I suspect that SEP runs as a 64-bit app on 64-bit windows, and so writes to HKLM\Software\Symantec. However, the TEM client runs as a 32-bit app, so by default when it looks at HKLM\Software\Symantec, it will instead be redirected by windows to HKLM\Software\Wow6432Node\Symantec.
I have recently had my laptop upgraded from a Windows machine to a MacBook Pro 13 running MacOS Mojave. I used to connect to the VPN of a client using Cisco AnyConnect Mobility Client, but changing my machine, it refuses to connect. At first, I was presented with an error message saying that no antivirus program was installed on my machine, so I installed Symantec Endpoint Protection (SEP) -the same antivirus that was installed on my windows machine. Since then, no matter what I do, when I try to connect, I'm presented with an error message saying "Dear *client's name* Vendor session is terminated because your Antivirus service is disabled" even though it's working just fine. I tried updating the antivirus definition, and uninstalling then reinstalling both AnyConnect and SEP, but nothing changed. I also tried connecting from a colleague's Mac (running MacOS High Sierra if that's relevant) and the connection was successful. I'm not sure if it's an OS thing or what.
It could also be the headend has an older version of hostscan (the bit that checks for your endpoint AV - related to but separate from the AnyConnect version). Support for macOS with Symantec Endpoint Protection was only added in hostscan 4.3.05033
@Marvin Rhoads Thanks for your reply. I'm not sure I understand your second point, but I have AnyConnect version 4.6-something so, newer than the version you were talking about. Do you mean that client I'm working with could have an older version?
My organisation has Windows Server 2016 OS and uses Symantec Endpoint Protection as the AV. Microsoft Learn recommend disabling Windows Defender if a third-party AV is being used.
Sources also indicate that Windows Defender Firewall component remains enabled despite Windows Defender being disabled.
Although Windows firewall in windows 10 is now called the Windows Defender firewall. However, it's not actually an integral part of the Windows Defender. The Windows firewall existed long before Windows defender.
"Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?
Vulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state."
If third-party AV features its own firewall, generally, it will automatically disable the Windows built-in firewall. If windows firewall was not disabled and you want to use third-party firewall, then just turn windows Firewall off.
I am using SEPM version 11.0.6 and I have like 40 managed computers from Windows XP to Windows 7. I would like to create a separate group where If users try to plug in their USB storage devices like Memory Sticks,BB phones,Ipods etc into their systems they cannot access them or see them. I only want these devices blocked. They can use their USB mouse,keyboard and printers. How can I do this in SEPM? Any help would be appreciated.
just as an addition to the previous posts: In SEP 11, Application and Device control, which is responsible for blocking USB devices, only runs on computers with 32-bit OS. E.g., if your Windows 7 computers are 64-bit, it won't work. In this case you have to update to SEP 12.1 (this is a good idea anyway).
Seems as though the blocking of the USB pen drives and BB phones is working perfect for the Windows 7 32 bit computers. However it is not working for windows XP 32 bit and windows 7 64 bit computers. Any ideas would be appreciated.
c80f0f1006