Symantec pcAnywhere 11.0                                  30-May-2003
For Windows 98/Me/NT/2000/XP
Copyright 2003 Symantec Corporation               All Rights Reserved

======================================================================

             Thank you for choosing Symantec pcAnywhere

If you experience problems or need help with using pcAnywhere,
consult the online Help or visit the Symantec Web site for
Knowledge Base articles, troubleshooting tips, and answers to 
frequently asked questions. 

The following online service and support options are available:

Internet:	HTTP://www.symantec.com
		(Online chat, technical support, downloads)
		
                ftp.symantec.com
                (Downloads only)

News server:	HTTP://service.symantec.com
                (Technical support, FAQs)

======================================================================

This document contains additions and changes to the printed manual. 
It also includes important upgrade, troubleshooting, and compatibility
information.

Please read this information before using pcAnywhere. Your version of
pcAnywhere might not include all of the features referenced in this 
document.

This document is organized into the following sections:
1. INSTALLATION
2. COMPATIBILITY
3. CORRECTIONS AND ADDITIONS
4. TECHNICAL NOTES

======================================================================
1. INSTALLATION
======================================================================

Administrator privileges are required to install pcAnywhere. During 
the installation process, you might be prompted to restart the 
computer for the settings to take effect. After restarting the 
computer, you must log on again using the same user credentials to 
ensure proper functionality.


Windows Me Installation Issues
======================================================================
In Windows Me, installing pcAnywhere into a directory with a long
path name might cause errors. To avoid errors, limit the 
installation path to 225 characters or less.

Installing Symantec pcAnywhere in Windows 98/Me requires a restart 
to complete the installation process. You will not be able to 
uninstall the product until you restart the computer.


International Installation Issues
======================================================================
On double-byte Windows XP operating systems, the IME is disabled during 
a Chat session or when the host user initiates a file transfer. Using 
the special Hankaku-Zenkaku and Katakana-Hiragana keys on the Japanese 
keyboard, the operator can switch from IME input to keyboard kana 
input. In kana input mode, each key on the keyboard types in 
Hiragana/Katakana, allowing for DBCS entry.


Symantec pcAnywhere File Locations
======================================================================
The pcAnywhere folder contains host files (.bhf), remote files
(.chf), caller files (.cif), log files, and other pcAnywhere 
configuration files.

The location of these files varies by operating system:

- Windows 9x/Me: 
   C:\WINDOWS\All Users\Application Data\Symantec\pcAnywhere

- Windows NT:
   C:\WINNT\Profiles\All Users\Application Data\Symantec\pcAnywhere

- Windows 2000:
   C:\Documents and Settings\All Users\Application Data\Symantec\
    pcAnywhere

- Windows XP:
   C:\Documents and Settings\All Users\Application Data\Symantec\
    pcAnywhere

If necessary, replace C with the drive in which the operating system 
is installed.


Host Administrator Installation Issues
======================================================================
The pcAnywhere Host Administrator tool is available as a custom setup 
option during the full product installation. If you want to use this 
tool, you should install it during the full product installation to 
ensure that all required components are installed.

If you install the pcAnywhere Host Administrator tool after you 
install pcAnywhere (which modifies the pcAnywhere installation), the 
Microsoft Management Console (MMC) is not included in the 
installation. The pcAnywhere Host Administrator tool requires MMC. You 
must manually install MMC if the computer does not already have MMC 
installed.


Advertised Installations
======================================================================
Advertised installations are not supported with this release of 
pcAnywhere.


Integrity Management
======================================================================
Securing installation packages using the Integrity Management" feature 
prevents unauthorized changes to the installed product. If pcAnywhere 
detects that a pcAnywhere executable, registry setting, or 
configuration file has changed in an installed, integrity-stamped 
package, pcAnywhere will not run. Users are restricted from changing 
pcAnywhere in any way, including installation of software upgrades 
via LiveUpdate.

When updates are needed, the current installation must be removed, 
and a new installation package must be created and installed.


