Endpoint Protection Small Business Edition

 View Only
  • 1.  Problems with Policy in SEP SME

    Posted Jul 21, 2010 11:15 AM

    We have EP 12 (12.0.1001.95) installed at our office. We have three Virus and Spyware Policies (guessing these are defaults). 1)Virus and Spyware Policy 2) )Virus and Spyware Policy - High Security 3))Virus and Spyware Policy - High Performance. All desktops, laptops and ervers are assigned to the first Policy.  Within that policy, we have a scheduled scan called Daily Scan (again probably the default) and it is enabled with the Start time as 11:45PM.

    Problem:

    The Daily Scans are starting anywhere between 1AM to 530AM on our servers. Desktops, I have also notice have a scan running when the end user goes to login (all workstations and servers are left ON at night).

    The 1AM one is not to concerning but still bugs me that it is over an hour late. The ones that are causing problems are those that are starting at 530AM and even one (SQLServer) is starting at 730AM!  Obviously, the daily scans are causing performance issues and I have to end the scan manually.

    Under Scan for Threats the "Daily Scan" is listed. It is not removable or editable which tells me these are policy based.  Can any one explain why I scans are starting so late?





  • 2.  RE: Problems with Policy in SEP SME

    Posted Jul 21, 2010 11:40 AM
    Check if you have set ramdomization option enabled for your scans..


  • 3.  RE: Problems with Policy in SEP SME

    Posted Jul 21, 2010 11:53 AM
    Where would I find that option? I do not see it under policies.


  • 4.  RE: Problems with Policy in SEP SME

    Posted Jul 22, 2010 09:55 AM

    So I changed the start time from 1145 to 1030 and now instead of starting between 1AM to 5AM, they started at 11PM-3PM (3:07AM on SQL vs 530AM) What the heck?  System times are all valid and in the same time zone (CST)




  • 5.  RE: Problems with Policy in SEP SME

    Posted Jul 22, 2010 10:30 AM

    The randomization feature is not available on SEP 12 SBE. What happens if you apply one of the other policies? Can we see if the scans are still random? What AV product was installed on these systems before SEP 12?


  • 6.  RE: Problems with Policy in SEP SME

    Posted Jul 22, 2010 10:56 AM
    I applied the High Performance which is set to only scan on weekends. Honestly that is really enough I think on a server for a FULL scan. I set it to come on at 11PM. I will have to wait and see if 1)the servers in fact get the correct policy 2) for a full scan over the weekend and see when it was actually started.

    We were previously using version 9 or 10 of the "Corporate Symantec" per End Point Stuff.


  • 7.  RE: Problems with Policy in SEP SME

    Posted Jul 22, 2010 11:10 AM
    It is very possible that there is some leftover of the old SAV in the registry that is kicking off those scans. This KB may apply to your situation.

    http://service1.symantec.com/support/ent-security.nsf/docid/2008020707573048?Open&seg=ent