Endpoint Protection

 View Only
Expand all | Collapse all

Upgrade to SEP Manager 14.2 loses policies

levd

levdJun 20, 2018 04:00 AM

John Owens

John OwensJun 28, 2018 10:00 PM

  • 1.  Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 18, 2018 05:52 PM

    Hi,

    Over the weekend, I upgraded our SEPM from 14.0 RU1 MP2 to SEPM 14.2.  Our server is a Hyper-V VM running W 2008R2. I noticed after the successful upgrade, some policies disappeared from our main group.  This group uses customized non-shared policies. After the upgrade the non-shared policies Firewall, Intrusion Prevention, Application and Device Control, Memory Exploit Mitigation, and Exceptions were gone from the group.  Any groups with shared policies were unaffected.  I also noticed some the locked settings in the remaining policies were now unlocked.  I created a checkpoint of the VM before the upgrade and was able to roll back to 14.0 RU1 MP2.  I tried the upgrade multiple times with same results each time.

    I looks like I will have to create new policies to replace the ones that disappeared.  I validated the built-in db after the update and it passed validation.  I have never seen this before after dozens of upgrades over the years.  Can anyone offer an explanation?

    Thanks,

    CQ



  • 2.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 18, 2018 05:57 PM
    Haven't seen this yet in test but haven't tested extensively. Latest version so engage support to start.


  • 3.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 19, 2018 04:32 AM

    Hi,

    @CQ gone meaning withdraw alike (group with no policies at all) or replaced by shared ones? I'm planning to do some upgrade test from same 14 RU1 Mp2 to 14.2 this week I'll look closely for those non-shared policies. Thanks for heads up. 

     



  • 4.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 19, 2018 06:48 AM

    @PG_PG

    The policies were withdrawn.  Interestingly, I had another group where some of the non-shared policies were withdrawn but also had a group with non-shared policies in which the policies were unaffected.



  • 5.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 19, 2018 10:01 AM

    Hi CQ,

     

    Im about to upgrade also. Do you only have this issue on your main group "my company"?

     

    LEVD



  • 6.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 19, 2018 12:38 PM

    @levd

    It is a second level subgroup of My Company.  The group does not inherit any policies from My Company.

     

    My Company (has default shared policies)

      I

      Company A (has its own shared policies not inherited)

            I

            Problem Group (has its own non-shared policies)



  • 7.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 20, 2018 04:00 AM

    CQ,

    Thanks for the info.

    LEVD



  • 8.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 20, 2018 06:55 AM

    CQ,

    Do you know about an easy way to recover this if it goes wrong? Offcourse i can snapshot my server however my DB is external SQL so once the tables are updated i guess i cant go back.
    Can you recover from within the manager?

    LEVD



  • 9.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 20, 2018 07:38 AM

    @levd

    I don't know of a way to recover the withdrawn non-shared policies.  I tried exporting them before the upgrade and importing after the upgrade,  This seemed to work but validated the database after the import and it failed.

    I guess I will open a support call but was hoping for a Symantec response in this forum. So far, nothing.   I have not had positive experiences with support in the past.



  • 10.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 20, 2018 07:51 AM

    Hi CQ,

    Ok. Can you update this post about your contact with support?
    Ill think ill wait with the update :)

     

    LEVD



  • 11.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 21, 2018 06:33 AM

    Any update from Symantec regarding this issue?



  • 12.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 10:03 AM

    Hello All,

    I have not seen this. Are any support cases open?  Does anyone have a DB backup from before the upgrade?  Are the policies being deleted completely, or just withdrawn?

    Thanks,

    John Owens



  • 13.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 10:10 AM

    Hi All,

    Please open a support case and provide case numbers.  Does anyone have a DB backup before the upgrade?



  • 14.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 21, 2018 10:37 AM

    I personaly tested this on a virtual machine, created 2 test groups.

    TEST1 - with Virus and Spyware policy and IPS policy non-shared

    TEST2 - with FW policy and ADC policy non-shared

    What happened after the upgrade to 14 RU2, from TEST1 group one of the non-shared policies disappeared and from TEST2 group both non-shared policies disappeared.

    We have a case opened for one of our customers, please take a look at it: 14789126

     



  • 15.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 10:48 AM

    @S_K

    I have taken ownership of the case and will attempt to reproduce in house.  I will keep you posted.

