Quantcast
Channel: Symantec Connect - Products - Discussions
Viewing all articles
Browse latest Browse all 21603

Cannot apply policy when Prevention is enabled

$
0
0
I need a solution

Hello,

I am running SDCSS 6.0.  I have created a hardened policy for an XP machine with Prevention disabled.  After watching events for a couple of weeks, I used the wizard to make the necessary changes.  Now I am trying to change the policy so that Prevention is enabled.  However, whenever I apply a Prevention policy to this one machine, I get the following error:

Policy Translation Failed: Failed to set Driver Configuration Registry Value Filter File:\??\C:\Program Files\Symantec\Data Center Security Server\Agent\IPS\driver\policy5716102.conf

The error appears on the client and in the management console.  As a result of the error, the new policy will not get applied to the client.  If I disable Prevention and reapply the policy, the client is fine again.  I also notice a particular prevention event when prevention is disabled and I am not sure if it is related:  

Description                     Process Modification Allowed for (CCMEXEC.EXE) on (C:\Program Files\Symantec\Data Center Security Server\Agent\IPS\bin\translate.exe).
Policy Name                     Hollister - Logging - Hardened - XP - India
Internal Rule                   .DN
Process                         C:\WINDOWS\SYSTEM32\CCM\CCMEXEC.EXE
Module Path                     \WINDOWS\SYSTEM32\CCM\MTRMGR.DLL
Target Process - Sandox         hardened_ps
Target Process Name             C:\Program Files\Symantec\Data Center Security Server\Agent\IPS\bin\translate.exe
Agent State                     Prevention Globally Disabled
Disposition                     Allow
Sandbox                         def_winsvcs_ps
Operation                       OpenProcess
OS Result                       00000000 (SUCCESS)
SDCSS Result                    00000000 (SUCCESS)
Process ID                      2692
Target Process ID               3488
Actual Permissions              00100411 (synch, terminate, vm_read, query_information)
Caller Thread ID                3416
Permissions Requested           00100411 (synch, terminate, vm_read, query_information)
Process Signature               Unsigned (00000000)
Module Signature                Unsigned (00000000)

I found this interesting because the target process is "translate.exe." The first error I provided above says Policy Translation Failed, so I wonder if translate.exe must run to be able to do the policy translation.  

I have tried changing the policy so that all sandboxes are turned off with Prevention enabled.  I still get the Policy Translation Failed error.  

I have not run into this on my other hosts so far.

Thanks in advance for your assistance,

Bob


Viewing all articles
Browse latest Browse all 21603

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>