Microsoft IntelliMirror Deployment
======================================================================
You must use the Published method to deploy an installation package 
via IntelliMirror. The Assignment method requires an installation 
advertisement, which is not supported in this release.


Web-based Deployment
======================================================================
When deploying a custom MSI over the Web to a Windows 9x computer, 
you must add the \Windows\System folder to the PATH environment variable 
on the Windows 9x target computer. 

You can use the Symantec Web-based Deployment Tool, which is located 
on the installation CD in the Tools\Web Deploy folder, to deploy 
custom installation packages over the Web. 


======================================================================
2. COMPATIBILITY
======================================================================

For enhanced security and performance and to reduce the size of the
installed footprint, pcAnywhere 11.0 is not backwards compatible
with pcAnywhere 5.0 for DOS or pcAnywhere 2.0 for Windows.

pcAnywhere 11.0 is compatible with versions 8.x, 9.x, and 10.x.

Host and remote objects created in pcAnywhere 11.0 can only
be used with pcAnywhere 10.0 and later.


Windows XP Compatibility Issues
======================================================================
Enabling the Windows XP Lock desktop items feature prevents
pcAnywhere from optimizing the host desktop or disabling the Windows 
Active Desktop feature.

pcAnywhere will not authenticate the default Windows XP administrator 
account using NT authentication. When setting up an NT caller in 
pcAnywhere using the NT User Manager feature, an Administrator 
account is listed. If you select this account, the host will not allow 
connections. If you need to set up an NT caller account with 
administrative rights on Windows XP, select another user that belongs 
to the administrator group or create a new account.

NT authentication does not support edited user names in Windows XP.
If you edit a user name in the Windows XP Control Panel, the 
original user name is listed under Name, and the changed name is 
listed under Full Name. Although Windows XP allows users to log on 
using either the original or changed name, pcAnywhere requires the 
original name when establishing a connection to another computer. 
This applies to pcAnywhere hosts using NT authentication on 
Windows XP.

The scroll bar will not appear on the Windows XP Welcome screen during
a pcAnywhere remote session if the option to optimize desktop
for remote control is enabled on the remote. If you maintain multiple
user accounts, you might not be able to view or select a user account
that is outside the display area. This optimize desktop option is 
enabled by default and is recommended for optimum performance.  

To disable the optimize desktop for remote control option:

1. On the remote computer, on the Edit menu, click Preferences.

2. On the Remote Operation tab, uncheck Optimize desktop for remote
   control.

3. Click OK.

The Windows XP taskbar might become minimized during a remote control
session. To restore the taskbar, resize it with the mouse. To avoid 
this issue, you can set the properties of the Windows XP taskbar to 
lock the taskbar.

Quick Deploy and Connect is not supported in Windows XP Home Edition 
due to limitations of the operating system.

Remote management does not support edited user names in Windows XP. 
You must log on using the original user name. For example, if an 
existing user name, XYZ, is changed to WXYZ, the  remote management 
logon will not accept the new name, WXYZ. Only the original name, 
XYZ, is accepted.

Blank passwords are not allowed when logging on to the host computer 
during a remote management session in Windows XP Home Edition.

The pcAnywhere Thin Host, which is deployed using Quick Deploy and 
connect, does not support Windows XP Fast User Switching. Using Fast 
User Switching while the thin host is running could result in the 
loss of video.


Windows 2000 Compatibility Issues
======================================================================
Because of operating system constraints, pcAnywhere does not 
automatically deactivate the Windows Active Desktop feature when you 
connect to a Windows 2000 host computer that has Active Desktop 
enabled. For improved performance, the host user should turn off 
Active Desktop before starting a session. 

If you connect to a host computer that has Active Desktop enabled, 
you turn it off after you connect if the host user has given you the 
appropriate access rights.

To deactivate Active Desktop:

1. Anywhere on the Windows desktop, right-click, then click Active 
   Desktop.

2. Uncheck Show Web Content.


Windows NT Compatibility Issues
======================================================================
For optimal performance in Windows NT, you should configure your
hosts to run as a service.

