There is an option in SEPM to that can be configured to disable the Windows firewall but I imagine this worked fine prior to upgrade?
http://www.symantec.com/docs/TECH197660
This was the closest I could find in the fix notes for RU1:
After disabling the SEP firewall policy, the Windows Firewall erroneously shows “…managed by vendor application Symantec Endpoint Protection…” until a restart
Fix ID: 4013065
Symptoms: You disable the Symantec Endpoint Protection firewall policy in Symantec Endpoint Protection Manager and update the policy on the Symantec Endpoint Protection client. Afterwards, the Windows Firewall on client shows “…managed by vendor application Symantec Endpoint Protection…” until you restart the computer.
Solution: Updated Symantec Endpoint Protection’s ownership of the Windows Firewall if the action option is “No Action” or if the Symantec Endpoint Protection firewall policy is disabled or withdrawn. This change makes the behavior consistent between before and after restart.
RU1 MP1 had a fix as well but it was for Windows 10 only.