search cancel

Network Intrusion Prevention appears to be disabled after a restart on Windows Embedded

book

Article ID: 162464

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

After you install and restart the Symantec Endpoint Protection (SEP) client on a Windows Embedded-based device, you see a notification that indicates that intrusion prevention is restored. The Symantec Endpoint Protection System log indicates that the network intrusion prevention driver failed to load, but then was restored and fully enabled. You want to know if you need to take any further action.

System log indicates the following:

Network Intrusion Prevention is not protecting machine because its driver was unloaded.

About a second later, however, another message appears:

Network Intrusion Prevention has been restored and enabled.

Cause

This event occurs on a device where the file-based write filter (FBWF) is enabled and on which you did not immediately run LiveUpdate

Resolution

When this event occurs, there is no further action you need to take.

Attachments