Endpoint Protection

 View Only
  • 1.  Client grabbed old policy

    Posted Mar 19, 2010 07:31 AM

    I have a client that had the latest policy but somehow pulled down an old one. The old policy should no longer exist as far as I know. Is there a setting I'm missing somewhere? I also tried to import the latest policy and it took but only until the client connected to SEPM at which point it pulled down the old one again. Any ideas? SEPM / Client is on RU5




  • 2.  RE: Client grabbed old policy

    Posted Mar 19, 2010 07:36 AM
    stop smc
    start run smc -stop
    navigate to : C:\Program Files\Symantec\Symantec Endpoint Protection
    delete the serdef.dat .bak( take a backup of it) 
    update the policy


    https://www-secure.symantec.com/connect/forums/endpoint-protection-client-using-old-non-existent-policies


  • 3.  RE: Client grabbed old policy

    Posted Mar 19, 2010 07:36 AM
    Both SEPM and client having correct date/time settings.?
    How many clients you are having this problem.?
    Whether all of them are belongs to same group?

    If it only one client try by repairing it from add/remove programs..


  • 4.  RE: Client grabbed old policy

    Posted Mar 19, 2010 08:54 AM
    @ Rafeeq - thanks I will try your suggestion

    @ AravindKM - Yes the time is correct on both now. There was an issue earlier in the week with daylight savings time change though. I have maybe 100 clients having this issue out 10k+...they are in different groups but each group may have multiple clients with wrong policy.


  • 5.  RE: Client grabbed old policy

    Posted Mar 19, 2010 10:13 AM

    I tried both suggestions with no luck. Going to re-install. Will update once complete.


  • 6.  RE: Client grabbed old policy

    Posted Mar 19, 2010 11:27 AM
    I removed SEP, ran cleanwipe, re-installed SEP. The client downloaded the old policy again so I'm stumped at this point. Could there be something hung up in the registry?


  • 7.  RE: Client grabbed old policy
    Best Answer

    Posted Mar 20, 2010 04:11 AM
    Remove SEP
    Delete following folders if present
    C:\Program Files\Symantec
    C:\Program Files\Symantec AntiVirus
    C:\Program Files\Common Files\Symantec Shared
    C:\Documents and Settings\All Users\Application Data\Symantec

    Also delete following reg keys
    HKLM\Software\symantec
    HKCU\Software\symantec
    Install SEP and try..


  • 8.  RE: Client grabbed old policy

    Posted Mar 21, 2010 01:04 AM

    Thank you AravindKM, this was this was the fix that worked for me.