Endpoint Protection

 View Only
  • 1.  SEP 12.1 client causing network broadcast storm

    Posted Aug 11, 2011 01:28 PM

    I have just installed SEP Manager 12.1 on my server and deployed the 12.1 client to a few groups of machines.  On one machine (Win 2003 Server), the moment that the client becomes active, the machine floods the network with some sort of broadcast and takes it down.  Unfortunately, this being a server, I haven't been able to take it down to do any troubleshooting beyond determining that uninstalling the SEP 12.1 client fixes the issue (and event logs show nothing remarkable).  I plan to schedule a time on a weekend (when it can be taken down) to plug it into an isolated switch and try to do some packet captures to see if I can determine what sort of info the broadcast flood contains.  In the meantime I was going to roll it back to 11.x until I can determine the issue.

    Any suggestions, recommendations, insight would be helpful.

     

    Thanks,

    Eric



  • 2.  RE: SEP 12.1 client causing network broadcast storm

    Posted Aug 11, 2011 01:33 PM

    check client logs, have you set the option to send data log to symantec?



  • 3.  RE: SEP 12.1 client causing network broadcast storm

    Posted Aug 11, 2011 02:17 PM

    I haven't looked at the client logs, mainly because I had to get the machine back up and running as quickly as possible.  The problem is that once the client starts up, the broadcast storm it creates takes the network down so nothing can communicate.  I have to unplug it and remove the client to get it back up and running.  I can take a look at the logs when I take it down on a weekend to troubleshoot it.

    Where is the option to send data logs to Symantec set?

     

    Thanks,

    E



  • 4.  RE: SEP 12.1 client causing network broadcast storm

    Posted Aug 11, 2011 02:32 PM

    If it during boot procedure then I doubt symantec services would actually start, it starts when computer starts.First check if it works fine after uninstalling SEP, I doubt this could be related to SEP, If you have NTP and PTP components intalled you can turn those off  by removing frm add/remove progtrams and check



  • 5.  RE: SEP 12.1 client causing network broadcast storm

    Posted Aug 11, 2011 02:46 PM

    It's definitely when the SEP service starts.  I've tried it twice and the moment the SEP client finishes deploying and the service starts, the broadcast storm starts.  Removing SEP fixes the issue.  It's possible that it's conflicting with another service on the server, but I haven't been able to diagnose what yet.



  • 6.  RE: SEP 12.1 client causing network broadcast storm

    Posted Aug 11, 2011 03:53 PM

    I would need to see a pcap to see what it is but I've got about 20 clients on our prod network and they don't make much noise.

    I've not seen this issue on the forum yet so I'm curious as to what this could be, especially if it's broadcast and creating this much of a problem for you.



  • 7.  RE: SEP 12.1 client causing network broadcast storm

    Posted Aug 11, 2011 03:57 PM

    That was sort of my plan when I can find time one weekend when I move it to an isolated network and not affect daily operations.