Endpoint Protection

 View Only
  • 1.  Exempt a folder from scanning not just risk detection...

    Posted Jun 24, 2009 12:17 PM
    Hello,

     I'd like to ask if there is a way to stop SEP11 from scanning a folder at all  (through Autoprotect and Scheduled Scans) instead of just stopping risk detection?  It doesn't make sense to me to have SEP11 scan through a folder that you have decided you don't want risk alerts on.  Also folders that have large size as well as a large number of compressed files like C:\MSOCache (and ones custom to certain depts) are causing a lot of scanning errors and because of their size are prolonging the scan time. 

    If, as I suspect, Centralized Exceptions can not do the above are there plans to include it?


  • 2.  RE: Exempt a folder from scanning not just risk detection...

    Posted Jun 24, 2009 12:28 PM
    We can add centralized exceptions for the same!!

    >>How to add a Centralized Exception for a detection that is not included with Known Security Risk Exceptions in the Centralized Exception Policy.
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008100706493648

    >>Making exceptions using centralized exception policies in Symantec Endpoint Protection
    http://service1.symantec.com/support/ent-security.nsf/docid/2008030423280248

    >>Symantec Endpoint Protection Manager - Centralized Exceptions - Policies explained
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008032010550448

    >>How to add a Security Risk Exception in the Endpoint Protection Manager
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121808365448

    >>How to create an exception for a known valid process flagged by Proactive Threat Protection
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007120611022848



  • 3.  RE: Exempt a folder from scanning not just risk detection...

    Posted Jun 24, 2009 12:31 PM
    Few more Links For your reference!


    >>How to configure Tamper Protection in Symantec Endpoint Protection 11.0
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007092616550248

    >>How to create an exception for a specific risk that is not listed in the list of known risks on the Symantec Endpoint Protection Manager
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008092302060248


  • 4.  RE: Exempt a folder from scanning not just risk detection...

    Posted Jun 24, 2009 01:55 PM
    This is a very intresting one..


  • 5.  RE: Exempt a folder from scanning not just risk detection...
    Best Answer

    Posted Jun 24, 2009 02:15 PM
     Once you have put an exception for a file or folder...no scan will scan those folders.
    be it Scheduled,Active/Quick or Auto-protect.

    Main reason for scanning error is when the Decompresser engine cannot extract a file like CAB ,TAR...password protected files..

    But once you put it under centalised exception it wont scan it...
    Tamper Protection does not do the scan ( So no need to put these files or folders under Tamper Protection exceptions )


  • 6.  RE: Exempt a folder from scanning not just risk detection...

    Posted Jun 24, 2009 06:42 PM
    Vikram,

     I was going off of experiences reported to me by an app analyst, I'll try to get her scan logs to see if they support what been told.  Thanks for the response.