Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

IPS definitions out of date?

Updated: 05 Aug 2010 | 15 comments
Gai-jin's picture
0 0 Votes
Login to vote

 SEPM is showing that almost all of my SEP client machines have outdated IPS definitions.  What would cause those not to be updating?

Clients are set to update from the SEPM server. 

discussion Filed Under:

Comments

Rafeeq's picture
02
Nov
2009
0 Votes 0
Login to vote

HI

What is the version you are running ? anything below mr4?

If so you need to upgrade to latest version.. check the fix id. Fix ID: 1405083

let us know the version you are running.

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121216360648
Troubleshooting Content Delivery to the Symantec Endpoint Protection client
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008092511045348

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Gai-jin's picture
02
Nov
2009
0 Votes 0
Login to vote

 Sorry, running RU5

 Sorry, running RU5

ash2107's picture
02
Nov
2009
0 Votes 0
Login to vote

What time is it scheduled to

What time is it scheduled to update those machines.. pleas check whether those client have the green dot showing on the below icon.. on on SEPM and make sure that the SEPM have the latest update.. If the update is too old on those clients.. open end point and click on "FIX" are you on a server enviroment? what windows server are you on to?

Rafeeq's picture
02
Nov
2009
0 Votes 0
Login to vote

HI

Please try these steps

Troubleshooting Content Delivery to the Symantec Endpoint Protection client
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008092511045348

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Gai-jin's picture
02
Nov
2009
0 Votes 0
Login to vote

 The SEPM has signatures

 The SEPM has signatures dated 10/23 -- Rev 001.  Are those the latest available?  I have a handful of clients with those signatures, but most have older versions as far back as 9/11.  Clients do have the green dot.  SEPM runs on Server 2008R2 Standard.

We are using the default liveupdate policies for both settings and content.  I double checked, and the policy does specify to get updates from the management server, and the content settings are all set to latest available.  


Rafeeq's picture
02
Nov
2009
0 Votes 0
Login to vote

Yes

The IPS signature , are upto date, i checked on my machine , thats the latest one.

can u check this document and make sure things are in place

Content Update files in the \Program FIles\Symantec Endpoint Protection\LiveUpdate are growing in size

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008082210033648

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

Gai-jin's picture
21
Dec
2009
0 Votes 0
Login to vote

 Sorry for the long time

 Sorry for the long time without an update.  I got pulled away from this issue and am just getting back to it.  I don't seem to have the issue Rafeeq linked to in the last post, as the directory in question is empty on both the server and the client. 

As of right now, I still have over half of my clients on IPS definitions dated 2009-09-11 rev. 001

Aniket Amdekar's picture
21
Dec
2009
0 Votes 0
Login to vote

Hi, If its an issue with

Hi,

If its an issue with corrupt definitions, this article should take care of it:

https://www-secure.symantec.com/connect/articles/h...

Aniket

Gai-jin's picture
22
Dec
2009
0 Votes 0
Login to vote

 Aniket -- Thanks for the

 Aniket -- Thanks for the suggestion.  I went through that whole process, then ran 'update content' on a client from the console, and after it finished, the client is still on 9-11 defs.  

Any other suggestions?

Gai-jin's picture
28
Dec
2009
0 Votes 0
Login to vote

 Bump.  Any other

 Bump.  Any other suggestions?

Grant_Hall's picture
28
Dec
2009
0 Votes 0
Login to vote

Hi Gai-jin, Two

Hi Gai-jin,

Two questions:

Are you using replication between two servers?

Where are you looking to see that IPS is outdated the homepage or client tab? Please verify that is shows as outdated in both locations.

Thanks,
Grant-

Please don't forget to mark your thread solved with whatever answer helped you : )

Gai-jin's picture
28
Dec
2009
0 Votes 0
Login to vote

 Grant_Hall: We only have one

 Grant_Hall: We only have one SEPM server.  It was migrated to a new server a while back, using the replication method.

The graph on the homepage shows the IPS defenitions out of date, and when I browse to an individual client and pull up properties, it also shows out of date there.  

Grant_Hall's picture
28
Dec
2009
0 Votes 0
Login to vote

Thanks Gai Well it wasn't the

Thanks Gai

Well it wasn't the problem I was thinking of then (issue a while back where the homepage reported different from the client tab). I will keep looking into this. Have you opened a case with phone support yet? If so please post the case number so we can follow it.

Thanks
Grant

Please don't forget to mark your thread solved with whatever answer helped you : )

Gai-jin's picture
28
Dec
2009
0 Votes 0
Login to vote

 I haven't opened a phone

 I haven't opened a phone support case yet.  I probably won't be able to until next week, as we have had staff off last week and this week for the holidays.  When we're back to full staff I'll have more time.  


brav's picture
05
Feb
2010
0 Votes 0
Login to vote

Gai-Jin did you manage to

Gai-Jin did you manage to resolve this issue ?

I'm experiencing the same at one of our sites. I've installed SEP RU5 on the machines and rolled out IPS across the company. Only one site is having problems , the same stated above . All other sites are ok & it's the same definitions going out.....

m00