To improve performance in Windows NT 4.0:

1. On the Windows taskbar, click Start > Settings > Control Panel.

2. Double-click System.

3. On the Performance tab, move the slider all the way to 
   the left. 
   Foreground and background tasks are now equally responsive.

When using NT authentication, you must grant Log On Locally rights 
to the NT domain user account. If the NT domain user account does
not have this NT user right, users will not be able to log on to the
host. 

In NT 4.0, hosts that use the SPX protocol will remain in the list of  
available hosts after the host has been cancelled. To solve this 
problem, you must add the SAP agent to your host's network 
configuration.

To add the SAP agent:

1. On the NT host, on the Windows taskbar, click Start > Settings >
   Control Panel.

2. Double-click Network.

3. click Services.

4. Click Add.

5. Click SAP Agent.
 
Note: Service packs must be reinstalled after adding the SAP Agent.

On rare occasions, pcAnywhere hosts configured with the host setting 
Lock computer might experience a problem in which the user 
cannot type a user name or password on either the host or remote
computer. Press Ctrl+Alt to unlock the keyboard.


Remote Access Perimeter Scanner
======================================================================
The Remote Access Perimeter Scanner lets you scan your network and 
telephone numbers for the presence of pcAnywhere and other remote 
access products to identify potential security risks. The following 
are known compatibility issues.

VNC for UNIX
----------------------------------------------------------------------
The remote control product VNC for UNIX uses port numbers above 5900. 
To ensure proper scanning for this product, you should specify a port
number range between 5900 and 5910. Note that specifying a port range
increases the time required to complete the scan.

Carbon Copy
----------------------------------------------------------------------
Currently, the Remote Access Perimeter Scanner is unable to detect 
whether a logon is required for Carbon Copy.

pcAnywhere 2.0
----------------------------------------------------------------------
To detect pcAnywhere 2.0 using the Remote Access Perimeter Scanner, 
you must scan for hosts that are waiting on port 65301, not the 
default pcAnywhere port numbers 5631 and 5632.


Authentication
======================================================================
The following are known issues concerning the authentication types
supported in pcAnywhere.

Windows 9x/Me
----------------------------------------------------------------------
Windows caller authentication works on Windows 9x operating systems.
However, due to certain networking limitations on these systems, 
pcAnywhere hosts might experience a temporary loss of connectivity to 
networked resources. If problems persist, you should choose another  
authentication type such as HTTP or FTP authentication.

You can also try the following options:

- If mapped drives are set to reconnect upon logon, double-click 
  each drive to re-establish connectivity.

- In a Windows Explorer window, type the absolute path to the resource. 
  For example: \\<resource>.

- On the Windows taskbar, click Start > Run, then type the 
  absolute path to the resource. For example: \\<resource>.

UNIX
----------------------------------------------------------------------
pcAnywhere 10.0 or later hosts that use FTP, HTTP, or HTTPS 
authentication on a UNIX server can only be connected to by 
pcAnywhere 10.0 or later remotes.

Currently, a pcAnywhere host cannot use HTTP authentication where 
security is restricted in certain folders within the authentication 
server.

HTTP/HTTPS Authentication
----------------------------------------------------------------------
pcAnywhere hosts authenticating to an HTTP/HTTPS server that is 
running on Windows NT with Integrated Windows Security cannot be run 
as a service. Uncheck the host startup setting Run as a service when 
authenticating to this type of server. 

pcAnywhere hosts in Windows 9x/NT that are authenticating to an
HTTP/HTTPS server with Basic Authentication require Internet
Explorer 5.0 or later to authenticate properly.

Microsoft LDAP Authentication
----------------------------------------------------------------------
Because of the way the account is configured, pcAnywhere will not 
authenticate the default Administrator account with Microsoft LDAP 
authentication. Instead, create a new user with Administrator 
privileges.

Novell Directory Services (NDS) Authentication
----------------------------------------------------------------------
NDS group callers will not be authenticated on a pcAnywhere host 
unless the user and the group are in the same context. Users in the 
same group but within a different context cannot be used to log on to 
a pcAnywhere host.

If NDS or Novell Bindery are the only authentication types selected, 
the authenticating computer must have the Novell Client installed.

