Transcription of Symantec Endpoint Protection 14.3 RU4 Release Notes
1 Symantec Endpoint Protection RU4 Release Notes Symantec Endpoint Protection RU4 Release NotesTable of ContentsDocumentation Legal 's new for Symantec Endpoint Protection RU4?..4 Known issues and workarounds for Symantec Endpoint Protection (SEP)..8 System requirements for Symantec Endpoint Protection (SEP) and unsupported upgrade paths to the latest version of SymantecEndpoint Protection ..27 Where to get more 2 Symantec Endpoint Protection RU4 Release NotesDocumentation Legal NoticeThis Documentation, which includes embedded help systems and electronically distributed materials, (hereinafter referredto as the Documentation ) is for your informational purposes only and is subject to change or withdrawal by Broadcomat any time. This Documentation is proprietary information of Broadcom and may not be copied, transferred, reproduced,disclosed, modified or duplicated, in whole or in part, without the prior written consent of you are a licensed user of the software product(s) addressed in the Documentation, you may print or otherwise makeavailable a reasonable number of copies of the Documentation for internal use by you and your employees in connectionwith that software, provided that all Broadcom copyright notices and legends are affixed to each reproduced right to print or otherwise make available copies of the Documentation is limited to the period during which theapplicable license for such software remains in full force and effect.
2 Should the license terminate for any reason, it is yourresponsibility to certify in writing to Broadcom that all copies and partial copies of the Documentation have been returnedto Broadcom or THE EXTENT PERMITTED BY APPLICABLE LAW, BROADCOM PROVIDES THIS DOCUMENTATION ASIS WITHOUT WARRANTY OF ANY KIND, INCLUDING WITHOUT LIMITATION, ANY IMPLIED WARRANTIES OFMERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NONINFRINGEMENT. IN NO EVENT WILLBROADCOM BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY LOSS OR DAMAGE, DIRECT OR INDIRECT,FROM THE USE OF THIS DOCUMENTATION, INCLUDING WITHOUT LIMITATION, LOST PROFITS, LOSTINVESTMENT, BUSINESS INTERRUPTION, GOODWILL, OR LOST DATA, EVEN IF BROADCOM IS EXPRESSLYADVISED IN ADVANCE OF THE POSSIBILITY OF SUCH LOSS OR use of any software product referenced in the Documentation is governed by the applicable license agreement andsuch license agreement is not modified in any way by the terms of this manufacturer of this Documentation is Broadcom with Restricted Rights.
3 Use, duplication or disclosure by the United States Government is subject to therestrictions set forth in FAR Sections , , and (c)(1) - (2) and DFARS Section (b)(3), as applicable, or their 2005-2022 Broadcom. All Rights Reserved. The term Broadcom refers to Broadcom Inc. and/or itssubsidiaries. All trademarks, trade names, service marks, and logos referenced herein belong to their respectivecompanies. 3 Symantec Endpoint Protection RU4 Release NotesWhat's new for Symantec Endpoint Protection RU4?This topic describes the new features in this Symantec Endpoint Protection (SEP) Features Improved Protection that uses behavioral rules to prevent damage to certain file types such as Microsoft Wordand .jpg, and large volume Protection that SEP uses against living-off-the land techniques The Web and Cloud Access Protection policy now uses the latest version of the Symantec Web Security Service(WSS) agent , version The versions provide many - Recent Features You can use SymDiag to gather debugging and troubleshooting information for the SEP client with integrated WSScomponent.
4 SymDiag gathers packet capture (PCAP) files, which Symantec Technical Support uses to help youanalyze and fix connection and checking the health of the SEP client The recent surge of targeted ransomware attacks increasingly use Living Off the Land (LOTL) techniques that leveragetrusted applications and tools to execute various phases of the attack chain. Symantec introduced a breakthroughendpoint technology, Adaptive Protection . Adaptive Protection helps enterprises to prevent attackers from using trustedapplications and tools in malicious ways without impacting end users and business Endpoint Protection uses a streamlined workflow that makes SEP enrollment into the cloud consolefast and easy. This workflow provides you friction-free access to the full benefits of the ICDm cloud consolein Symantec Endpoint Security Complete. To learn more about this solution and how to implement it in yourenvironment, see:Enabling Adaptive Protection in Symantec Endpoint Protection .
5 You can write and use custom queries to search for malware on client computers using YARA rules (PoC Release )Scanning the SEP client computer using custom YARA rules Block unfiltered traffic that is accessed through Bluetooth devices by selecting a network adapter in a firewall rule. In the SEPM Firewall policy, configure a firewall rule that specifies either All Adapters or Ethernet. On the Policiespage > Policy Components tab, you can add the specific Bluetooth device name. On the SEP client, configure a firewall rule by selecting the General tab > Bluetooth Device (Personal AreaNetwork) network adapter. 4 Symantec Endpoint Protection RU4 Release Notes To protect the SEP client from ransomware attacks, SEPM reminds you to set a password that requires the clientuser to use a password before performing several tasks. These tasks include opening or uninstalling the client,stopping the client service, importing or exporting a policy, or importing the client communication settings.
