Quantcast
Channel: Symantec Connect - Products - Discussions
Viewing all 19521 articles
Browse latest View live

TWurl for HTTPS sites question

$
0
0
I need a solution

Hello everyone,

I'm trying to find a solution for how to use TWurl for populating a https site with content from another https site.

I got a task where we're asked to use the proxySG to replace the content on a webpage with the content from another webpage.

Example: if i go to fragbite.se i want the addressbar to say https://fragbite.se but the proxy should populate the page that is served to the client with content from https://bbc.com.

In tests that i've done, i've managed to get exactly this to work however, only when the OCS is using HTTP.

In the example below you can see the working TWurl rewrite for HTTP.

--------------------------------------------------------------------------------

define url_rewrite P
   rewrite_url_prefix "https://fragbite.se/""http://192.168.3.201/"
end

define action portal
rewrite(url,"https://fragbite.se/(.*)","http://192.168.3.201/$(1)")
transform P
end

define action force_uncompressed
delete (request.header.Accept-Encoding)
end

<Proxy>
url=https://fragbite.se/ action.portal(yes)

<Cache>
action.force_uncompressed(yes)

--------------------------------------------------------------------------------

(policy above was found here: https://origin-symwisedownload.symantec.com/resources/webguides/proxysg/certification/rp_webguide/Content/Topics/Tasks/URLRewrite.htm )

So the problem with the above CPL is that if i change http://192.168.3.201 to https://bbc.com then the URL in the addressbar is changed to https://bbc.com which is not what i'm looking for.

Is there anyone who have managed to make a working CPL for TWurl with between two HTTPS webpages?

Forwarding hosts doesn't work for this either as they are not dynamic and will only display content in ex. www.google.com/ (if the site tells the proxy to get a resource from somewhere else, the proxy doesn't listen to the server).

Have a wonderful day!

Best regards,

Matt

0

ASG | Radius accounting with Cisco ISE

$
0
0
I need a solution

Dear All

  Customer would like SSO authen solution  If Cisco ISE send Radius accounting via Syslog following reference from url as below,

https://community.cisco.com/t5/identity-services-engine-ise/forward-ise-2-4-radius-accounting-messages-to-check-point/td-p/3776561

ASG Proxy can support to receive Radius Accounting event as a SYSLOG message or not ?

but follow my understand Proxy must receive Radius accounting direct not via Syslog message.

and create authentication realm Policy Substitution it will support SSO authentication.

please recommend for this case.

Besr Regards,

CR

0

Category for URL and IP address are not the same in WebPulse Site Review

$
0
0
I need a solution

Hi

There's a problem that some website is affected by malware or virus and that website is categorized as negative category by URL. Negative category will be blocked by default due to policy but I found that I still can connect with IP address that resolved from URL that affected by virus. I check category for the IP address and it categorized as positive category so I have to manually add IP address in blacklist to resolve the issue. 

Is there a way to do this automatically to prevent client to access website like this?

Any help would be appreciated

0

AV Exclusions

$
0
0
I do not need a solution (just sharing information)

Hi,

I have just been reviewing the exclusions policy that we have for some of our servers and in particular the automatically created exclusions for certain products as mentioned in the Admin guide and HOWTO80947.

Reading the article the SEP agent is able to scan for third party products installed and build exclusions based on the scan results.

Is there a definitive list of applications that SEP supports?

Can this scan be manually initiated?

I have noticed that the agents detect some products but not others listed in the HOWTO guide.

Its not an issue to manually define the exclusions, but the automatic method appears to reduce the need for wildcard exclusions or file extension exclusions.

What are other peoples experiences?

Many thanks

0

Can't access web based applications

$
0
0
I need a solution

Hello, after installing SEP on the laptop, I can't access my Spiceworks application on our internal servers. I access Spiceworks using http://servername:port. I am able to reach the login screen of spiceworks. However, when i put my credentials i get a error stating incompatible browser. However, my browser is correct version

When i disable Symantec, it works fine?

Any assistance??

