Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SEPv11 - NTP Notification Popups on Client - How to disable?

Updated: 26 Sep 2010 | 16 comments
thatdude's picture
0 0 Votes
Login to vote

I've gone through every setting I can think of to disable the NTP notifications on the SEP client but I keep getting balloon notifications that something has been blocked. Am I missing something? I would like all notifications to the users as it relates to NTP to be disabled.

Comments

Prachand's picture
17
Feb
2010
0 Votes 0
Login to vote

How to Disable Client

How to Disable Client Intrusion Prevention Notifications in Symantec Endpoint Protection Manager

 

http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/fc03b94f7fe2910988257457005b1343?OpenDocument

Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)

thatdude's picture
17
Feb
2010
0 Votes 0
Login to vote

hmm... It doesnt appear to be

hmm... It doesnt appear to be an IPS block but I could be wrong. An example of the balloon message is Symantec Endpoint Security block network traffic from googletalk.exe

Vikram Kumar-SAV to SEP's picture
17
Feb
2010
0 Votes 0
Login to vote

 This is Firewall

 This is Firewall Notification 
Edit the firewall Policy
in the rule section on the top you will see a tab for notification.

thatdude's picture
17
Feb
2010
0 Votes 0
Login to vote

Ok thanks. I thought this was

Ok thanks. I thought this was the firewall. The bad news is I don't have anything checked or enabled on the notifications tab. Is there anything else to check in terms of firewall notifications?

Vikram Kumar-SAV to SEP's picture
17
Feb
2010
0 Votes 0
Login to vote

 Are your Clients in Client

 Are your Clients in Client Control Mode ?
If yes then you wiil have to do this on the client itself.

thatdude's picture
17
Feb
2010
0 Votes 0
Login to vote

I run mixed mode on all my

I run mixed mode on all my locations. I've even tried server control and still have the balloon notifications.

lawman 2's picture
17
Feb
2010
0 Votes 0
Login to vote

It sounds like you have a

It sounds like you have a firewall policy applied with a notification set. Look at the firewall policy applied. Under rules select the tab at the top for Notifications and see if there is a check in the box to Display notification on the client computer when the client blocks an application.

thatdude's picture
17
Feb
2010
0 Votes 0
Login to vote

I have 3 locations for now

I have 3 locations for now and a different firewall policy per location. Each firewall policy doesnt have anything enabled under the notifications tab. Any other ideas?

Thanks

Vikram Kumar-SAV to SEP's picture
17
Feb
2010
0 Votes 0
Login to vote

Look at rule 10 Allow all

Look at rule 10 Allow all applications
What is action set for it ? 

thatdude's picture
17
Feb
2010
0 Votes 0
Login to vote

I don't use a Allow All

I don't use a Allow All applications rule. All my firewall rules use Any for application. I control applications differently by basically using a blacklist with ADC. I do use Block All at the end of each firewall policy.

JT_T's picture
17
Feb
2010
0 Votes 0
Login to vote

Like Prachand mentioned, it

Like Prachand mentioned, it really looks like it's IPS which is giving those notifications. Have you turned off IPS notifications?

thatdude's picture
17
Feb
2010
0 Votes 0
Login to vote

This is difficult to explain

This is difficult to explain via chat but I'll give it a try.

This particular alert has to do with Google Talk and is triggered when I move between locations (i.e. VPN to Home location).

I checked the security logs and I do see some IPS entries for [SID: 21596] Jabber IM Client Connection detected.
Traffic has been allowed from this application: C:\Program Files\Google\Google Talk\googletalk.exe

If I check the Traffic or Packet logs for the same date/time stamp the traffic is shown as being allowed.

The Traffic and Packet logs showing a blockin googletalk.exe do not match the IPS log date/time stamp but it does show Googletalk.exe a few entries later being allowed and then blocked in the next entry. Looking at locations on the allowed and then blocked log entry it shows allowed for VPN and blocked when it changes to the Home location. A few seconds later googletalk.exe begins working again on the home location.

Outside of this discussion but almost related I'm not happy that SEP doesn't seem to allow administrator control of session state because when a location changes it drops the traffic when a deny all rule is being used in the firewall policy. If you could set allow existing connection then it would allow the existing ACK SYN flags from previous connections to continue while switching profiles. This is not that big of a deal as long as I can hide popup notifications.

AravindKM's picture
17
Feb
2010
0 Votes 0
Login to vote

Pls Clarify

According to your post the message you are getting is "Symantec Endpoint Security block network traffic from googletalk.exe" .Do you have Symantec Endpoint Security installed in your PCs,because Symantec Endpoint Protection will give message as Symantec Endpoint Protection blocked something.

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

thatdude's picture
18
Feb
2010
0 Votes 0
Login to vote

Yes it's Symantec Endpoint

Yes it's Symantec Endpoint Protection... i made a typo

AravindKM's picture
18
Feb
2010
0 Votes 0
Login to vote

Can you confirm the policy is

Can you confirm the policy is got applied in your clients.For this in SEPM console go to Clients---> <The group which the said client resides > ----->details.Here you will get the policy sl. no.(This will change if you do some changes in the policies,I mean the date and time part.) .Note it.Go to the client,In the client GUI go to Help and support----->Troubleshooting here it will show the currently applied policy sl. no.Mach it with the noted policy sl. no.Both should be same.

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Acretian's picture
25
Mar
2010
0 Votes 0
Login to vote

Its an IPS popup

this is an IPS popup and if you want disable this notification then you can follow the doc mention by Prachand above.
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/fc03b94f7fe2910988257457005b1343?OpenDocument