Endpoint Protection

 View Only
Expand all | Collapse all

IPS issues

  • 1.  IPS issues

    Posted May 09, 2013 09:21 AM
      |   view attached

    OK here is the issue:

     

    SEPM reports IPS failures on all workstations and only 1 server. All the other servers are updating just fine.  The AV definitions are working just fine. 

    I have tried to update it manually and add the JDB file. I have also tried

    "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\bin\LuCatalog.exe" -cleanup


    Ran "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\bin\LuCatalog.exe" -update

    No change

    Tried to Delete all files under C:\ProgramData\Symantec\Definitions\SymcData\spcCIDSdef

    and Ran Syslink replace.

    none of this fixed it.

    It is odd that it was working and then just stopped last month. All the workstations are running XP professional and Windows 7 professional.

    I have attached a screenshot of the computers. The failure ratio is 100%?



  • 2.  RE: IPS issues

    Posted May 09, 2013 09:22 AM

    JDB will not update IPS, you need to run liveupdate from SEPM to get it downloaded.



  • 3.  RE: IPS issues

    Posted May 09, 2013 09:24 AM

    The JDB only updates AV definitions so it won't work for IPS content.

    What happens if you run LiveUpdate on an affected client to test, does it update this way?



  • 4.  RE: IPS issues



  • 5.  RE: IPS issues

    Posted May 09, 2013 10:12 AM

    That is what I thought but I was trying everything I could find.

     

    I also tried the date thing as well.

     

    I am having to uninstall and reinstall the liveupdate on the test PC.  I had to change and update the policy to allow the users to use liveupdate.  Thanks for the help.  

    Give me a few more minutes as I am rebooting the PC.



  • 6.  RE: IPS issues

    Posted May 09, 2013 11:46 AM
      |   view attached

    OK so I rebooted and did the live update.  See the pic of what it says.  I looked on the site and the current is 5-08-13



  • 7.  RE: IPS issues

    Posted May 10, 2013 03:38 AM

    Are your clients getting updates from SEP or from liveupdate symantec servers? Your first post informs about  changes done on the SEPM level, while you last screenshot shows LUE session probably from client.

    If the definitions are being provided by SEPM - has the server already those IPS defintiions ready for deployment? Admin -Servers- Local site - Show Liveupdate downloads?



  • 8.  RE: IPS issues

    Posted May 10, 2013 07:26 AM
    You can manually update IPS Definition. 1) Create "incoming" folder on "C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\IPSDefs" path. 2)copy latest IPS definition content from updated system on above mentioned path and paste into "incoming" folder which created on affected system. After the successfully copy this content, wait for 10 to 15 min.


  • 9.  RE: IPS issues

    Posted May 10, 2013 08:39 AM

    As a test I on a few machines, I uninstalled LU and reinstalled with a older pkg.  It installed fine but when running liveupdate from the client or by using luall.exe it didn't do anything.

     So I took the folder SyKnAppS from a working computer and pasted it to the non-working one and overwrote anything there.

    This worked on some machines and showed the correct date for the NTP, I was able to run liveupdate and it updated the IPS to the correct definitions.  However,  it only worked on some machines and now I am showing 14 out of 22 that are bad.

     

    I hope this helps more.



  • 10.  RE: IPS issues

    Posted May 10, 2013 09:49 AM

    Yes they are pulling from SEPM.  Yes the server has the latest updates.

     

    Yea the last screen shot was of a client showing what running directly from live update shows.

     

    I have tried both SEPM and Liveupdate servers but no go on both except the AV def.

    I have added more information to my last post and hope that helps more. I am at a loss now.



  • 11.  RE: IPS issues

    Posted Jun 18, 2013 11:27 AM

    Just an update to the above - and good news for admins and end users who find themselves in this situation!

    SONAR and IPS Intelligent updater (IU) are now available on :

    http://www.symantec.com/security_response/definitions.jsp

    NOTE: These SONAR and IPS Intelligent updater are only for SEP 12.1 RU3.

    For more information, please see Latest Symantec Endpoint Protection Released - SEP 12.1.RU3