Novell LDAP
----------------------------------------------------------------------
To ensure proper functionality, Novell LDAP authentication requires 
the latest version of Novell Client.


Logging
======================================================================
The following are known issues related to logging.

Activity Log Processing
----------------------------------------------------------------------
pcAnywhere 10.0 and later does not support activity logs created by 
earlier versions of pcAnywhere.

When using Windows 9x and logging to a central server on a domain, 
the Windows 9x workstation must be logged on to the same domain as the 
server that receives the pcAnywhere logs. Also, to send pcAnywhere 
logs to a system that resides in a workgroup, the Windows 9x workstation 
must also reside in that workgroup. If the workstation is not part of 
the domain or workgroup, Windows will not authenticate properly, 
and pcAnywhere logs will not be generated.

If a host is running as a service when a system is logging across
domains to a central server, the same administrator user name and
password must exist on both systems, the one sending the logs and 
the one receiving the logs. If the same user name and password do not
exist on both systems, the logs will not be generated properly.

When a host is running as a service and pcAnywhere is logging across
domains, host events will not be sent to a central server.  Remote
and file transfer events are sent properly, but the host events will
not appear in the log. This problem only occurs with pcAnywhere 
logging.

NT Event Logging
----------------------------------------------------------------------
For NT Event logs to be formatted properly when sent to a central 
server, pcAnywhere or the Remote Access Perimeter Scanner must be 
installed on that server.

Sending pcAnywhere logs to a Windows 9x system with share-level 
access might cause unpredictable results. User-level access is 
recommended.


Keyboard Issues
======================================================================
If you encounter problems with your remote keyboard when connected to 
a pcAnywhere host in Windows NT, try pressing the Esc, Shift, Alt, 
or Ctrl keys individually.


Winmodem Issues
======================================================================
If you encounter problems with Winmodem drivers, contact 
the manufacturer of the modem to obtain the latest drivers.


Infrared Devices
======================================================================
Displaying the Microsoft Infrared icon on the Windows taskbar could
result in slow in-session video performance in Windows NT.

To avoid this problem:

1. On the Windows taskbar, click Start > Settings > Control Panel.

2. Double-click Infrared.

3. On the Monitor Preferences tab, uncheck Display the Infrared 
   Icon in Taskbar.


ISDN/CAPI Devices
======================================================================
Some CAPI devices do not handle communication errors properly. If 
you experience connection problems, try enabling pcAnywhere encoding. 
This enables error correction.

To enable pcAnywhere encoding:

1. Do one of the following:
   - To enable pcAnywhere encoding on a host, right-click a host 
     connection item, then click Properties.

   - To enable pcAnywhere encoding on a remote, right-click a remote
     connection item, then click Properties.

2. On the Security Options tab, in the Encryption Level list, click 
   pcAnywhere encoding.

If you plan use channel bonding when connecting to a host, ensure that 
the Attempt channel bonding option is enabled on the host.

To use the Callback feature over an ISDN connection that uses channel  
bonding, ensure that the channel bonding option is also enabled on the 
remote computer.


Windows NT Remote Access Service (RAS)
======================================================================
A remote node dialing into RAS does not have its computer name posted
for pcAnywhere to detect. To connect to a pcAnywhere host on the
remote node, specify the remote node's IP address.


TCP/IP Firewall Security
======================================================================
Administrators may configure their network security to allow 
TCP/IP connections over the Internet. By default, pcAnywhere uses two
ports, 5631 and 5632, which must be left open by the administrator 
to allow pcAnywhere connections through the firewall. 

If necessary, administrators can change the default port numbers in 
pcAnywhere Preferences. Use caution when changing port numbers. Some 
port numbers between 0 and 1024 are reserved for Web-based applications 
and services, such as FTP and the Internet. Choosing a reserved port 
number might interfere with these applications and possibly result in 
loss of service. The pcAnywhere port numbers are registered, and, in 
most cases, you do not need to change them.


