Hello,
I am running SDCSS 6.0. I have created a hardened policy for an XP machine with Prevention disabled. After watching events for a couple of weeks, I used the wizard to make the necessary changes. Now I am trying to change the policy so that Prevention is enabled. However, whenever I apply a Prevention policy to this one machine, I get the following error:
Policy Translation Failed: Failed to set Driver Configuration Registry Value Filter File:\??\C:\Program Files\Symantec\Data Center Security Server\Agent\IPS\driver\policy5716102.conf
The error appears on the client and in the management console. As a result of the error, the new policy will not get applied to the client. If I disable Prevention and reapply the policy, the client is fine again. I also notice a particular prevention event when prevention is disabled and I am not sure if it is related:
Description Process Modification Allowed for (CCMEXEC.EXE) on (C:\Program Files\Symantec\Data Center Security Server\Agent\IPS\bin\translate.exe).
Policy Name Hollister - Logging - Hardened - XP - India
Internal Rule .DN
Process C:\WINDOWS\SYSTEM32\CCM\CCMEXEC.EXE
Module Path \WINDOWS\SYSTEM32\CCM\MTRMGR.DLL
Target Process - Sandox hardened_ps
Target Process Name C:\Program Files\Symantec\Data Center Security Server\Agent\IPS\bin\translate.exe
Agent State Prevention Globally Disabled
Disposition Allow
Sandbox def_winsvcs_ps
Operation OpenProcess
OS Result 00000000 (SUCCESS)
SDCSS Result 00000000 (SUCCESS)
Process ID 2692
Target Process ID 3488
Actual Permissions 00100411 (synch, terminate, vm_read, query_information)
Caller Thread ID 3416
Permissions Requested 00100411 (synch, terminate, vm_read, query_information)
Process Signature Unsigned (00000000)
Module Signature Unsigned (00000000)
I found this interesting because the target process is "translate.exe." The first error I provided above says Policy Translation Failed, so I wonder if translate.exe must run to be able to do the policy translation.
I have tried changing the policy so that all sandboxes are turned off with Prevention enabled. I still get the Policy Translation Failed error.
I have not run into this on my other hosts so far.
Thanks in advance for your assistance,
Bob