Endpoint Protection

 View Only
Expand all | Collapse all

GUP - Group OU issues

MabundaG

MabundaGJun 17, 2016 01:53 AM

PraveenAyappan

PraveenAyappanJul 01, 2016 07:06 AM

  • 1.  GUP - Group OU issues

    Posted Jun 15, 2016 03:53 AM

    Hi, We are running SEP12 RU6MP1 in our environment. Our SEP infrastructure synch with AD. AD synch is set to occur hourly. When configuring GUPs, we move the machine to be configured as a GUP to a certain OU container in AD. The machine moves to the correct OU in AD, but on the client, it stays on another OU.

    I have created a package pointing it to the correct OU, installed it on the server. It seemed fine. After some time, the client SEP group moved back into the incorrect OU container. What might be causing this issue?

    Thanks in advanced,

    Mabunda



  • 2.  RE: GUP - Group OU issues

    Broadcom Employee
    Posted Jun 15, 2016 04:04 AM

    Is the client moving to the AD OU where the computer is registered?

     



  • 3.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 04:11 AM

    Hi, in Active directory, yes

    On the SEP client, it is in another group.



  • 4.  RE: GUP - Group OU issues

    Broadcom Employee
    Posted Jun 15, 2016 04:18 AM

    Ok, if you synch with AD the GUP will move to the OU container of AD.

     



  • 5.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 04:36 AM

    Hi,

    Here is the AD group (This is where the client should be in):

    IT/Servers/SEPMs and GUPs/*OU Name*/*GUP Name*

     

    Group Name in the SEP client

    My Company\saps\IT\Servers\Gauteng

     

     



  • 6.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 04:41 AM

    check the Group the client is pointing to

    HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink

    Value:Preferredgroup



  • 7.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 05:01 AM

    interesting!

    There is no group entry there. There are two strings there.

    1. Default

    2. SylinkFileChecksum



  • 8.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 06:23 AM

    is that particular OU is synced in SEPM and is the client machine a cloned machine by any chance.



  • 9.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 08:10 AM

    Hi, and yes, that OU is synched in SEPM and we synch the whole AD.

    No, the machine is not cloned, it is a newly created VM Win Server 2012 R2.



  • 10.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 08:17 AM

    by any chance is the client trying to register itself to the new OU or no attempts ? and also what is the group name it shows in the client console ?



  • 11.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 08:24 AM

    I do not see any attempts of it trying to register itself to the new OU.

    On the SEP client, it shows that it is on: My Company\Company\IT\Servers\Gauteng

     

    It is suppose to be under: IT/Servers/SEPMs and GUPs/*OU Name*/*GUP Name*



  • 12.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 08:35 AM

    is it happening for all the clients or only one client ? and have you tried to reinstall it ?



  • 13.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 09:14 AM

    I have tried re-installing and it is happening on about 7 servers. We have more than 500 GUPs in the environment.



  • 14.  RE: GUP - Group OU issues

    Posted Jun 15, 2016 10:15 AM

    I suppose it is time for you to engage support. raise a ticket with them.



  • 15.  RE: GUP - Group OU issues

    Posted Jun 17, 2016 01:53 AM

    Thanks Praveen. I will do just that.



  • 16.  RE: GUP - Group OU issues

    Posted Jun 17, 2016 03:59 AM

    Out of curiosity, while the client reports staying in the original OU, do you actually see a record for the client in the AD-Synced group from the SEPM side view?

    I'm wondering if:

    1. The sync is not working, or
    2. You've copied this client out of an AD-Sync group in the past (http://www.symantec.com/docs/TECH142225)


  • 17.  RE: GUP - Group OU issues

    Posted Jun 24, 2016 08:36 AM

    Hi, I have downgraded the SEP client from SEP12 RU6MP1 on the GUP server to SEP12 RU3 as a test. To my surprise, it works the way it should.

    I have logged a call support with Symantec.



  • 18.  RE: GUP - Group OU issues

    Posted Jun 24, 2016 08:47 AM

    well that's interesting, keep us posted on the developments made.



  • 19.  RE: GUP - Group OU issues
    Best Answer

    Posted Jul 01, 2016 06:26 AM

    Steps taken since it’s Win Server 2012,

    1. Stopped the SEP client on the GUP server.

    2. Opened “regedit”

    3. Navigated to “HKLM\Software\Wow6432Node\Symantec\Symantec Endpoint Protection\SMC\Sylink\Sylink\”

    4. Double clicked on “HardwareID”, cleared the value and clicked on ok.

    5. On explorer, I navigated to the following path: “C:\ProgramData\Symantec\Symantec Endpoint Protection\PersistedData”

    6. Renamed “sephwid.xml” to sephwid.old

    7. Restarted the server

    8. Problem sorted.

     



  • 20.  RE: GUP - Group OU issues

    Posted Jul 01, 2016 07:06 AM

    were you imaging your server OS as well ?