0

Image prep guide

$
0
0
I need a solution

Hi,

I don't have any training or experience creating images but I've ended up being tasked with creating one for some new PCs.  Are there any guides for prepping the image before capturing it with Ghost?  A few immediate questions I have are:

  • The PCs we have came pre-installed with Windows 10 Pro, do I need to re-install Windows 10 with a volume licensed version or will Ghost re-apply the current license?
  • Do I need to sysprep before or after joining the PC to the domain.

I'm sure there is a lot more I'm not even aware of or thinking about right now.  Any info is appreciated, thanks!

0

Emails to Clients Bounce Back 553 Error

$
0
0
I need a solution

Hi, 

I am unable to email any of our clients using Symantec as I am receiving a "553 Filter Message Error". I am unable to send emails, or even reply to old ones. This is now affecting my personal email accounts which I have attempted to use to be able to communicate with clients, but I am now getting the same error. Im not sure what you are using to filter messages, but filtering my personal accounts is a major issue, let alone the company Domain. 

Would it be possible for someone to contact me on how to get this resolved ASAP. I spoke to support who said they could not help me as I am not a customer, therefore, there is nothing to be done. We can't ask all of our clients to raise tickets on our behalf as it is incredibly unprofessional.

Thanks, 

0

Questions about deploy a several endpoint server

$
0
0
I need a solution

Dear,

At the moment my dlp infrastruture is a three tier deployment with one endpoint server for aprox. 3000 computer divide in a local site and several branch office.

Each bandwidth of this branch office is 4 megas , and the the local site has a bandwidth of 20 megas.

The local site has aprox, a 1800 computer and the each branch office has aprox 40 computer.

The endpoint server have 20 policy using a IDM, keywords and regular expressions

My idea is take a endpoind server for each branch office or agroup several branch office for on one endpoint server

And my questions about are

Its possibe to use a server with a role of file server for a endpoint server 

For 40 computer how is the hardware necessary for a deloy a endpoint server

I have to create one agent package for endpoint server

Its possible later via enforce change some computer to other endpoint server in case this is shoutdown

The last year the bandwith has present a saturation and shoutdown the enpoint server and i like the prevent this episode again using a local endpoint for the process of all the policy and later only send the result to the enforce server

0

AutoUpgrade Clients to SEP 14.2 and Maintain Existing Features

$
0
0
I need a solution

We are looking for a way to AutoUpgrade our SEP clients to version 14.2 MP1 and truly maintain all of the existing client features.

We have been "AutoUpgrading" SEP clients since version 11.  We have always used the "Maintain Existing Client Features When Updating" option during the AutoUpgrade.  This has never been a problem for us before now.

Recenlty we upgraded our SEP Managers to SEP 14.2 and used the "AutoUpgrade" function with "Maintain Existing Features" and found that all the clients had a new feature installed called Application Hardening.  This was totally unexpected.  This change was not documented in the Release Notes 

It seems that Symantec Endpoint Protection Hardening was introduced between the 14.0 and the 14.2 releases and as a result, you could not upgrade 14.0.x clients with SEP Hardening automatically.

NOTE that Application Hardening requires a separate license to use and then, it can only be enabled and managed via the Cloud management portal.  We are not using the Cloud-based features and currently do not have any plans to.

So, in 14.2, when you upgrade all of your clients with AutoUpgrade and use the "Maintain Existing client features when updating" option, your clients will have the Application Hardening feature installed.

We do not want to have a component installed on our clients that we are not going to use and that we won't be purchasing a licnese for.

Does anybody know of a way for us to AutoUpgrade our clients and still Maintain the existing client features during the upgrade?

Was everybody even aware that this happens?

0

Best Practices guide for Blue Coat Intelligence Services (BCIS) Advanced Web Bundle?

$
0
0
I need a solution

I now have a subscription to Blue Coat Intelligence Services (BCIS) Advanced Web Bundle for my ProxySG appliances - formerly, I only had BCWF (Blue Coat Web Filter).

I'm searching for any kind of "Best Practices" guide to help me implement some of the new features that I now have available... specifically, Threat Risk Levels, Security Categories and Geo IP.

