Login to participate
Security ArticlesRSS

Hardware change causes a RE-REGISTRATION which generates MULTIPLE entries for SEP clients in the SEPM Database

Kedar Mohile's picture

Hardware change causes a RE-REGISTRATION which generates MULTIPLE entries for SEP clients in the SEPM Database

It found after groups synchronized with Active Directory, that multiple entries are found in the clients tab for added OUs.

This causes:

Communication Issues:  SEP client will show the green dot for a few seconds and then it disappears. IIS shows 200's and sylink/secars logs show error 500 with an invalid group id.
 
Reporting Issues: Security Status Details on the Home page showing Attention Needed OR Duplicate clients appear in the Symantec Endpoint Protection Manager.
 
This issue is found both in deployments with:
 
1.      USER MODE
2.      COMPUTER MODE
 
This issue is resolved with SEP 11 RU5. However, incase if you are still working on MR4 or any version below the samethe following URL mentioned in the “Symantec Endpoint Protection README.TXT Date: August 2009 “ should help
 
 
 To fix the issue, enter the following URL in a browser on the computer running Symantec Endpoint Protection Manager:
 
 
Entering the URL runs a program that deletes all duplicate clients from the Default group and sets the hardware keys of the clients in the OU group to NULL so they automatically re-register to their former Active Directory groups.
 
 
 
Hardware change causes a “RE-REGISTRATION” which is the root cause of this issue to occur.

Lets look at WHAT IS A HARDWARE CHANGE ?

Change or addition of Hardwarwe like RAM, HDD, NIC,  etc., Change in Enabled NIC’s MAC-addresses OR any related configuration, switching between wireless/wired connection on the system, connection mode changed to VPN,  docking/undocking of the System
   
All the above mentioned Hardware change triggers a “RE-REGISTRATION” of clients in SEPM. This is commonly seen where laptop client computers are in groups synchronized with Active Directory
 
Reference:
Symantec Endpoint Protection README.TXT Date: August 2009

Thanks :-)

 
Vikram Kumar-SAV to SEP's picture

 Good to know..

 Good to know..

Celebrating 2 years as a community member....

chenh's picture

Is this issue going to impact

Is this issue going to impact any clients that do not sync with AD?

shp's picture

Good one....... I have one

Good one.......

I have one question.. Is it possible to get duplicate client logs....

Regards,
Srinivas H.P.
HCL Infosystems Ltd

Kedar Mohile's picture

Is this issue going to impact any clients that do not sync with

Just checked these question as was on leave and away...

Is this issue going to impact any clients that do not sync with AD?

Yes this issue migh occur with clients that do not sync with AD

Is it possible to get duplicate client logs....

Yes this does affect client logs and reporting

Thanks :-)

d-doug's picture

Awesome.  We could have used

Awesome.  We could have used this a few months ago.

Is there somewhere that lists what servlets are available to us and what they do?

JustinAndersen's picture

update available?

Has there been any progress made on this issue with clients that do not sync with Active Directory? 

I've had this issue occur with MR4 and RU5.