Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Managed SEP client virus def not updating

Created: 24 Jan 2012 | 8 comments
ahtshun's picture
+1 1 Vote
Login to vote

Hi all,

I just upgraded my SEPM to 12.1.1000.157 and still progressively upgrading all my managed SEP clients.

However i found out that most of my SEP clients virus definition were not updated.

Virus and Spyware protection definitions: 23rd  Jan 2012 r34

Proactive Threat Protection definitions: 23rd  Jan 2012 r11

Network Threat Protection definitions: 21st Jan 2012 r2

 

I did enable my LUA server to download virus definitions for both SEP 11.x and SEP 12.x.

 

Can someone assist me on my issue?

Thank you in advanced.

Comments

Avkash K's picture
24
Jan
2012
1 Vote +1
Login to vote

Have you confirmed on your

Have you confirmed on your LUA that it's successfully downloading & distributing the defs.??

Also confirm when you last LUA download has been done?

If it's done today then it will show 24th Jan defs.

 

Regards,

Avkash K

ahtshun's picture
24
Jan
2012
0 Votes 0
Login to vote

Hi avkash, Yes my LUA ran

Hi avkash,

Yes my LUA ran successfully today.

 

Mick2009's picture
31
Jan
2012
0 Votes 0
Login to vote

Double-checked?

Hi Ahtshun,

First question: is this an all-SEP environment where the SEPMs can access the internet?  If so, allowing them to automatically download their own materials may be the best idea. 

When is it Recommended to Use LiveUpdate Administrator 2.x with Symantec Endpoint Protection?
Article URL http://www.symantec.com/docs/TECH154896

 

Here are a couple of excellent links to help you make sure that your LUA 2.x server is in fact downloading and distributing the correct materials.

The following resources can help admins to determine how best to configure their LUA:

LiveUpdate Administrator 2.x: What product selections are needed for specific versions of Symantec Endpoint Protection?
Article URL http://www.symantec.com/docs/TECH139618

LiveUpdate Administrator: Product Selection Guide
https://www-secure.symantec.com/connect/articles/liveupdate-administrator-product-selection-guide 

 

There are some admins who have accidentally configured their LUA servers to download SEP 12.0 materials, or SEP 12.1 beta materials. 

My in-house LUA is working perfectly with SEP 12.1 SEPMs.  Do update this thread with additional details and the admins here in teh forum can help you get yours working well, too.

With thanks and best regards,

Mick

AR Sharma's picture
24
Jan
2012
1 Vote +1
Login to vote

Here's the Solution!

This is very beautiful flowchat for troubleshooting client defs issue step by step. Please go through it, you will definately get the solution.

If you are able to narrow down your issue and still not able to solve, then please let us know.

http://www.symantec.com/docs/TECH95790

Thanks & Regards,

AR Sharma,

IBM Certified System Admin- Lotus Domino V7

ITIL V2 Certified

cus000's picture
25
Jan
2012
0 Votes 0
Login to vote

Try to check client LU

Try to check client LU log....

ShadowsPapa's picture
25
Jan
2012
1 Vote +1
Login to vote

This is a big issue with SEP

This is a big issue with SEP in the past few days - I'm seeing this situation all over the place.

Including our own, which is causing us to have to review SEP in general because of the nasty issues with the 12.1 upgrade that trashed a lot of stuff a few weeks ago.  Personally, I feel 12.1 is a disaster.

Everything was just fine last week as of Tuesday, the 17th. SEP 11.0.7 clients, SEPM servers - 2 of them, VMs running Server 2008R2 and SEPM 12.1 RU1.

One of the SEPM servers was protected via SEP 11.0.7, the other was a clean build because of earlier issues and was running SEPM 12.1 RU1 for OS protection. (the SEPM upgrade trashed things seriously)

ALL CLIENTS were otherwise running SEP 11.0.7 (in big part because they would not update using any means, and attempts to manually force an update really trashed them)

ALL clients were getting updates perfectly. SEPMs were running LU every hour, and the clients used ONLY our management servers for updates except notebooks that could not contact the SEPMs - they had a different policy for the "off-network" location that allowed them to do LU to Symantec for updates. The LU updates running on the SEPM server ran like it should the logs look normal - they are stating new defs were downloaded.

Starting on the 19th, 2 or 3 client computers were unable to update- they were stuck as far as defs. Worse - one was the BOSS. He had to run the update file from Symantec to get DEFS updates. It kept getting worse with more computers "falling off" - they'd check in, but not get updates. I was out of state for a week and unable to see this as it started and progressed, by the time I returned, it's a total disaster, a real mess.

Finally, as of today, the 25th, the SEPM servers are stuck at the defs from the 20th, some clients are stuck at the 19th, 21st, the vast majority of clients are stuck at the 22nd r4 while 27 clients are stuck on the 23rd, r18 defs, 3 got defs from the 24th, and worse yet, I keep getting server health alerts that the clean fresh server with a clean fresh install of SEPM12.1 RU1 hasn't checked in for 10 minutes. In fact, every so often in the console, it is showing off-line. It's currently on-line, but overnight, I got 3 such alerts.

I never see such alerts from SEPM1 which was an upgrade to 12.1 RU1 over the top of SEPM 11.0.7 

Quite frankly, if it was really simple, I'd trash 12.1, and go back to 11.0.7, the last STABLE build of the SEPM SEP products, but it's far too late since SEPM12 changed the database drastically and it would cost us thousands to do so now.

So - I need a solution to the DEFS issues and the SEPM server communications issue and I need it fast - especially since the boss is involved, he has to manually update defs every day, and he knows how unhappy I am in general with the 12.1 upgrade process. With the state wanting to consolidate IT services, this is NOT a good time to be looking bad while we go through a state audit. The result will be a move to the central AV - state standard, which is currently sophos.

BAAAD timing guys as the entire state is reviewing what AV/EP product to choose as the standard for all agencies. Very bad timing. Frankly, it could cost Symantec the entire state account. And frankly, this week, I'm inclined to agree. It's not what I'd choose, but when you have hundreds of computers scattered across an entire state - most of which are on old defs and losing protection......... and we don't have staff out there to deal with it, it's panic time here.

I'm seeing this defs update issue with many other customers, and this forum is a small sample. SEPM12 has some serious issues.

OtisOverdrive's picture
26
Jan
2012
0 Votes 0
Login to vote

New Clients

I have a new 12.1 Management server.  The server gets updates daily, but none of the 12.1 clients get updates.  I have one 11.x machine that does get updates.  Why would the older client get updates, but none of the new?

SameerU's picture
30
Jan
2012
0 Votes 0
Login to vote

Hi

Please check whether there is any content filtering for the sites

Regards