Endpoint Protection

 View Only
  • 1.  I need to determine the root cause for Download Insight and/or Intrusion Prevention component malfunctioning

    Posted Jun 26, 2013 07:38 AM

    At random intervals we get notifications that some of our servers (and each time it's different servers) have Download Insight component that's malfunctioning, it also shows that the Intrusion Prevention component is malfunctioning as well.

    We're using SEPM Version 12.1.1000.157 RU1

    I've done some research and it seems that between those two components, if the one fails the other does as well.

    We have Download Insight configured at Level 5 for all servers BUT we don't have Intrusion Prevention enabled because we already have a physical IPS device connected to our domain, and Best Practise suggests you only have one device configured.

    So I need to compile a RCA as to why the Download Insight/Intrusion Prevention components malfunctioning so regularly at random times on random servers?

    I know how to fix the problem, I need to know what might cause this and obviously how we can prevent it?

    Thank you



  • 2.  RE: I need to determine the root cause for Download Insight and/or Intrusion Prevention component malfunctioning

    Posted Jun 26, 2013 08:08 AM

    Run the SymHelp tool on the system and see if any errors are returned.

    You may need to turn on WPP logging to get a better detail.



  • 3.  RE: I need to determine the root cause for Download Insight and/or Intrusion Prevention component malfunctioning

    Broadcom Employee
    Posted Jun 26, 2013 08:22 AM

    open a support ticket and collect the information.

    does refresh goes off the message?



  • 4.  RE: I need to determine the root cause for Download Insight and/or Intrusion Prevention component malfunctioning

    Posted Jun 28, 2013 06:55 AM

    I ran the SymHelp tool on a server that last gave the problem and it picked up the following.

    But it doesn't really make sense because there is no comms issues between the server and the client. I checked the troubleshooting steps and confirmed that the client has the latest def update, it's green and the policy number matches with that of the manager.

    But like I said, it's random servers everytime. I'm not sure that if IPS is disabled by (our) policy that it will affect Download Insight (not disabled by our policy) when it's definitions are updated? That's the only thing I can think of.....

    Untitled.jpg



  • 5.  RE: I need to determine the root cause for Download Insight and/or Intrusion Prevention component malfunctioning

    Posted Jun 28, 2013 08:12 AM

    Hi, 

    For RCA you may need to open a support ticket and work with support team.

    Regards

    Ajin

     



  • 6.  RE: I need to determine the root cause for Download Insight and/or Intrusion Prevention component malfunctioning

    Posted Jun 28, 2013 08:15 AM

    I will do that thank you