"Monitor mode" configuration in the Linux Virus and Spyware Protection policy may not function as expected
search cancel

"Monitor mode" configuration in the Linux Virus and Spyware Protection policy may not function as expected

book

Article ID: 451876

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

When Symantec Endpoint Protection (SEP) for Linux clients are part of a group with Host Integrity enabled, the "Monitor mode" configuration in the "Virus and Spyware Protection policy > Linux Settings > Global Scan Options" may not function as expected. Files may be quarantined even when configured to log/monitor only. 

Environment

Symantec Agent for Linux 14.3 RU1 and later
Symantec Endpoint Protection Manager (SEPM)
Operating System: Red Hat Linux (and other supported Linux distributions)
Host Integrity enabled in the client group

Cause

Host Integrity is enabled for the client group, causing SEPM to automatically generate a second location policy alongside the "Default" location, known as the "Quarantine" location. While SEP for Linux does not support location awareness and is designed to use only the "Default" location settings, the Linux agent's policy parser currently reads all location policies in sequence. The agent applies the settings from the last location it reads. Because the "Quarantine" location appears last in the policy, settings in that location (where Monitor mode and TCP mode are often disabled by default) override the configuration in your "Default" location.

Resolution

To ensure the correct policy is applied, use one of the following workarounds:

  1. Sync Policies: Ensure that "Monitor mode" (and TCP mode, if used) is enabled in the Virus and Spyware Protection policy of both the Default and Quarantine locations. This ensures the agent applies the intended setting regardless of which policy is parsed last.
  2. Disable Host Integrity: If Host Integrity is not required for this specific group of Linux systems, disable it. This removes the auto-generated Quarantine location and prevents the override from occurring.

Fix: A code fix is being tracked so the Linux agent applies only the Default location's settings and ignores all other locations, consistent with location awareness not being supported on Linux. This issue is targeted to be fixed in SEP 14.5 version.