Endpoint Protection

 View Only
  • 1.  GUP not getting content from manager

    Posted May 06, 2012 02:34 PM

    Hello everybody!

    I am a little new with this forum so i hope to post in the correct place.

    Im dealing with a extrange GUP case for a while, and im not able to find a solution. This is the thing:

    A customer wants to test how GUPs work, he created a group with a single GUP and a client. Both apply the policy (client is pointing correctly to the GUP on registry, and GUP is listenning on port 2967). But none are downloading content. There is no proxies anywhere. Both are on the same subnetwork. Manager has updated definitions and clients on other groups without GUP configured are updating correctly.

    When he changes the GUP or the client to the default group, they correctly download content.

    He ran Cleanwipe on client and GUP and reinstall SEP again, but the results are the same.

    The Hello secars test works OK. Ping and telnet to client,GUP or manager works fine for every port. All versions are the same (12.1.1000.157).

     

    Im running out of ideas to check whats going on! I attach the Sylink.log and debug.log of the GUP and hope someone out there can help me a little!

    Attachment(s)

    txt
    debug log GUP.txt   245 KB 1 version
    txt
    GUP sylink.txt   681 KB 1 version


  • 2.  RE: GUP not getting content from manager

    Broadcom Employee
    Posted May 07, 2012 01:11 AM

    the SEPM itself is updated witrh 2012/04/16 rev018, which is same definition on client.

    if SEPM is not updated reinstall liveupdate. check this link

    http://www.symantec.com/business/support/index?page=content&id=TECH171060



  • 3.  RE: GUP not getting content from manager
    Best Answer

    Trusted Advisor
    Posted May 07, 2012 01:16 AM

    Hello,

    Upon checking your Logs, we found the following - 

     

    04/17 11:58:51.987 [29304] <SendRegistrationRequest:>http://129.39.137.155:8014
    04/17 11:58:51.987 [29304] 11:58:51=>Send HTTP REQUEST
    04/17 11:58:52.096 [29304] 11:58:52=>HTTP REQUEST sent
    04/17 11:58:52.096 [29304] 11:58:52=>QUERY return code
    04/17 11:58:52.096 [29304] 11:58:52=>QUERY return code completed
    04/17 11:58:52.096 [29304] <SendRegistrationRequest:>SMS return=407
    04/17 11:58:52.096 [29304] <ParseHTTPStatusCode:>407=>Uninterpreted Status
    04/17 11:58:52.096 [29304] <SendRegistrationRequest:>Content Lenght => 4106
    04/17 11:58:52.096 [29304] HTTP returns status code=407
    04/17 11:58:52.096 [29304] <SendRegistrationRequest:>RECEIVE STAGE COMPLETED
    04/17 11:58:52.096 [29304] <SendRegistrationRequest:>COMPLETED, returned 5

     

    This could happen due to old legacy Proxy settings still avaialble in the registry.

     

    Try these steps provided below:

     

    Re-generate the current proxy settings.

    Back up registry
    1. Click Start, and then click Run.
    2. In the Open box, type regedt32, and then click OK.
    3. Locate HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\.
    4. Right Click on Connections from the menu, click Export.
    5. In the Save inbox, select a location in which to save the .reg file, type a file name in the File name box, and then click Save

    Remove DefaultConnectionSettings & SavedLegacySettings
    1. Delete the following registry keys:
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
    HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
    2. Reboot the system.

    Note: Windows will detect the keys have been removed and re-generate the keys to the current values. The DefaultConnectionSettings
    DefaultConnectionSettings registry values under the following registry key can be also be removed in case it may take some time to reboot the machine -

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections

    Reference: http://www.symantec.com/docs/TECH104926

    Hope that helps!!



  • 4.  RE: GUP not getting content from manager

    Posted May 09, 2012 06:28 PM

    Thanks Mithun!

    Exactly, after deleting those registries, the GUP started communicating!