Symantec Desktop Firewall Products
======================================================================
The Norton Firewall products come preconfigured to allow pcAnywhere
TCP/IP communication through the firewall. No additional
configuration is necessary unless the pcAnywhere default ports are 
altered. 

Norton Personal Firewall might generate firewall alerts if you use 
pcAnywhere Express. An active content component uses your Web browser 
to establish network connections to other pcAnywhere hosts. To enable 
pcAnywhere Express to properly connect to a host, configure Norton 
Personal Firewall to permit network communication with other computers. 
Firewall alerts will vary, depending on which Web browser you use.

For more information about how to handle these firewall alerts, see 
the following Knowledge Base document on the Symantec Web site:

http://service1.symantec.com/SUPPORT/nip.nsf/docid/2000120606411136


Microsoft QuikRes
======================================================================
Changing the pcAnywhere host desktop resolution or color depth 
using the freeware program QuikRes might cause the host to 
lose desktop optimization or end the connection.


Microsoft Visual C++
======================================================================
Disconnecting from a pcAnywhere host from a remote computer in which 
a compile is in progress might cause an error in the compiler. To avoid
this problem, before connecting, deactivate the Optimize host desktop 
option on the remote computer.


======================================================================
3. CORRECTIONS AND ADDITIONS
======================================================================
The following information is not covered in the printed or online user
documentation.


Caller Security Options
======================================================================
The Prompt to confirm connection security feature is not applicable 
for callers who have superuser rights. To use this feature,
you must set up a caller account that has individual caller rights
defined. 


Caller Authentication
======================================================================
To use Windows authentication on Windows 9x systems, you must create 
a hidden share on the Primary Domain Controller called pcanywhere$.

To authenticate to a Windows 9x pcAnywhere host, the host 
must be in a logged-off state or logged on as the user who is being 
authenticated to the domain.


Command Line
======================================================================
Using the /s command in conjunction with the /abort or the /message 
command will not work properly unless the /timer command is also used.

The /timer switch will not allow more than 99 seconds. Entering a
number higher than 99 could produce an error.


Encryption
======================================================================
Symantec pcAnywhere provides the following  unsupported tools to help 
you configure and manage your operating system's encryption 
configuration:

- MACHKEY.exe: Lets Windows NT/2000/xP hosts that run as a service 
  or Windows 9x hosts that launch with Windows use public-key 
  encryption. 

- CertCons.exe: creates a certificate store from a list of 
  certificates or existing certificate stores. 

- SetDefaultProvider.exe: Lets a user change the default Cryptographic 
  Service Provider for the local computer.

If you build a pcAnywhere package that contains a private-key 
container name on the same computer on which the private key was 
generated, the object's private-key container name is invalid on 
all other computers. This is the way in which private-key container 
names are generated. When an initial private key is installed, it 
generates a private-key container name in a format such as
XXX-YYYYY-ZZZ. When the public key is exported to another
computer, the private-key container name is changed to a format of
XXX-YYYYY-ZZZ-<computerspecific>. A possible work around
is to install the original key on one computer, and then 
export it to another computer, which would then perform the build 
including the private-key container name.

The pcAnywhere Encryption Wizard in pcAnywhere does not automatically 
provide a private-key container keyset after you select the digital 
certificate information to authenticate the local computer. You must 
manually select the correct keyset from the Private key container list. 
The keyset is listed only if the option to Run as a service is selected. 

To set up public-key encryption in an installed pcAnywhere package:

1. Export a digital certificate from a local computer. The exported 
   file requires a .pfx extension to import a private/public
   key pair to another computer.

2. Install the built pcAnywhere package on another computer.

3. Import the exported digital certificate (.pfx file) to the computer
   on which the package is installed.

4. Export the public key (.p7b file) of the computer on which the 
   package is installed to the computer to which it will connect. 
   pcAnywhere requires the certificate information about the
   computer to which the local computer is connecting to support 
   public-key encryption. 
   

pcAnywhere DynIP Installation
======================================================================
Symantec pcAnywhere provides a six-month trial version of DynIP Client 
for Windows, which lets you register a personalized Internet name for 
your host computer that can be used by others to connect to it. 