The V6.7.x ProxySG Administrator Guide only briefly touches on these areas, and I'd love to have something more in-depth on this topic.

Thanks,

Lee

0

Mail from 92.222.92.253 is no reaching destination

$
0
0
I need a solution

Hello,
Since a few days ago, messages from the server correo.efismart.es (92.222.92.253) are not arriving to destinations managed by you. As an example, legitimate mails sent from xxxxx@montajesfiver.com to  xxxxx@abanca.com do not reach destination, the mails are accepted by destination servers but they not appear in the recipient mail, so I undertand that the mail is silently rejected. The domain montajesfiver.com is managed by the correo.efismart.es server.

I have revised the mail server logs of the last few days and I do not find any suspicious activity, only the usual mail movement. Also I have check the mail address agaisnt several reputation services and all of them return that the reputation is good or neutral, also the ip is no listed in any blacklist service but yours.

The IP of the server appears with negative reputation in https://ipremoval.sms.symantec.com/. I tried to send an investigation request but the form keeps show up again and again when I press the investigate submit button, so I am not sure that the request is sent.

Any help will be appreciated.

Many thanks,

Enrique

0

How to Find unauthorized Local administrator with SEP HI policy ?

$
0
0
I need a solution

Hi,

i am looking a way to Find unauthorized Local administrator with SEP HI policy ?

0

MS moves to SHA2 only code signing for patches

$
0
0
I need a solution

Are any updates needed to ITMS Patch Management system related to Microsoft move from dual-signed patches to SHA2 only patches? 

https://support.microsoft.com/en-us/help/4472027/2...

I want to make sure PM doesn't view patches as invalid if they are missing the SHA1 signature.  

0

Anti virus scanning while file upload before save into sever

$
0
0
I need a solution

I have requirement to do Anti virus scanning during upload the docuement in Java based web application without saving the file on server. I am urgently looking for solution (Technical & Licensing ). Please do let me know ASAP.

0

Remove Property not possible

$
0
0
I need a solution

Hi,

a few days ago we´ve updated our Workflow Solution Environment to 8.5. Since that it seems that it is not longer possible to remove Properties on Properties Tab.

I can create some new Properties without any problems. When i click on "Remove Property" button the coursor jumps to first postion an nothing else happens.

Does anyone have an idea?

BR

Patrick

0

Client Updation Step

$
0
0
I do not need a solution (just sharing information)

Flow from SEPM to Client PC

0

Unable to block audio/video streaming

$
0
0
I need a solution

Hi all,

We have not find a way to block audio/video streaming in WSS. Has anyone managed to configure and block web streaming successfully?

Regards,

0

Upgrade System Build

$
0
0
I need a solution

Hello and Welcome everyone

In my company we are using Endpoint Encryption 11.1.3 (Build 804) with Autologon and I wonder if you found any solution to "upgrading system build" problem in Windows 10 ?

We are preparing for massive migration from Windows 7 to Windows 10 and problem is , When we try upgrade system build 1803 to 1809 etc , after first restart  , upgrade crashes because Build setup loads before hard drive logon 

i know script methode for solving that but keeping every pc/laptop up-to-date with it might be...problematic (500+ pc updated by WSUS)

Looking forward to hear from you 

Cheers

Norbert

0
1553536013

SEP shows Browser and Network Intrusion Prevention problems

$
0
0
I need a solution

Hi everyone,

A lot of our clients (Windows 7/10; SEP 14.0.3752.1000.105) show recently the problem that the Network Intrusion Prevention and Browser Intrusion Prevention is turned off. Then automatically it turns on again and sometime later it is off again.

The problem is that I cannot really find the issue. I also tried to deactivate the warning in the Client User Interface Settings but it has no effect. Can anybody give me a hint where I should look? Unfortunately, our installation is not in English, so it can be a bit hard to find the correct translation in the menu ;)

Thanks
Stephan

0

Adding a new Active Directory on SEE Managent Server

$
0
0
I need a solution

And I need to put on my SEE Management Server a new AD from a trusted domain. This other Active Directory is in  another server, with another IP range. How can I do this?

Thanks, for any help.

0
Viewing all 19521 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>