    John



  • 16.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 21, 2018 02:18 PM

    @john_owens

    I was going to open a case but I see @S_K has already done that.  For now I will hold off.  In my situation, SOME but not all non-shared policies were deleted from some my groups.  I run SEPM on a Hyper-V VM and have a checkpoint of the entire machine BEFORE the upgrade so I can easily roll back to help as needed.

    CQ



  • 17.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 02:44 PM

    I reproduced something similar.

    SEP 14 RU1 MP1 installed on SEPM.

    Created Test Group. Converted all policies over to Non-Shared policies.

    Upgraded SEPM to 14.2.

    Logged into SEPM. 

     

    Missing after upgrade:

    Intrusion Prevention

    Memory Exploit Mitigation

    Integrations

    Exceptions

     

    The other 4 Non-Shared policies remained after the upgrade.

     

    Remained after upgrade:

    Virus and Spyware Protection

    Firewall

    Application and Device Control

    LiveUpdate



  • 18.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 02:49 PM

    @CQ

    Please open a case. The more cases we have the better chance there is to get this fixed quickly.

     



  • 19.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 21, 2018 03:30 PM

    @john_owens

    Will do.  FYI in my case the Firewall policy was lost too.  Also, my live update policy was replaced by a different one.

     



  • 20.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 03:30 PM

    I have advanced this to Development/Engineering. If you would please open cases and reference Etrack 4186631 it would be very helpful.

    Thanks,

    John Owens



  • 21.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 21, 2018 03:41 PM

    @john_owens

    FYI my case # is 14896771



  • 22.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 03:54 PM

    Thank you. I took ownership of it for you and will drive it from here.



  • 23.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 21, 2018 03:56 PM

    KB you can subscribe to for updates.

    https://support.symantec.com/en_US/article.TECH250749.html?



  • 24.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 22, 2018 12:06 PM

    We have identified the issue and are working on a fix. Current ETA for availability is next week.
     



  • 25.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 22, 2018 01:18 PM

    Will the fix be SEP 14 RU2a or 14 RU2 MP1?



  • 26.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 22, 2018 01:29 PM

    It will be 14.2 refresh build. Current eta is next week.

     



  • 27.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 26, 2018 11:14 PM

    I ran into the same issue, not only did i lose my policies at first, but then account got locked out, luckily i did roll back to old VM and have an external SQL database and it held everything that was previous. I will put in a case as well and see what gets said, Needless to say after many of years of doing updates and upgrades, it seems after 12-14 it has been alot of problems, i had to redo a whole server because my 14.0 which was working fine, decided to no longer allow anyone to log into it.  i put a case in for that , but end result was i had to redo one from scratch, luckily i had exported copies of policies, and was able to import those, but had to do all the hardware device exceptions from scratch



  • 28.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 26, 2018 11:30 PM

    @john_Owens, I have the same issues as well , luckily was able to roll back , did you want me to add a case in for this?



  • 29.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 26, 2018 11:39 PM
    Hi Shawn. No need to open case. We have a fix that will be posted this week.


  • 30.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 26, 2018 11:39 PM
    Hi Shawn. No need to open case. We have a fix that will be posted this week.


  • 31.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 27, 2018 12:04 PM

    Hi John,

     

    Will you be updating this thread once this fix is released?

     

    Thanks



  • 32.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 27, 2018 01:12 PM

    Hi Michael,

    Yes, I will do that.  You can also subscribe to this document to be updated for when the refresh build is available.

    https://support.symantec.com/en_US/article.TECH250749.html?

    Thanks,

    John



  • 33.  RE: Upgrade to SEP Manager 14.2 loses policies
    Best Answer

    Broadcom Employee
    Posted Jun 28, 2018 04:19 PM

    14.2.760.0000 is now posted and available for download on FileConnect.  This will fix the Non-Shared Policy issue.



  • 34.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 28, 2018 09:49 PM

    Is there any change in SEP client side for this new version 14.2.760.0000?



  • 35.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 28, 2018 10:00 PM
    no client changes.


  • 36.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 02:56 AM

    What about if somebody already upgraded to 14 RU2? Is upgrade from 14 RU2 to 14 RU2 Refresh build possible?



  • 37.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 07:01 AM

    And what about the problem with unnmanaged client 14.2 RU - firewall rules are not working after system reboot? 



  • 38.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 07:23 AM

    Is anyone aware? Did you open a support case? If so, post the case number.



