time and help. Dave



  • 2.  RE: endpoint protection exceptions HELP!!

    Posted Mar 12, 2012 04:56 PM

    Dave, you need to do 2 things

    First, open SEPM, click on computers, select your server, then click the Policies tab

    Under "other policy settings" click Edit Settings for Tamper protection

    Under Tamper protection, select "log only" in the drop-down

    If you are running RU1 - and I strongly recommend the upgrade - there is a check box to "Display notification message"  make sure that is not checked.

    Click OK to save these settings.

    Right about that you have Exceptions click Tasks - select Edit Policy

    Click Exceptions in the left

    In the Exceptions area, click Add to add each of the flagged Zenith/Continuum exe files.  As far as I know, you can't exclude the entire folder...

    Click Add, select Windows Exception, select Tamper Protection Exception.

    Enter the full path and file name.

    (A crying shame that Symantec still doesn't have [program_files_(x86)] as a varaiable.)

    Click OK when you are finished.

    Apply the Exceptions policy to the server.

    That should do it!

    Larry



  • 3.  RE: endpoint protection exceptions HELP!!

    Posted Mar 12, 2012 10:19 PM

    If it is SEP tamper protection causing this, i agree with the above suggestion. But if it is not, try to disable SEP and see things are good, then we can proceed with exceptions.

    The below articles may also help you in case of tamper protection.

    What should I do when I get a Tamper Protection Alert?

    http://www.symantec.com/business/support/index?page=content&id=TECH97931

     

    How to Create Exceptions or Exclusions for Tamper Protection Alerts that have already been logged

    http://www.symantec.com/business/support/index?page=content&id=TECH92553

     

    Creating Tamper Protectin Exception

    http://symantec.com/docs/HOWTO55213