When Symantec Endpoint Protection (SEP) for Linux clients are part of a group with Host Integrity enabled, the "Monitor mode" configuration in the "Virus and Spyware Protection policy > Linux Settings > Global Scan Options" may not function as expected. Files may be quarantined even when configured to log/monitor only.
Symantec Agent for Linux 14.3 RU1 and later
Symantec Endpoint Protection Manager (SEPM)
Operating System: Red Hat Linux (and other supported Linux distributions)
Host Integrity enabled in the client group
Host Integrity is enabled for the client group, causing SEPM to automatically generate a second location policy alongside the "Default" location, known as the "Quarantine" location. While SEP for Linux does not support location awareness and is designed to use only the "Default" location settings, the Linux agent's policy parser currently reads all location policies in sequence. The agent applies the settings from the last location it reads. Because the "Quarantine" location appears last in the policy, settings in that location (where Monitor mode and TCP mode are often disabled by default) override the configuration in your "Default" location.
To ensure the correct policy is applied, use one of the following workarounds:
Fix: A code fix is being tracked so the Linux agent applies only the Default location's settings and ignores all other locations, consistent with location awareness not being supported on Linux. This issue is targeted to be fixed in SEP 14.5 version.