Endpoint Protection

 View Only
Expand all | Collapse all

Please help me about ADC

Migration User

Migration UserFeb 24, 2013 08:04 PM

Migration User

Migration UserFeb 24, 2013 08:21 PM

Migration User

Migration UserFeb 25, 2013 08:37 PM

  • 1.  Please help me about ADC

    Posted Feb 23, 2013 03:15 AM

    Hi everybody

    ADC of My SEP have strange phenomenon ..! please see my picture

     

    Please help me slove this issue

    Thanks/phamduyus



  • 2.  RE: Please help me about ADC

    Posted Feb 23, 2013 03:53 AM

    Hi,

    What sep feature do you have installed ?

    What happend when you disable NTP feature ?

    Do you have blocked .exe extension thorugh SEP ?



  • 3.  RE: Please help me about ADC

    Posted Feb 23, 2013 04:01 AM

    Hi

    What sep feature do you have installed ? => yes, I installed ADC at client

    What happend when you disable NTP feature ? => I don't known. can you more explain

    Do you have blocked .exe extension thorugh SEP ? => yes, I create a rule block *.exe extension thorugh SEP (you see my picture. first is blocked by SEP



  • 4.  RE: Please help me about ADC

    Posted Feb 23, 2013 04:10 AM

    What is your current verson of SEPM?

    What is OS Version where this policy not working?



  • 5.  RE: Please help me about ADC

    Posted Feb 23, 2013 04:11 AM

    s it possible that you can share the small snapshot of your configured policy?



  • 6.  RE: Please help me about ADC

    Posted Feb 23, 2013 04:26 AM

    Try with file name only...or with checksum of file.



  • 7.  RE: Please help me about ADC



  • 8.  RE: Please help me about ADC

    Posted Feb 23, 2013 04:33 AM

    Check the below

     

    How to configure Application Control in Symantec Endpoint Protection 11.0 : Configuring Application Control Policies

     

     

    Article:TECH102525  |  Created: 2007-01-26  |  Updated: 2010-12-08  |  Article URL http://www.symantec.com/docs/TECH102525

     



  • 9.  RE: Please help me about ADC

    Posted Feb 24, 2013 07:45 AM

    No it doesnot seems like SEP is blocking it. Can we re check it by disabling the SEP and executing this application?



  • 10.  RE: Please help me about ADC

    Posted Feb 24, 2013 03:01 PM

    If you can, post a screen shot of the rule or export the policy and attach so I can test as it is.



  • 11.  RE: Please help me about ADC

    Posted Feb 24, 2013 03:38 PM

    "the handle is invalid" does really look like SEP error.

     

    - is this file embedded to Word or only linked?

    - from the screenshot it references the path to ...temporary internet files -> content IE5 and mspaint[1].exe - can you confirm this linkage is really correct? or should it be on the root of teh D: drive?

    - if you disabled SEP on that machine can you access this file without issues?

    - is this a XP machine? are you able to reproduce the issue on win7?



  • 12.  RE: Please help me about ADC

    Posted Feb 24, 2013 07:53 PM

    What is your current verson of SEPM? => SEP 11.x

    What is OS Version where this policy not working? => OS = XP pro 32 bit



  • 13.  RE: Please help me about ADC

    Posted Feb 24, 2013 07:53 PM

    - is this file embedded to Word or only linked? => File Embedded - Not link

    - from the screenshot it references the path to ...temporary internet files -> content IE5 and mspaint[1].exe - can you confirm this linkage is really correct? or should it be on the root of teh D: drive? => when running I saw create file in ".... temporary internet files -> content IE5 and mspaint[1].exe"

    - if you disabled SEP on that machine can you access this file without issues? => If disable SEP then same result

    - is this a XP machine? are you able to reproduce the issue on win7? => Running on OS XP Pro 32 bit



  • 14.  RE: Please help me about ADC

    Posted Feb 24, 2013 08:04 PM

    Please see ADS policy config



  • 15.  RE: Please help me about ADC

    Posted Feb 24, 2013 08:21 PM

    Please see ADC policy config



  • 16.  RE: Please help me about ADC

    Posted Feb 25, 2013 01:56 PM

    - if you disable SEP on that machine can you access this file without issues? => If disable SEP then same result

    ...this would be pointing not really towards SEP blocking this file execution



  • 17.  RE: Please help me about ADC

    Posted Feb 25, 2013 08:37 PM

    have anyone give to me yours advise this issue ??