Endpoint Protection

 View Only
  • 1.  group specific file exception 11.0.6

    Posted Dec 16, 2010 04:35 PM

    How can I create a special group (NetAdmins) that I can exclude certain specific files for that group only?

    My new avadmin is saying this is not possible.  Says we have to know the complete path to the file but this file could exist in different locations.  This was easy with Mcafee you could do it like 5 ways.

    I find it hard to believe that SEP is incable of excluding risk only by knowing a complete path!

    You want an example: ipscan.exe



  • 2.  RE: group specific file exception 11.0.6

    Posted Dec 16, 2010 04:45 PM

    It is possible using prefix variables for example. Please see:

    Creating Centralized Exception Policies in Symantec Endpoint Protection Manager http://www.symantec.com/docs/TECH104326

    Symantec Endpoint Protection Manager - Centralized Exceptions - Policies explained
    http://www.symantec.com/docs/TECH104432

    How to add a Security Risk Exception in the Endpoint Protection Manager
    http://www.symantec.com/docs/TECH10312



  • 3.  RE: group specific file exception 11.0.6

    Posted Dec 16, 2010 04:46 PM

     Wildcard variables such as * and ? are not supported by Symantec Antivirus or Endpoint Protection so you cannot use the exclusions,

    Can you please tell for what application you want to create exclusion?



  • 4.  RE: group specific file exception 11.0.6

    Posted Dec 17, 2010 04:42 PM

    well in my example is ipscan.exe  which the application is Angry IP Scanner.

    It is an open source IP and port scanner.

     

    On the central exceptions.  Would these affect all machines or just the machines in the group?

     

    With Mcafee one thing I could do besides wildcards was exclude the name of the risk. 

    SEP finds IPSCAN.EXE as risk name "AngryIPScanner"



  • 5.  RE: group specific file exception 11.0.6

    Posted Dec 17, 2010 04:56 PM

    Centralized exceptions are like policies - they will have effect on all machines whioch are in groups you assign Centralized exceptions to. However, you can create exceptions also locally, on one client:

    How to Create Scanning Exceptions for both Managed and Unmanaged Symantec Endpoint Protection Clients
    http://www.symantec.com/docs/TECH91951



  • 6.  RE: group specific file exception 11.0.6



  • 7.  RE: group specific file exception 11.0.6
    Best Answer

    Posted Dec 20, 2010 10:08 AM

    Used the known exception centralized exception policy.  Thank you