Endpoint Protection

 View Only
Expand all | Collapse all
Migration User

Migration UserFeb 18, 2015 03:25 AM

Migration User

Migration UserFeb 18, 2015 03:26 AM

  • 1.  Firewall

    Posted Feb 18, 2015 02:51 AM

    Hi friends.

    1. I nedd yuo help. After inatallation SEP on my server, i have this: These settings are being managed by vendor application Symantec Endpoint Protection. I need to create new rule and this rule will be block port SMB 445, 137-139. But when i enable this rule it not block ports, though firewall Windows is enable too.

    FW1.JPG

    2. And esle, on my enother server SEP install too, but this These settings are being managed by vendor application Symantec Endpoint Protection not apply. And here, my rule WORK

     

    FW2_0.JPG

     

    How i can do, that my rule work on my first server?



  • 2.  RE: Firewall

    Posted Feb 18, 2015 02:54 AM

    What feature do you have installed both server ?

    As a best practice recommendation it is always advised to use only one software Firewall on a computer. Two software Firewalls running on a computer might drain resources and the both software Firewalls might have rules those might conflict with each other. Enabling more than one Firewall program is likely to result in conflicts and poor performance. 

    To prevent the above situation Symantec Endpoint Protection (SEP) installer automatically detects and disables Windows Firewall if enabled. Exception to this would be that if SEP is installed without Network Threat Protection (NTP) active Windows Firewall will not be disabled

    Best Practices for using Windows Firewall with Symantec Endpoint Protection 12.1

    Article:TECH196975  | Created: 2012-09-20  | Updated: 2012-09-20  | Article URL http://www.symantec.com/docs/TECH196975


  • 3.  RE: Firewall

    Posted Feb 18, 2015 02:58 AM

    I install SEP on my all servers  by defoult. However i have that you see



  • 4.  RE: Firewall

    Posted Feb 18, 2015 03:03 AM

    Does have you installed NTP feture ?

    SEP is installed without Network Threat Protection (NTP) active Windows Firewall will not be disabled



  • 5.  RE: Firewall

    Posted Feb 18, 2015 03:10 AM

    Yes, NTP is installed on all servers. However on first not work and on second work.....



  • 6.  RE: Firewall

    Posted Feb 18, 2015 03:15 AM

    Does sep client received latest policy ?

    You need to enable windows firewall.

    Using (Enabling) Windows Firewall with Symantec Endpoint Protection Network Threat Protection installed

    Article:TECH197660  | Created: 2012-10-01  | Updated: 2013-12-20  | Article URL http://www.symantec.com/docs/TECH197660

     



  • 7.  RE: Firewall

    Posted Feb 18, 2015 03:21 AM

    How option i need choose, that Windows firewall ENABLE?

    On my picture, Windows firewall already active?



  • 8.  RE: Firewall
    Best Answer

    Posted Feb 18, 2015 03:22 AM

    Please check below blog

    How to enable Windows firewall setting in Windows 7 machine in SEPM 12.1.2

    https://www-secure.symantec.com/connect/blogs/how-enable-windows-firewall-setting-windows-7-machine-sepm-1212

    May that client NTP feature not installed.

     



  • 9.  RE: Firewall

    Posted Feb 18, 2015 03:25 AM

    No, You need to reboot server



  • 10.  RE: Firewall

    Posted Feb 18, 2015 03:25 AM

    Can i enable windows firewall and disable SEP NTP withuot reboot server?



  • 11.  RE: Firewall

    Posted Feb 18, 2015 03:26 AM

    fw3.JPG



  • 12.  RE: Firewall

    Posted Feb 18, 2015 03:28 AM

    Does both of SEP client are same group ?

    does both sep client received having latest policy?

    You can try above blog and check windows firewall enabled or not.



  • 13.  RE: Firewall

    Posted Feb 18, 2015 03:38 AM

    I did that  http://www.symantec.com/business/support/index?page=content&id=TECH197660

    and Windows Firewall enable, and my rule WORK. 

    Thank you very much!!! 



  • 14.  RE: Firewall

    Posted Feb 18, 2015 07:43 AM

    You just need to withdraw the firewall policy, you don't need to reboot to do this!