Endpoint Protection

 View Only
  • 1.  Reinstalled SEPM 11 and now SEP clients won't check in with it.

    Posted Oct 30, 2012 12:51 PM

    I have two SEPMs running 11 RU7 MP2 in a load balanced environment.  I decided to take one of them and uninstall the SEPM off of C drive and reinstall it on E drive.  After I completed the reinstall i noticed that the SEP clients were no longer communicating with the SEPM I reinstalled.  After some research it appears that this is due to the sylink.xml not having the proper certificate for the reinstalled SEPM.  I didn't think about this when I initially reinstalled the SEPM so I don't have a backup of the cert myself. 

     

    I thought of two different things to try...

     

    1. Backup the cert from the good functioning SEPM and import it into the other SEPM since looking at the cert within the sylink.xml it looked the same for both servers. 

    - I tried this and the process worked fine but no SEP clients still would check into the reinstalled SEPM.

    2. I found a list of cert files from the previous install of SEPM on C:.  I tried using one of the previous ones and it did not work.  I believe these backups were from times when the SEPM was upgraded from one revision to another.

     

    So at this point I'm kind of stuck.  Looking for suggestions on how to approach this without having to manually touch all 6000 machines.  Does anyone have a way to do this from the SEPM side?

     

    Thanks,

    Mike



  • 2.  RE: Reinstalled SEPM 11 and now SEP clients won't check in with it.

    Broadcom Employee
    Posted Oct 30, 2012 01:00 PM

    can you check if there is management server list ? if yes, what is the setting?

     



  • 3.  RE: Reinstalled SEPM 11 and now SEP clients won't check in with it.

    Posted Oct 30, 2012 01:06 PM

    See solution in this thread:

    http://www.symantec.com/connect/forums/sepm-cannot-see-clients



  • 4.  RE: Reinstalled SEPM 11 and now SEP clients won't check in with it.

    Posted Oct 30, 2012 02:28 PM

    There is a management server list.  And the list contains both load balanced SEPMs by name and then by IP address in the list.



  • 5.  RE: Reinstalled SEPM 11 and now SEP clients won't check in with it.

    Posted Oct 30, 2012 02:41 PM

    Thanks Brian for the link.  This is exactly what I tried but it didn't seem to do the trick.  I'm going to go back and try it again with a previous jks file in the folder and see if I have any better luck.  I'll keep you guys posted.

     

    Mike