WelcomeProducts & ServicesSecurity ResponseSupportSolutions & IndustriesLicensingTrainingStore
Enterprise
Symantec.com > Enterprise > Support > Knowledge Base


Security Content for Symantec Endpoint Protection clients and Symantec Endpoint Protection Managers are dated Dec 31 2009 even when using the latest definitions

Question/Issue:
Why are the Security Content dates for Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Manager (SEPM) not progressing beyond 12/31/09?

Symptoms:
Security Content dates on the following Symantec products are dated 12/31/09 rev xxx despite being the latest available through LiveUpdate:


Note: This includes all Security Content updates - including Antivirus definitions, Proactive Threat Protection (PTS) Truscan definitions, and Intrusion Prevention System (IPS) definitions.


The following is a list of the expected behaviors of affected Symantec software with default configurations. If the settings for functionality such as alerts or notifications have been altered from the default values, it is possible that your experiences may vary from those below.

Cause:
An issue was identified in the Symantec Endpoint Protection Manager (SEPM)/Symantec Protection Center (SPC) which causes Security Content newer than 12/31/2009 11:59 PM to be considered older than content previous to that date/time. Any content with a date of 1/1/10 12:00 AM or newer would be purged from the SEPM if the maximum number of definitions revisions had been reached. Since 12/31/09 rev xxx is considered the latest content available to an unpatched SEPM/SPC, a client would not update to a content revision later than the highest numbered revision available on 12/31/2009. To mitigate this issue, Security Response stopped incrementing the date on SEP Security Content downloaded by SEPM/SPC Servers and instead only incremented the revision number of the content. Symantec released a patch to resolve this issue for SEPM/SPC, but Security Response will continue to provide both a 12/31/2009 rev xxx and 2010 content streams for SEPM/SPC for the time being.


Solution:
Symantec released a patch that will resolve this issue for Symantec Endpoint Protection 11 and Symantec Endpoint Protection Small Business Edition 12 users. This patch is available via Public LiveUpdate, LiveUpdate, Administrator and LiveUpdate Administration Utility. It can also be downloaded directly from the Symantec FTP server. The vast majority of SEPM/SPC users will already be patched due to automatic LiveUpdates.

Note: If you do not wish to have your SEPM/SPC updated automatically, please see the section below titled: “Preventing LiveUpdate from updating SEPM/SPC” under the SEPM and SPC Workarounds and Information section.


Manual Patch Installation Instructions:




For un-patched SEPMs:

Hide details for SEP Client Workarounds and Information:SEP Client Workarounds and Information:
This section covers information for the Symantec Endpoint Protection Client product.

Hide details for SNAC Workarounds and Information:SNAC Workarounds and Information:
This section covers information for the Symantec Network Access Control product.

Hide details for SEPM and SPC Workarounds and Information:SEPM and SPC Workarounds and Information:
This section covers information for the Symantec Endpoint Protection Manager and Symantec Protection Center.

Hide details for Addendum for Rapid Release Users:Addendum for Rapid Release Users:
This section covers information on using Rapid Release definitions.

In certain situations, Symantec Support will recommend the use of Rapid Release (RR) virus definitions during an active infection. As the RR Intelligent Updater (IU) definitions are dated normally, they will be removed immediately on a SEPM that has reached its threshold for definition revisions. There are two work-arounds that will allow the use of Rapid Release definitions:

Hide details for Addendum for LiveUpdate Administrator Users:Addendum for LiveUpdate Administrator Users:
This section covers information on configuring LiveUpdate Administrator to update SEPM with the 2010 definition issue patch.




Document ID: 2010010308571348
Last Modified: 03/15/2010
Date Created: 01/03/2010
Operating System(s): Windows 2000 Professional, Windows 2000 Server/Advanced Server, Windows XP Home Edition, Windows XP Professional Edition, Windows XP Tablet PC Edition, Windows Server 2003 Web/Standard/Enterprise/Datacenter Edition, Windows Vista, Windows XP Professional x64 Edition, Windows Server 2003 x64 Edition, Windows Vista x64 Edition, Windows Server 2008 DataCenter 64-bit, Windows Server 2008 DataCenter 32-bit, Windows Server 2008 Enterprise 64-bit, Windows Server 2008 Enterprise 32-bit, Windows Server 2008 Standard 64-bit, Windows Server 2008 Standard 32-bit, Windows Server 2008 Web Server 64-bit, Windows Server 2008 Web Server 32-bit, Windows Server 2008 Small Business Edition, Windows Server 2008 R2, Windows 7, OS X 10.3.x, OS X 10.4.x, OS X 10.5.x, OS X 10.6.x
Product(s): Endpoint Protection 11, Endpoint Protection Small Business Edition 12, Network Access Control 11, Symantec AntiVirus for Macintosh 10.0
Release(s): Endpoint Protection 11 [All Releases], Endpoint Protection Small Business Edition 12 [All Releases], Endpoint Protection Small Business Edition 12.0, Network Access Control 11 [All Releases], Symantec AntiVirus for Macintosh 10.0, Symantec AntiVirus for Macintosh 10.1, Symantec AntiVirus for Macintosh 10.2, Symantec AntiVirus for Macintosh 10.x [All releases]


Site Index · Legal Notices · Privacy Policy · · Contact Us · Global Sites · License Agreements
©1995 - 2010 Symantec Corporation