Symantec client upgrade to Endpoint Security Agent 2.5.x.x (SEP 16) blocks access to an application allowed in the Firewall Policy.
search cancel

Symantec client upgrade to Endpoint Security Agent 2.5.x.x (SEP 16) blocks access to an application allowed in the Firewall Policy.

book

Article ID: 414223

calendar_today

Updated On:

Products

Endpoint Security

Issue/Introduction

After the Symantec client is upgraded from 14.x to the Endpoint Security Agent 2.5.x.x (SEP 16), access to an application allowed in a Firewall rule that uses a UNC path to the application and the MD5 File Fingerprint, is now blocked. Prior to the client upgrade, the Firewall rule worked as expected and no changes were made to the Firewall policy prior to the SEP 16 client upgrade.

Environment

Symantec Endpoint Security (SES) client versions 14.x and higher upgraded to the Endpoint Security Agent version 2.5.x.x (SEP 16) using an Installation Package containing ESA version 2.5.x.x (SEP 16)

Cause

With version 2.5.x.x of the Endpoint Security Agent (SEP 16),  process information using a FW rule configured with a UNC path and MD5 File Fingerprint at times could fail to process as expected with the SymNets component. 

Resolution

This issue was resolved through content with the release of Endpoint Security Agent version 2.6.x.x (SEP 16.0 Update 1). This issue occurs when using an Installation Package created with Endpoint Security Agent version 2.5.x.x (SEP 16.0), and prior to the ESA version 2.6.x.x (SEP 16 Update 1 release). 

To create an Installation Package for the latest version of SEP 16, at the SES console, go to Settings > Installation Package, then select, "16.0 (latest version)" from the list under, "Symantec Agent Version". 

Additional Information

To verify the ESA version from the SEP 16 client interface, open the SEP 16 client on the device, then click on the "i" to see the information, click on "Troubleshooting" and change the "Category" using the drop down to select "Engines". Scroll down and look for the "Endpoint Security Agent Platform". That will show the version of ESA for that SEP 16 client.

 

To verify the ESA version from the SES console, go to Devices then locate and open the device. The ESA and SEP versions will be displayed in the "Agent Information" section.

 

Endpoint Security Agent (SEP 16) client information is found here: Symantec Endpoint Protection (SEP) 16