Endpoint Protection

 View Only
  • 1.  RU6 and Outlook Web Access

    Posted Apr 21, 2010 09:20 PM
    The last few days our OWA has gone down after installing RU6 on our Exchange 2003 server.  The only way to keep it up is running the smc -stop command and killing the Endpoint.  I have noticed in the client logs that there are a lot of iis events trying to change some registry settings that the SEP client is blocking.  Anyone see this yet? 


  • 2.  RE: RU6 and Outlook Web Access

    Posted Apr 22, 2010 12:31 AM
    In general, there are some very specific Exchange directories that need to be excluded on any AV product.  Check MS's KB for that info and best practice.

    And for OWA, I'd ONLY install AV and NTP with the firewall disabled.  App control shouldnt be on there, which is what I think is the only thing that could be trying to block reg keys.  


  • 3.  RE: RU6 and Outlook Web Access

    Posted Apr 22, 2010 12:33 AM
    Yes, the only thing we have on our server package is AV/AS and NTP.  The firewall policy is set to allow all.  The only reason we run NTP on our servers is to take advantage or Intrusion Protection.  We had major issues with a few QBOT and QAKBOT and other BOTS.