Posted on 07-27-2018 10:36 AM
About 2 weeks ago, a large percentage of our lab computers stopped checking in with the JSS (they would perform login/logout hooks, but no checkin). After working with Nathan in Jamf, he quickly helped me figure out that if a computer updated SEP to 14.2.0 (we initially installed 14.0.1) it would then have Firewall functionality (https://support.symantec.com/en_US/article.TECH250508.html) and it would be turned on. As soon as I turned it off, the computers immediately were able to check in.
The issue now is finding out how to script turning off the firewall. I just started looking into this, but I figured I'd reach out in case anyone else ran into this same issue and had any experience disabling features in SEP. If nothing else, maybe someone else is experiencing this same issue and this might help them out.
Thanks!
Posted on 07-31-2018 06:38 AM
In case anyone else runs into this issue, I called Symantec and they said there wasn't any way to turn off Firewall in a script (which to me means there probably is but isn't something they'd recommend doing). They did say that if our Symantec clients were managed (they are, we have an SEPM server) that we could disable it using the following steps with SEP Manager:
I'm not sure whether our SEP Administrator followed those exact steps or did something different (I think they mentioned something about copying the policy or rule that was in place for Windows computers), but almost immediately after them making the change the affected computers started checking in again.