Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Unable to re-activate Firewall as user

Updated: 22 May 2010 | 13 comments
flutti's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hello everybody

Since we are currently in the proof of concept phase for migrating from SAV10 to SEP11, I have deployed the SEP11 client to various test users.
On the notebooks, the firewall is activated per default.
There are some users on the network, which are allowed to turn off the firewall for testing purposes.

The problem we ran into now is that these users can turn off the firewall, but cannot turn them on again.
Being logged in as local administrator, turning the firewall on again is possible.
Did I miss something in the policies of SEP that enables the normal user to turn the firewall on again?
I mean - I almost could understand it that you cannot turn off the firewall as normal user. But not being able to turn it ON again as normal user makes no sense to me.

Any ideas or input on this one is appreciated.

Comments

Rafeeq's picture
17
Mar
2010
0 Votes 0
Login to vote

hi

you just need to click on fix all to trun on the firewall. You dont get that option?
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007110514540148

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

flutti's picture
17
Mar
2010
0 Votes 0
Login to vote

Screenshot

One of the users sent me this screenshot.
Where is this button supposed to be?

firewall_disabled_frbu_01.JPG
AravindKM's picture
17
Mar
2010
0 Votes 0
Login to vote

click on options near the NTP

click on options near the NTP ,you will get option for enabling it..

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

flutti's picture
17
Mar
2010
0 Votes 0
Login to vote

This is true

You are right, this is the case.
But it does not activate the firewall at all when you click on "Enable Network Threat Protection".

Regarding this "Fix"-button: When logged in as local administrator, this button is available.

Rafeeq's picture
17
Mar
2010
0 Votes 0
Login to vote

hi

check the value of registry key when you enable and disable it

https://www-secure.symantec.com/connect/articles/symantec-endpoint-protection-few-registry-tweaks

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Rafeeq's picture
17
Mar
2010
0 Votes 0
Login to vote

hi

sepm , did you allow your users to disable and enable NTP
open sepm
clients - policies- location specific
click on server control
check if you have enabled users to activate NTP

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

AravindKM's picture
17
Mar
2010
0 Votes 0
Login to vote

open sepm clients - policies-

open sepm
clients - policies- location specific
click on server control--customize 
any time you specified before re-enabling network protection?

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

flutti's picture
17
Mar
2010
0 Votes 0
Login to vote

@ Rafeeq: I have checked the


@ Rafeeq:
I have checked the Registry on the user's machine.
After re-activating NTP as user, the value of the key does not change from 0 to 1.
When re-activating NTP as local administrator, it changes to 1.

On the SEPM, the settings are like this, yep.
I allow the user via location specific settings to deactivate NTP.

@ AravindKM:
any time you specified before re-enabling network protection?
What do you mean with this?

AravindKM's picture
18
Mar
2010
0 Votes 0
Login to vote

Sorry for non-clarity.. In

Sorry for non-clarity..
In fact I mean the setting "amount of time before re-enabling Network Threat Protection"

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

flutti's picture
18
Mar
2010
0 Votes 0
Login to vote

No problem. I did not

No problem.
I did not activate this option.

This seems quite strange to me ... May it be because the SEP11-Client Version installed on these Clients is 11.0.4014.26 and the SEPM runs on 11.0.5002.333?

AravindKM's picture
19
Mar
2010
0 Votes 0
Login to vote

I am not finding a fix in

I am not finding a fix in 11.0.5 anyway just for testing try it..

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

flutti's picture
21
Mar
2010
0 Votes 0
Login to vote

Fixed it?

Well ... I seem to have fixed this by re-installing the SEP11-Client. But now in version 11.0.5002.333, which is the same version as the SEPM.
I have absolutely no idea why on earth this fixed this problem, but okay - as long as it does the job I'm fine with it.

One issue less, let's move to another ...

AravindKM's picture
22
Mar
2010
0 Votes 0
Login to vote

Happy to hear your problem

Happy to hear your problem got solved..

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind