Symantec Endpoint Management (EPM) Partners Community

 View Only

Windows 7 Firewall indicate that "These Settings are being managed by vendor application Symantec Endpoint Protection", even when Symantec Endpoint Protection (SEP) 11.0 Network Threat Protection (NTP 

Mar 09, 2011 07:23 AM

Problem

You install Symantec Endpoint Protection 11.0 without Network Threat Protection on a Windows 7 machine.

Windows 7 Firewall indicate that "These Settings are being managed by vendor application Symantec Endpoint Protection, even when Symantec Endpoint Protection (SEP) 11.0 Network Threat Protection (NTP) is not installed.

In the Windows 7 Firewall, Domain networks shows "Connected" with a Red "X", Home or Work (private) networks shows "Not Connected" with a Red "X" and Public networks shows "Connected" with a Red "X". even though Symantec Endpoint Protection Network Threat Protection is not installed.

 

 

 

You notice that on the Advanced settings screens of the Windows Firewall Control Panel indicates that the Windows Firewall is "On"

This behavior differs from that in XP, as in XP the Windows firewall is explicitly off.

 

ERROR

 "These Settings are being managed by vendor application Symantec Endpoint Protection".

 

Cause of the this Error:  

The behavior of Windows 7 in regards to 3rd party firewalls (such as SEP) differs slightly than previous versions of Windows. In Windows 7, Microsoft changed Security Center to Action Center. In Action Center, a more universal interface was created for protection technology (Firewall, Antivirus, etc). Windows Firewall is indeed turned off when SEP NTP is enabled, indicated by the Installed Firewall list, as well as the General Firewall status section indicating that firewall rules are being managed by SEP. To verify the true Windows Firewall status: Open Action Center -> Expand "Security". Find line item "Network Firewall On". Below is a link "View installed firewall programs": Symantec Endpoint Protection is listed as installed and On, Windows firewall is listed as installed and Off

 

Solution  

This is expected behavior, and both SEP 11.0 and the Windows 7 firewall are working as intended.

However, incase you would like to change the settings, then perform the steps given below:

1) Create a New Group specifically for "Windows 7" machines in the Symantec Endpoint Protection Manager 11

2) Move all the Windows 7 Machines from their Respective groups to the group created specifically for "Windows 7" machines.

3) Once all the above steps are completed, Go to the Policies Tab for the specifically "Windows 7" machines.

4) Open the "Firewall Policy" and Click on "Create Non-shared from Copy"

5) Uncheck the Box that states "Enable this policy" and Click on "OK" button.

 

 

You will see the Firewall Policy gets grayed out. (as shown below)

 

 

 

6) Click on Tasks next to Firewall Policy [non-shared] and click on "Withdraw Policy" and then Click on "Yes".

 

 

7) You will see the Firewall Policy completely removed from the Policies TAB of the "Windows 7" group.

 

Once completed with the above steps, within sometime we will see the Windows 7 Firewall Settings will be with Green Check and the Message ""These Settings are being managed by vendor application Symantec Endpoint Protection" disappear.

 

 

Statistics
0 Favorited
1 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Mar 21, 2013 03:28 AM

Nice work 

Jan 17, 2012 04:07 AM

Hello,

You are carrying a older version of SEP (11.0.5002), it is advised to migrate to the Latest version of SEP 11.0.7101 (SEP RU7 MP1).

Check this Article to find how Old version are you carrying:

What are the Symantec Endpoint Protection (SEP) versions released officially?

https://www-secure.symantec.com/connect/articles/what-are-symantec-endpoint-protection-sep-versions-released-officialy

It is important to maintain consitency in the SEP 11 - check article below:

About Maintaining Consistency of Software Versions throughout a SEP 11 Organization

http://www.symantec.com/docs/TECH131660

Migrating to Symantec Endpoint Protection 11.0.7101 (RU7 MP1)

http://www.symantec.com/docs/TECH171552

Reason for Migration: 

Release notes for Endpoint Protection and Network Access Control 11

http://www.symantec.com/docs/TECH103087

 

Hope that helps!!

Jan 05, 2012 03:13 AM

I have removed the firewall policy in my client group.

Still got this on my client - https://www-secure.symantec.com/connect/imagebrowser/view/image/1685171/_original

I followed the guide above...

 

We are running sep v 11.0.5002.333.

 

Any ideas?

Dec 01, 2011 03:04 AM

Good Aritcle Mithun..Will helps many of us

Nov 21, 2011 02:48 PM

Nice article Mithun.. And thanks for sharing...

Nov 21, 2011 10:55 AM

me too, same result

Nov 18, 2011 10:15 AM

Nice article Dear

Nov 15, 2011 11:51 AM

Really nice article. Good job!!!

Sep 06, 2011 12:11 PM

I have found that the same procedure described here works on a Windows Server 2008 R2 64 bits. This article provided me the last step I didn't discovered by myself, that is to withdraw the policy, not technically needed for the solution, but cleaner :-)

Thanks.

May 26, 2011 04:50 PM

I tried these exact steps on a Windows 7 computer and they did not work.  I'm running 11.0.5002.333.  Has anyone else had similar troubles?

KH

Mar 20, 2011 04:55 PM

Good Article

Related Entries and Links

No Related Resource entered.