Moving Endpoint Protection Management to another server
Updated: 21 May 2010 | 21 comments
I want to wipe out our old SEP Server because I do not have the password for it and the reset doesn't work and the IT guy I replaced has nothing documented. What is the best possible way to put this on another server and get all clients managed on the new server.
Thanks
discussion Filed Under:
Comments
There are 4 ways in which we
There are 4 ways in which we can move SEPM from one server to another.
1. Disaster Recovery
2. Move SEPM form one server to another with the same ip address ( as suggetsed by vikram)
3. Replication
4.Clean install on the new server and then replace the sylink.
1. Disaster Recovery :
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007082112135948
2. Move SEPM form one server to another with the same ip address
http://service1.symantec.com/support/ent-security.nsf/docid/2008031204405448
3. Replication : Add a replication partner to the old SEPM. Stop all SEPM service on the old SEPM so that all the cleints move to the new SEPM, then Uninstall the old SEPM
4.Clean install on the new server and then replace the sylink.: Uinstall SEPM from the old server. Install SEPM on the new server and replace the sylink using sylink replacer:
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
I notice #2 keeps being
I notice #2 keeps being posted as moving to a server with same IP address when the link is really for moving to a server with a DIFFERENT IP address.
My recommendation
I'd go for the 2nd option in your situation. But the 4th option should work as well.
[Edit]
Now that I think about it more, I think the 4th option is best. You can keep the current one running until you get your new one setup as you like then force all the clients to start talking to the new server.
Eric C. Lukens IT Security Policy and Risk Assessment Analyst University of Northern Iowa
You have mentioned "I do not
You have mentioned "I do not have the password for it and the reset doesn't work". Why its not working... What was the error...? If you can reset the password its easy to replace the server.
Just have to take a backup of database, server.xml, keystore.jks and restore it on to new server.
Regards,
Srinivas H.P.
HCL Infosystems Ltd
I would rather figure out why
I would rather figure out why resetting the password isn't working. The error message I get is the following:
Failed to connect to the server.
Make sure that the server is running and your session has not timed out.
If you can reach the server but cannot log on, make sure that ou provided the corret parameters.
If you are experiencing nettwork issues, contact your system adminstrator.
Make sure the server is running? Is that saying make sure the service is running? It wasn't but I did start it manually.
I followed the steps to reset the password so I assume admin/admin is the credentials but I don't know that for sure.
This is not a password issue.
This is not a password issue. Please check are you getting any error in the event viwer
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Title: 'Symantec
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Check scm-server-0.log
Check scm-server-0.log log file under "\program Files\symantec\symantec Endpoint Protection Manager\tomcat\logs" folder.
Paste the error here....
Regards,
Srinivas H.P.
HCL Infosystems Ltd
This is the error I am
This is the error I am gettiing:
Symantec Endpoint Protection Manager service stops with a Java -1 error in the event log
This is beyond frustrating and annoying. I feel like just uninstalling it no longer using this product.
Title: 'Symantec Endpoint
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
I saw it the first time you
I saw it the first time you posted it and none of the options solved the problem. Still getting the same message. I'm done. I will try and do a fresh install on the new server. If it doesn't work I will look into another product. Now I have to figure out how to get all the clients linked to the new server.
inorder to restore the
inorder to restore the commuincation with SEPM we need to replace the sylink.xml from the new SEPM to the clients.
You can use either of the 2 to do that
Also before moving the SEPM to the new folder, will it be possible for you to paste the scm.server0.log
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
For me number 4 is the best
For me number 4 is the best way to have a new sepm, you can find unmanaged client anyway...then replace the sylink at once..
If you have unmanaged client
If you have unmanaged client that is the best way to bring back all the client to SEPM...
You can go for a new version(RU5). You can download it from fileconnect.
Regards,
Srinivas H.P.
HCL Infosystems Ltd
Upgrade will solve your problem
Dear Reaser,
I understand that you have lost the the exixting password. The best and effort less way to do it is:
1. Take the Server privite key backup folder.
2. Download the latest SEP version RU 5 which is avilable in the net.
3. Install the SEPM with a the same IP and Host name.
4. Restoring the server certificate
The server certificate is a Java keystore that contains the public certificate and the private-public key pairs. You must enter the password that is contained in the
Backup.txt file. This password is also in the original server_timestamp.xml file.
To restore the server certificate
Note: If you have implemented one of the other certificate types, select that type.
Note: The only supported paste mechanism is Ctrl + V.
Note: If you get an error message that says you have an invalid keystore file, it is likely you entered invalid passwords. Retry the password copy and paste process as described above.
Note: Do not close the Services window until you are finished with disaster recovery and establish client communications.
Note: By stopping and starting Symantec Endpoint Protection Manager, you fully restore the certificate.
5. Re-deploy the clients with SEP RU5, not only the clients will get updated they will also recommunicte with the SEPM Server.
Please let me know if you need any more information.
Warm Regards,
Sumit Bose
Hi Sumit The information that
Hi Sumit
The information that you are providing to the customer has already been provided
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007082112135948
Above all Disaster Recovery will not work untill and unless you have the Encryption password.
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
@Prachand,Im my case SEPM is
@Prachand,
Im my case SEPM is up and running... I have reinstalled and restored the SEPM in many cases(by restoring database, overwriting server.xml and keystore.jks files and reconfiguring SEPM) and i have not come across the use of this password.
I need to know the scenario where exactly its required in the future, We have other methods of disaster recovery with out that password(Like i have mentioned above).
Regards,
Srinivas H.P.
HCL Infosystems Ltd
Hi Srinivas In order To
Hi Srinivas
In order To restore client communications with a database backup we need the encryption password.
As when you run the managemnt server configuration wizard we need the encrypttion password.
Also there has been instances where after restoring the Database back up you get JAVA -1. In that case we need to run the managment server configuration wizard and that requires the original database password.
When the Best Practice Senario for DR is considered the following is needed:
Keystroke
private keys
server.xml
Domain Id
Encryption password
host name
site name
ip address
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
When we run management
When we run management configuration wizard after db restore, it wont ask for that password.
I m not importing the Keystroke.jks and server.xml files i m directly copying it to tomcat folder.
When i do that and reconfigure SEPM it wont ask for any password. sem5 db password is the only one asked.
Regards,
Srinivas H.P.
HCL Infosystems Ltd
reaser Problem Solved or he Choose other Products ???
@ All Admins, Specially Symantec Employees .
Why reaser who starting this froum didn't answer (Feedback) about his Problem ? Who care about hi's last status & what he did at the end ?
If there was a Case Status in Symantec Connect to follow the Problem up to End, it can help to All Customers, even Professionals here .
Hi Nourbaksh , What ever
Hi Nourbaksh , What ever information could have been provided has been provided to him , No its up to him , if he tries the steps suggetsed , or give more information as in the logs requested
Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)
Would you like to reply?
Login or Register to post your comment.