Advanced Threat Protection

 View Only
  • 1.  ATP 2.3 and SEP 14 - Blacklist

    Posted Feb 15, 2017 09:05 PM

    Hello,

    I have a SEP 14 SEPM server and at ATP 2.3 server. When I configure black lists on the ATP server the ATP server does not enable blacklisting on the SEPM server per the Installation and Adminstration guide.

    Any suggestions?

    Cheers

    Cameron Mottus



  • 2.  RE: ATP 2.3 and SEP 14 - Blacklist

    Broadcom Employee
    Posted Feb 23, 2017 06:05 PM

    Hello again!

    Are you adding an MD5 hash to the blacklist or a SHA2 hash?

    Sounds like you've read the documentation, but this KB doc might clear up any confusion: https://support.symantec.com/en_US/article.TECH234046.html



  • 3.  RE: ATP 2.3 and SEP 14 - Blacklist

    Posted Feb 26, 2017 02:24 PM

    Hi TSE-JDavis,

    That is what should happen per the documenation. For some reason ATP is unable to enable System Lockdown.

    ATP is able to push the rest of its commands to the SEPM.

    The customer will be opening a technical support case.

    Thanks!