![]() ![]() Option 2 - If security policy demands a more strict control than option 1, fingerprint list can be updated to include new binaries in the new definitions. Please see screen shot below for reference. Click OK and OK again to close all dialogue windows.Put the above 2 paths in and make sure "Use wildcard matching" is selected.Click Add button under "The following files are approved:".Click System Lockdown link under "Location-independent Policies and Settings".In Clients page, select the group(s) and click Policies tab in the right pane.In Symantec Endpoint Protection Manager (SEPM) console #HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion\Common Client\PathExpansionMap\INSTALLDIR#*\* #HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion\Common Client\PathExpansionMap\APPDATA#*\* Option 1 - Add the following 2 SEP file paths so that binaries under these paths are allowed even if they are not in the fingerprint list. If system lockdown is fully enabled instead of in test mode, then SEP client system log may contain error stating "An update for Virus and Spyware Definitions Win32 failed to install. Target: C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\.2093.105\Data\Definitions\VirusDefs\tmp4c57.tmp\ECMSVR32.DLL. ![]() Caller process: C:\Program Files\Symantec\Symantec Endpoint Protection\.2093.105\Bin\ccSvcHst.exe. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |