Client cannot update policy from the Server
Updated: 09 Oct 2010 | 25 comments
This issue has been solved. See solution.
Dear ALL,
I'm using SEP Manager 11.0.5. My problem is SEP client cannot update from the server (policy, definitions).
I've checked Communication between Server and client, it seems OK.
On SEP Manager, some clients display computer icon with green dot, others are not. But from the client (which display computer icon with green dot), SEP icon dont have green dot.
When I go to Troubleshooting..., the server status is Offline, and it belongs to wrong group (even i already update Sylink.xml with SylinkDrop tool).
I dont know what happened.
Thanks
Discussion Filed Under:
Comments
1.Is the windows firewall on,
1.Is the windows firewall on, on clients and on servers?
2. Is the issue with ALL clients?
3. Was the sepm server uninstalled, and then re-installed?
4. Post the sylink.log file from one of the clients
-VKalani
Are you facing problem in all
Are you facing problem in all clients or in some?
What is the OS of server and clients?
"it belongs to wrong group"--Whether the client is present in this group in SEPM?If yes you can move to correct group...
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Thanks for super fast
Is this what you want?
1 8/27/2010 3:35:21 AM Information 12070201
Windows Version info:
Operating System: Windows XP Professional x64 (5.2.3790 Service Pack 2)
Network info:
No.0 "Local Area Connection 2" 00-15-17-72-09-a1 "Intel(R) PRO/1000 PT Quad Port LP Server Adapter" 172.25.5.1
2 8/27/2010 3:35:21 AM Information 12070202 Symantec Management Client has been started.
3 8/27/2010 4:13:29 AM Error 120B0001 Failed to contact server for more than 10 times.
4 9/8/2010 9:20:01 AM Information 1207021A User is attempting to terminate Symantec Management Client....
5 9/8/2010 9:20:01 AM Information 1207021A Stopping Symantec Management Client....
6 9/8/2010 9:20:03 AM Information 12070204 Symantec Management Client is stopped.
7 9/8/2010 9:20:54 AM Information 1207020E Location has been changed to Default.
8 9/8/2010 9:20:55 AM Information 1207020E Location has been changed to Default.
9 9/8/2010 9:20:55 AM Information 12070201
Windows Version info:
Operating System: Windows XP Professional x64 (5.2.3790 Service Pack 2)
Network info:
No.0 "Local Area Connection 2" 00-15-17-72-09-a1 "Intel(R) PRO/1000 PT Quad Port LP Server Adapter" 172.25.5.1
10 9/8/2010 9:20:55 AM Information 12070202 Symantec Management Client has been started.
11 9/8/2010 9:21:03 AM Information 12070301 Connected to Symantec Endpoint Protection Manager (VNDI09055)
12 9/8/2010 9:21:09 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager (VNDI09055)
13 9/8/2010 9:33:21 AM Information 1207021A User is attempting to terminate Symantec Management Client....
14 9/8/2010 9:33:21 AM Information 1207021A Stopping Symantec Management Client....
15 9/8/2010 9:33:23 AM Information 12070204 Symantec Management Client is stopped.
16 9/8/2010 9:33:43 AM Information 1207020E Location has been changed to Default.
17 9/8/2010 9:33:43 AM Information 1207020E Location has been changed to Default.
18 9/8/2010 9:33:43 AM Information 12070201
Windows Version info:
Operating System: Windows XP Professional x64 (5.2.3790 Service Pack 2)
Network info:
No.0 "Local Area Connection 2" 00-15-17-72-09-a1 "Intel(R) PRO/1000 PT Quad Port LP Server Adapter" 172.25.5.1
19 9/8/2010 9:33:43 AM Information 12070202 Symantec Management Client has been started.
20 9/8/2010 9:33:55 AM Information 12070301 Connected to Symantec Endpoint Protection Manager (VNDI09055)
21 9/8/2010 9:34:01 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager (VNDI09055)
22 9/8/2010 9:40:22 AM Information 1207021A User is attempting to terminate Symantec Management Client....
23 9/8/2010 9:40:22 AM Information 1207021A Stopping Symantec Management Client....
24 9/8/2010 9:40:23 AM Information 12070204 Symantec Management Client is stopped.
25 9/8/2010 9:40:29 AM Information 1207020E Location has been changed to Default.
26 9/8/2010 9:40:29 AM Information 1207020E Location has been changed to Default.
27 9/8/2010 9:40:29 AM Information 12070201
Windows Version info:
Operating System: Windows XP Professional x64 (5.2.3790 Service Pack 2)
Network info:
No.0 "Local Area Connection 2" 00-15-17-72-09-a1 "Intel(R) PRO/1000 PT Quad Port LP Server Adapter" 172.25.5.1
28 9/8/2010 9:40:29 AM Information 12070202 Symantec Management Client has been started.
29 9/8/2010 9:40:34 AM Information 12070301 Connected to Symantec Endpoint Protection Manager (172.25.5.3)
30 9/8/2010 9:40:40 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager (172.25.5.3)
31 9/8/2010 9:48:01 AM Information 1207021A User is attempting to terminate Symantec Management Client....
32 9/8/2010 9:48:01 AM Information 1207021A Stopping Symantec Management Client....
33 9/8/2010 9:48:02 AM Information 12070204 Symantec Management Client is stopped.
34 9/8/2010 9:48:11 AM Information 1207020E Location has been changed to Default.
35 9/8/2010 9:48:12 AM Information 1207020E Location has been changed to Default.
36 9/8/2010 9:48:12 AM Information 12070201
Windows Version info:
Operating System: Windows XP Professional x64 (5.2.3790 Service Pack 2)
Network info:
No.0 "Local Area Connection 2" 00-15-17-72-09-a1 "Intel(R) PRO/1000 PT Quad Port LP Server Adapter" 172.25.5.1
37 9/8/2010 9:48:12 AM Information 12070202 Symantec Management Client has been started.
38 9/8/2010 9:48:19 AM Information 12070301 Connected to Symantec Endpoint Protection Manager (172.25.5.3)
39 9/8/2010 9:48:25 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager (172.25.5.3)
40 9/8/2010 10:38:27 AM Information 1207021A User is attempting to terminate Symantec Management Client....
41 9/8/2010 10:38:27 AM Information 1207021A Stopping Symantec Management Client....
42 9/8/2010 10:38:28 AM Information 12070204 Symantec Management Client is stopped.
43 9/8/2010 10:38:34 AM Information 1207020E Location has been changed to Default.
44 9/8/2010 10:38:35 AM Information 1207020E Location has been changed to Default.
45 9/8/2010 10:38:35 AM Information 12070201
Windows Version info:
Operating System: Windows XP Professional x64 (5.2.3790 Service Pack 2)
Network info:
No.0 "Local Area Connection 2" 00-15-17-72-09-a1 "Intel(R) PRO/1000 PT Quad Port LP Server Adapter" 172.25.5.1
46 9/8/2010 10:38:35 AM Information 12070202 Symantec Management Client has been started.
47 9/8/2010 10:38:46 AM Information 12070301 Connected to Symantec Endpoint Protection Manager (172.25.5.3)
48 9/8/2010 10:38:52 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager (172.25.5.3)
49 9/8/2010 10:45:01 AM Information 1207021A User is attempting to terminate Symantec Management Client....
50 9/8/2010 10:45:01 AM Information 1207021A Stopping Symantec Management Client....
51 9/8/2010 10:45:02 AM Information 12070204 Symantec Management Client is stopped.
52 9/8/2010 10:45:50 AM Information 1207020E Location has been changed to Default.
53 9/8/2010 10:45:51 AM Information 1207020E Location has been changed to Default.
54 9/8/2010 10:45:51 AM Information 12070201
Windows Version info:
Operating System: Windows XP Professional x64 (5.2.3790 Service Pack 2)
Network info:
No.0 "Local Area Connection 2" 00-15-17-72-09-a1 "Intel(R) PRO/1000 PT Quad Port LP Server Adapter" 172.25.5.1
55 9/8/2010 10:45:51 AM Information 12070202 Symantec Management Client has been started.
56 9/8/2010 10:45:53 AM Information 12070301 Connected to Symantec Endpoint Protection Manager (172.25.5.3)
57 9/8/2010 10:45:59 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager (172.25.5.3)
If your SEPM was reinstalled
If your SEPM was reinstalled follow any one of the following procedure to connect all clients Back(If you not having a backup of old server.Do you have backup?)
How to point Symantec Endpoint Protection(SEP) clients to a new Symantec Endpoint Protection Manager after you have either uninstalled, are going to decommission or replace the Existing Primary Symantec Endpoint Protection Manager (SEPM).
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Please paste the sylink log
Please paste the sylink log from the client
https://www-secure.symantec.com/connect/downloads/sylink-toggle
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Client can connect but cannot access SEP Console
Thanks for your support so far!
I forgot to restore Certificate. After restored, client now can connect to Server, but I cannot access SEP Manager console.
It displays "Unexpected Error". This happened before, and that's reason why I resinstalled SEP Manager.
After restored certificate, I cannot access to SEP console.
Pls help!
Just Try
PLease go to IIS manager -> SEPM website
Right click on reporting and click on Browse.
You should get a login screen. Use the SEPM credentials and login.
let us know if you are able to login
If this Info helps to resolve the issue please Mark as Solution
Thanks
Go to Programs--->Symantec
Go to Programs--->Symantec endpoint protection manager--->management server configuration wizard and reconfigure your SEPM....
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Run the Mangement server
Run the Management server configuration wizrad
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Problems sill persists
@Maheshroja: appeared error (as attachment)
@ AravindKM: I've tried to reconfigure the server, it worked for a while (about 3 minutes), and error appeared again
Hi
Restart IIS and SEPM related services and check
If this Info helps to resolve the issue please Mark as Solution
Thanks
Restart your server and
Restart your server and try.If not helps Pls attach the scm-server-0.log which is present in Program Files \Symantec\Symantec Endpoint Protection Manager\tomcat\logs
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
@AravindKM: YES I already
@AravindKM:
YES I already tried to restart the server.
Attachment is the log file.
@AravindKM: YES I already
@AravindKM:
YES I already tried to restart the server.
Attachment is the log file.
Hi
Refer this
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/4bd90f7f0f5b95c18825738c00660e10?OpenDocument
If this Info helps to resolve the issue please Mark as Solution
Thanks
Http 403 error is related to
Http 403 error is related to permissions
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Plaese
Its looks like IIS issue , Found in the Log "HTTP 403 Access Forbidden,URL: http://localhost:8014" Remove IIS and Login as Local Administrator and Install IIS and Re-install and Check, If not working then try repair SEPM and see.
If this Info helps to resolve the issue please Mark as Solution
Thanks
Is the SEPM installed on
Is the SEPM installed on Windows XP?
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Ensure that the appropriate
Ensure that the appropriate rights are configured for IIS.
Verify that the DefaultAppPool identity is set to "Network Service."
Open the IIS Administrator
Expand <server name> > Application Pools
Right-click DefaultAppPool and select Properties
Under Identity, verify the Predefined radio button is selected and that the Network Service is selected in the drop-down list.
Verify user rights.
Click Start> Run.
Type gpedit.msc.
Expand Computer Configuration> Windows Settings> Security Settings> Local Policies.
Select User Rights Assignment.
Double-click on Adjust memory Quotas for a Process and Replace a process-level token and verify that the "NETWORK SERVICE" is listed.
Note: If the "Add User or Group..." option is disabled, it is possible that this policy is locked by a domain GPO (group policy object) which will require an assessment of domain GPOs.
Restart the "IIS Admin" service to update any changes.
Verify Authentication and Access Control.
Open the IIS Administrator
Expand <server name> > Web Sites
Right-click on Default Web Site and select Properties
Select Directory Security.
Under "Authentication and Access Control" select Edit.
Verify that Enable Anonymous Access is checked.
Please check the appropriate setting if you are utilizing Authenticated Access.
Verify Secure Communications is not selected (if SSL is not implemented).
Open the IIS Administrator
Expand <server name> > Web Sites
Right-click on Default Web Site and select Properties
Select Directory Security
Under "Secure Communications", select Edit
Verify that Require Secure Channel (SSL) is not selected.
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Error Message: 403.2
Error Message: 403.2 Forbidden: Read Access Forbidden
http://support.microsoft.com/kb/247677
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
HI
Ensure the appropriate rights are configured for Internet Information Services (IIS). Perform the below verifications:
Note - If the "Add User or Group..." button is disabled, it is possible that this policy is locked by a domain GPO (group policy object) which will require an assessment of domain GPOs.
For More info refer http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007122815441848
If this Info helps to resolve the issue please Mark as Solution
Thanks
You are getting this error ,
You are getting this error , beacuse the SEPM is installed on Windows XP. Using a client OS like Windows 2000 Professional or Windows XP to host the SEPM is only feasible in the smallest of networks (fewer than ten SEP clients). If at all possible, it is recommended to install the SEPM on a server OS.
WORK AROUND
Set the connection limit for the Web site to an unlimited number of concurrent connections. To do this, follow these steps:
Click Start, point to All Programs, point to Administrative Tools, and then clickInternet Information Services (IIS) Manager.
ExpandComputerName, and then expand Web Sites.
Right-click the Web site that you want to configure, and then click Properties.
Click the Performance tab.
Under Web site connections, click Unlimited or you can Set the limit value if thats needed for the case.
Click OK,and exit IIS Manager. and Restart the SEPM and IIS service
.
Title: 'Symantec Endpoint Protection Manager is experiencing communication issues on Windows XP or Windows 2000.'
Document ID: 2007102210033448
> Web URL: http://service1.symantec.com/support/ent-security....
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
hi ALL, I follow instruction
hi ALL,
I follow instruction https://www-secure.symantec.com/connect/forums/une...
My SEPM was installed on XP SP3 machine (2GB RAM). So far so good, I keep the Heart Beat intervals to 1 hour and randomize it for 5 Minute, and also keep it in pull mode for the client communication.
By the way, our company now has about 100 XP computer and expands to 250 in the future,do we have to install SEPM on 2K3 machine or just keep it?
Thanks anyway
Yes you have to go for a
Yes you have to go for a server OS in SEPM.100 computer is a more than sufficient reason for a server OS in SEPM...
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Would you like to reply?
Login or Register to post your comment.