  • 39.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 07:51 AM

    I'm newbie here, pls advice how to open the case. And the problem is following. I'm using at the moment unmanaged client, first one, previos version 14.01RU - no any problem. After upgrading to 14.2RU (clear installation and rolling over), f.e. i have Application Rule allow browser (try IE11, Chrome, Firefox, Slimjet) any traffic, i made opposite rule in firewall Rules to block any traffic from browsers, and these rules are working until i make rebooting the system (try Win7x64 and Win10x64). When the system has been rebooted, Firewall Rules are in place but not working the above browsers clear walking in the net. 

    Google Translation


  • 40.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 07:53 AM

    Open a case following this:

    https://support.symantec.com/en_US/contact-support.html



  • 41.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 08:19 AM

    Case Number 15116949 and I attached info from SymDiag.



  • 42.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 08:35 AM

    But still not good to upgrade to 14 RU2 even the Refresh Build because still other issues which are new and not solved:

     

    Why Symantec didn't fix all these issues at once in a new release, for example 14 RU2 MP1?

     



  • 43.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 29, 2018 09:56 AM

    S_K -

    Are you having the Non-Shared Policy issue?  If so, you would need to roll back before the upgrade (Disaster Recovery) and then upgrade to the refresh build of 14.2.

    If you are not having that issue, you do not need to upgrade the SEPM to the refresh build.

    The other 2 issues you stated are being looked at for 14.2 MP1.  The non-shared policy issues was big enough we felt it needed to be addressed as soon as possible and that is why the refresh build was delivered.

    John



  • 44.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jun 29, 2018 01:33 PM

    How do I know if I'm downloading 14.2.760.000 from FileConnection? The dates of what I downloaded is June 22nd and 21st, which doesn't appear to the 14 RU2 refresh that I need to avoid this non-shared policy issue.



  • 45.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jun 29, 2018 01:42 PM

    The older builds were pulled.  The only version available is 14.2.760.000.



  • 46.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jul 06, 2018 08:25 AM

    is upgrade of the SEPM from 14 RU2 to 14 RU2 Refresh build supported because for previous builds it was not, for example:

    Upgrading from 14 MP1 (14.0.2332.0100) to 14 MP1 Refresh Build (14.0.2349.0100) is not supported

     



  • 47.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jul 12, 2018 01:27 PM

    After upgrade to 14.2.760.000 we are still missing custom policies. I have a SEP DB backup and access to a full backup of the server files pre-upgrade. What I don't have are exported policies to import that are current.

    Is there any way for me to recover those lost settings?



  • 48.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jul 12, 2018 01:36 PM

    Hi Seth,

    Did you restore to before upgrade and then upgrade with 14.2.760?  Just upgrading from the broken state to the new 760 build will not bring back the custom policies.

     



  • 49.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jul 12, 2018 02:51 PM

    Nope, we waited until the refresh build was available (it was a direct upgrade from 14.0.3876.1100). Guess I was overconfident that the issue was resolved and deleted the snapshot after the 'successful' install. Didn't realize I had a problem until days later when some systems were having trouble receiving definitions from the GUPs and server and discovered that the entire firewall rule was missing (guess Windows FW doesn't open port 2967 by default).

    If there is a simple way to pull it from an older server backup, great. If not, I will try to restore the pre-uprade server to a new VM and export the policies.



  • 50.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jul 17, 2018 02:20 PM

    John  Thanks for all of the work in the forums . . . .

    Is there a way to extract the firewall configurations from the backups?

     

    Thanks!



  • 51.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jul 18, 2018 10:36 AM

    Hi Joe,

    If you install another SEPM and restore from that Backup you could then export the policies.  There is no way to do it just from the backup itself though.

    John



  • 52.  RE: Upgrade to SEP Manager 14.2 loses policies

    Posted Jul 25, 2018 04:45 PM

    this version absolutely does NOT fix the issue with non-shared policies. I upgraded from 14.0.3752.1000 to 14.2.760 and lost nearly all of my shared policies. 14.2.760 was the first version of 14.2 that i have touched.



  • 53.  RE: Upgrade to SEP Manager 14.2 loses policies

    Broadcom Employee
    Posted Jul 25, 2018 05:00 PM

    David Fauci -

    Did you lose Non-Shared or Shared Policies?  We have many reports of the build correcting the issue with Non-Shared Policies.  If your non-shared policies were removed in this upgrade I encourage you to open a case.

    Thanks,
    John Owens