Symantec Scan Engine 5.2 continuously disconnects from the NetApp Filer when installed on Windows 2008

Article:TECH143591  |  Created: 2010-11-05  |  Updated: 2012-10-18  |  Article URL http://www.symantec.com/docs/TECH143591
Article Type
Technical Solution


Problem



When Symantec Scan Engine 5.2.x is installed on Windows 2008, the NetApp Filer continuously reports that Scan Engine has disconnected from the filer.  Typically this warning/error is logged once every 6 minutes in the Filer's syslog, or anything the Filer attempts to scan a file.  Soon after the disconnect warning, the Filer will log that Scan Engine has successfully registered with the Filer again.


Error



Wed Oct 27 15:31:54 CDT [XXXXX: vscan.dropped.connection:warning]: CIFS: Virus scan server \\NTAPPXXXXX (xx.xx.xx.xx) has disconnected from the filer.

Wed Oct 27 15:37:25 CDT [XXXXXX: cifs.server.errorMsg:error]: CIFS: Error for server \\NTAPPXXXXX: SMB2 Session Setup Error No Trusted Logon Servers Available - STATUS_NO_LOGON_SERVERS.


Cause



Changes in security settings from Windows 2003 to Windows 2008.


Solution



When Symantec Scan Engine 5.2.x is installed on Windows 2008 this issue is typically caused by the Scan Engine Server using SMB 2.0, or the SSE Server not allowing anonymous access for Named Pipes.

To allow anonymous access for Named Pipes on the Scan Engine Server,
1. Go to Local Security Policy > Local Policies > Security Options.
2. Under Policy, look for “Network access: Named Pipes that can be accessed anonymously”.
3. Under the Security Setting for this Policy make sure NTAPVSRQ is there, if not go ahead and add it.
4. Under the same policy list, look for “Network access: Let Everyone permissions apply to anonymous users”.
5. Change this policy from disabled to enabled.
6. Restart the Server.

Note, this is needed because the NetApp Filer uses the "anonymous" user through the NTAPVSRQ pipe.

To disable SMB 2.0 on the Scan Engine Server,
1. Open command prompt on Windows Server
2. Type the following commands and hit enter after each:

 

sc config lanmanworkstation depend= bowser/mrxsmb10/nsi
sc config mrxsmb20 start= disabled

 

Note, this is needed because the NetApp Filer does not work with SMB 2.0, at least not at the creation of this KB.  If this is the specific issue you are running into you should see error in the NetApp Log file,

Wed Oct 27 15:37:25 CDT [XXXXXX: cifs.server.errorMsg:error]: CIFS: Error for server \\NTAPPXXXXX: SMB2 Session Setup Error No Trusted Logon Servers Available - STATUS_NO_LOGON_SERVERS.

 

 

Please contact Support for more information.  Also, please see KB 156942 www.symantec.com/business/support/index




Article URL http://www.symantec.com/docs/TECH143591


Terms of use for this information are found in Legal Notices