we started having lot of mapped drives disconnecting from users after we
updated Symantec Endpoint Protection to version 12.
Eventually we noticed that SEP12 firewall was blocking NCP/524 in some

SEP12 default rules had changed from SEP11, now it allows traffic from
applications xx and blocks other traffic. When looking at log files,
sometimes the NCP/524 traffic comes from nwtray or System Network
service - BUT sometimes it didn't show any application/service name at
all - and in that case SEP12 blocked the traffic!

This can be fixed by adding separate rule to SEP12 firewall and allow
NCP/524 trafic in all cases.

what a hassle,