For more information, see the DynIP online help or visit the 
Knowledge Base on the Symantec web site.


Host Conferencing
======================================================================
When hosting a conference in Windows XP, the host computer should be
running in session 0. In Windows XP, session 0 is typically set when 
the first user logs on to the computer. Video distortions
might occur on the remote computers that are connected to the host 
conference computer if the host computer is running in a session 
higher than zero, for example, the host user does a fast user 
switch and then logs off during the connection.


Host Administrator
======================================================================

To manage host services on other NT computers outside of an NT domain,
the computer that is running the Host Administrator Tool and any 
NT computer that you want to manage must have the same NT account 
name, password, and administrator rights. When managing host services 
on NT computers within a domain, only one account requires 
administrator rights. 

Host objects that authenticate using a local NT account will not work 
if distributed via the Host Administrator. The Host Administrator 
should not be used to create and distribute hosts that authenticate 
using local NT accounts.
 
When requesting the status of a host, the pcAnywhere Host 
Administrator will pause until the process is complete.
 
If the client is configured to save the pcAnywhere log file to a 
location other than the \data directory, the Host Administrator will 
not be able to locate the activity log.


Lock Mouse and Keyboard Options
======================================================================
To use the Lock keyboard and mouse options, you must restart the 
computer after installing pcAnywhere. 


Multi-Processor Systems
======================================================================
If you experience problems with video painting or display speed 
during a pcAnywhere session on a multi-processor system, try 
the following registry key called ProcessorMask.

To add or modify the ProcessorMask registry entries:

1. Run the Registry Editor (REGEDIT.EXE or REGEDT32.EXE)

2. Locate the following key:
   HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\pcAnywhere\CurrentVersion\Host

3. Create or edit the DWORD value with the ProcessorMask name.

4. Set one of the following values to the entry:

   - 0: Forces pcAnywhere to use all processors in the 
        system. (The is the default value.)

   - 1: Forces pcAnywhere to use only the first processor
        in the system. Use this to solve the video and speed issues.


pcAnywhere Express
======================================================================
A Parameter is not correct error message might appear when installing 
pcAnywhere Express from a deep directory structure. If this error 
appears, copy the installation files to the local computer, then run 
the installation program locally. pcAnywhere Express is located in 
the Unsupported folder.


Policy Editor
======================================================================
Programs created with the OLE Automation Server can manipulate 
policy settings that were configured using policy management. To 
ensure policies are enforced, create a custom installation package 
and unselect the OLE automation feature.


Remote Management - Edit System Files
======================================================================
The following are known issues concerning Remote Management.

Edit System Files
----------------------------------------------------------------------
.INI files larger than 500KB might not display properly on a 
Windows 98/Me computer.

Logoff Options
-----------------------------------------------------------------------
You should select the Close all open programs option when attempting
to shut down, restart, log off, or lock the host computer if the host
computer has been locked or is waiting outside of the Windows logon.

The Lock computer option will not work properly on a Windows NT 4.0 
computer if the computer has not been restarted since pcAnywhere was 
installed. 

Edit Registry
-----------------------------------------------------------------------
Resizing or moving the pcAnywhere Session Manager window when using 
the Edit Registry feature could cause video display issues on the 
remote computer.


Session Recording and Playback
======================================================================
A recorded session should be played back using the same or higher 
resolution settings in which it was recorded. 


Symantec Packager
======================================================================
Errors might be encountered if the "Operating system files" option is 
not selected when configuring products. This option only needs to be 
selected the first time a package is installed. All subsequent package 
installations should not require this option.


======================================================================
4. TECHNICAL NOTES
======================================================================
pcAnywhere contains encryption software derived from the RSA Data 
Security, Inc., MD5 Message-Digest Algorithm. Copyright (c) 1991-92 
RSA Data Security, Inc. All Rights Reserved.

As a deterrent to unauthorized users, the Remote Access Perimeter 
Scanner sends a clear-text message to each machine that it scans.
This message includes the IP address, user name, and computer name of 
the originator of the scan.

                          < END OF FILE >
