Endpoint Protection

 View Only
  • 1.  System lockdown function blocks all *.exe files on the clients.

    Posted Dec 15, 2015 12:47 AM
      |   view attached

    Hello everyone.
    We use SEP V 12.1.6. The OS on server is Win server 2012. We have 500 clients with WINXP SP3 Proffesional. System Lockdown does not work properly. First of all we make fingerprint file and after updating Symantec Live the md5 file of UMEngx86.dll is altered. After that SLD function blocks all *.exe files on the clients. 
    What do we do wrong?



  • 2.  RE: System lockdown function blocks all *.exe files on the clients.

    Posted Dec 15, 2015 08:13 AM

    Hello everyone.
    We use SEP V 12.1.6. The OS on server is Win server 2012. We have 500 clients with WINXP SP3 Proffesional. System Lockdown does not work properly. First of all we make fingerprint file and after updating Symantec Live the md5 file of UMEngx86.dll is altered. After that SLD function blocks all *.exe files on the clients. 
    What do we do wrong?



  • 3.  RE: System lockdown function blocks all *.exe files on the clients.

    Posted Dec 15, 2015 08:36 PM

    Was UMEngx86.dll part of the fingerprint file?

    If everything is being blocked it sounds like you enabled it without letting it run in log mode for some time. It's best you let it run in log only mode to see what exceptions need to be. If exceptions need to be made they will need to be manually added.



  • 4.  RE: System lockdown function blocks all *.exe files on the clients.

    Trusted Advisor
    Posted Dec 16, 2015 09:39 AM

    Over how long a period did you run the fingerprint file? 

    Did you allow the machines having the fingerprint file to be used as per normal over a period of time? 

    If only a short period of time was used for the figerprint file then those files may not have launched in the time period not allowing the file to capture them so when you've put lockdown in enforcement mode it locks them down. 

    Did you follow the system lockdown configuration?
    https://support.symantec.com/en_US/article.HOWTO80848.html