6 Requiring apassword protects clients against ransomware attacks that could stop the SEP service before the attack runs. To setthe password, on the Clients page > Policies tab, click receive the following notification once every six months to remind you to enable at least one of the passwordoptions: Some Symantec Endpoint Protection groups have not been assigned a password. Ifyou set the password for all groups, the notification does not appear. These notifications appear on the Monitors >Notifications the Symantec Endpoint Protection clientSymantec Endpoint Protection Manager (SEPM) Language support for Simplified and Traditional Chinese has been added back for the Symantec Endpoint ProtectionManager, the Windows, Mac, and Linux clients. The following third-party components were upgraded: Apache Commons Compress, Apache Server, log4j, SpringFramework, Spring Security, Spring Boot, and OpenJDK. The option labels to specify which email protocol that the email server connects to have changed.
7 Use STARTTLSand Use SMTPS replaced Use TLS and Use SSL. These options are on the Admin > Servers > Edit the serverproperties > Email Server tab. RU4 is the last version of SEPM that installs or upgrades on Windows Server 2008 R2. Symantec recommendsthat you upgrade to a later version of Windows with TLS support for more secure and platform updatesWindows client If you are installing the Symantec Endpoint Protection client version RU3 or later on Windows, Mac, or Linuxcomputers, you do not need to restart the client. If you are upgrading the Symantec Endpoint Protection client RU3 or later on Windows, Mac, or Linux computers, you do not need to restart the client in most cases. Restarting the client computers from Symantec Endpoint Protection Manager If you enroll the SEPM in the cloud to manage policies from the Symantec Integrated Cyber Defense Manager (ICDm),the System policy appears in the Troubleshooting > Hybrid Management panel.
8 You can add the System policy fromthe cloud console only, and not SEPM. The Windows client introduces a new log, the Attack Surface Reduction log. This log replaces the Hardening EventViewer that appears when Data Center Security (DCS) is installed on the SEP client. The Attack Surface Reduction log 5 Symantec Endpoint Protection RU4 Release Notesdoes not include the Overrides and Exception Requests option or the Symantec trusted option. To access the logon the client, click View Logs > Application Hardening. You can only see the log if you manage the client from theICDm cloud console. The Windows client now correctly switches to a location that uses the OR relationship with the DNS Lookup, DNSS uffix, NIC Description, User, and Wireless SSID criteria. Download Insight allows the client user 3 minutes to allow a suspicious file before it removes the file by default. In , the Remove the file from my computer message is followed by the amount of time the client user has to makea decision.
9 You can no longer re-install RU4 does not have a Mac client client: Notes ymantec Endpoint Protection Manager RU4 ships with the RU3 Release ofthe Symantec Endpoint Protection client for Linux. When the Linux client RU4 is available in February2022, LiveUpdate downloads the Linux client installation package to the Symantec Endpoint ProtectionManager. Symantec agent for Linux RU4 and Symantec Data Center Security Linux agent can co-exist on a singleworkstation or server. You can manage both the Symantec agent for Linux RU4 and Symantec Data CenterSecurity Linux agent from either management Removed Removed the Display antivirus alerts within Windows Security Center option from the Virus and SpywareProtection policy > Miscellaneous page. The client no longer supports this settings Removed the warning for the Use Symantec servers when private servers are not available option in Clients page> Clients tab > External Communications.
10 Clients are no longer supported. 6 Symantec Endpoint Protection RU4 Release NotesDocumentation The Symantec Endpoint Protection for Mac Client Guide and the Symantec Endpoint Protection for Linux AgentGuide PDF files are translated into French, Japanese, Portuguese, Spanish, Simplified Chinese, and TraditionalChinese. To find the current and previous Symantec Endpoint Protection Manager database schemas, contact 's new in all releases of Symantec Endpoint Protection 7 Symantec Endpoint Protection RU4 Release NotesKnown issues and workarounds for Symantec EndpointProtection (SEP)The items in this section apply to this Release of Symantec Endpoint Issue column displays the version number when the issue appears. For example, [ RU1] means thatthe issue applies to version RU1 and later. When these issues are fixed, they appear in the fix-it :Versions, system requirements, Release dates, Notes , and fixes for Symantec Endpoint Protection and EndpointSecurityUpgrade issuesTable 1: Known upgrade issuesIssueDescription and solutionThe following error message appears:" Symantec Endpoint Protection RU2 for Win64bit is the latestpackage.