Endpoint Protection

 View Only
Expand all | Collapse all

SEP client offline status and not reporting to SEPM

Migration User

Migration UserJun 01, 2015 01:12 AM

  • 1.  SEP client offline status and not reporting to SEPM

    Posted May 31, 2015 09:58 PM
      |   view attached

    Good Day,

     

    I have encountered problem on my SEP clients. 3 subnet range from my remote site suddenly disconnected on my SEPM server. SEP client status now is OFFLINE and they are not reporting to my SEPM server. My SEP version is 12.1 RU2

    Client to SEPM communication:

    1. Ping is good from both end, client >< SEPM communication

    2. RDP is good from SEPM to client

    3. Tracert was successful

    4. Client communication port was open

    Isolation that i already did was the following:

    1. Update communication settings

    2. Change the Sylink file

    3. Re-install SEP client

     

    Is there other procedure i can consider on resolving this issue? Thanks

     

    Best Regards,

     

    Attachment(s)

    zip
    Sylink.zip   8 KB 1 version


  • 2.  RE: SEP client offline status and not reporting to SEPM

    Posted May 31, 2015 10:01 PM

    Enable sylink debugging on the affected client to see what is going on. Post the log here for review if needed. Also run the symhelp tool.



  • 3.  RE: SEP client offline status and not reporting to SEPM

    Posted May 31, 2015 11:46 PM

    Are you able telnet port 8014 ?

    does any changes in firewall site.



  • 4.  RE: SEP client offline status and not reporting to SEPM

    Posted May 31, 2015 11:48 PM

    @Brian - I already attached the sylink log. Hope you can have a time to check

     

    @James - we are using customize port for SEP communication and as per checking with network team the port is open both ways

     

    Best Regards,



  • 5.  RE: SEP client offline status and not reporting to SEPM

    Posted May 31, 2015 11:56 PM

    As per logs 'Connection Failed'

     

    6/01 09:55:17.328 [5340] 9:55:17=>Send HTTP REQUEST
    06/01 09:55:38.341 [5340] 9:55:38=>HTTP REQUEST sent
    06/01 09:55:38.341 [5340] <GetIndexFileRequest:>Send Request failed.. Error Code = 12029
    06/01 09:55:38.341 [5340] <ParseErrorCode:>12029=>The attempt to connect to the server failed.
    06/01 09:55:38.341 [5340] <GetIndexFileRequest:>Send Request failed.. Error Code = 12029
    06/01 09:55:38.341 [5340] <ParseErrorCode:>12029=>The attempt to connect to the server failed.
    06/01 09:55:38.341 [5340] <GetIndexFileRequest:>COMPLETED
    06/01 09:55:38.341 [5340] <IndexHeartbeatProc>GetIndexFile handling status: 6
    06/01 09:55:38.341 [5340] <IndexHeartbeatProc>Switch Server flag=1
    06/01 09:55:38.343 [5340] HEARTBEAT: Check Point 5.1
    06/01 09:55:38.343 [5340] <ScheduleNextUpdate>new scheduled heartbeat=2048 seconds
    06/01 09:55:38.343 [5340] HEARTBEAT: Check Point 8
    06/01 09:55:38.343 [5340] NextProxySetting: Cycled through all proxy settings.
    06/01 09:55:38.343 [5340] Get Next Server!
    06/01 09:55:38.343 [5340] ResetProxySetting: Will now use proxy setting 1
    06/01 09:55:38.343 [5340] <PostEvent>going to post event=EVENT_SERVER_DISCONNECTED
    06/01 09:55:38.344 [5340] <PostEvent>done post event=EVENT_SERVER_DISCONNECTED, return=0
    06/01 09:55:38.344 [5340] <IndexHeartbeatProc>====== IndexHeartbeat Procedure stops at 09:55:38 ======
    06/01 09:55:38.344 [5340] <IndexHeartbeatProc>Set Heartbeat Result= 1
    06/01 09:55:38.344 [5340] <IndexHeartbeatProc>Sylink Comm.Flags: 'Connection Failed' = 1, 'Using Backup Sylink' = 0, 'Using Location Config' = 0
    06/01 09:55:38.344 [5340] <IndexHeartbeatProc>Connection Failed! No. of tries = 1
    06/01 09:55:38.344 [5340] Use new configuration
    06/01 09:55:38.344 [5340] HEARTBEAT: Check Point Complete
    06/01 09:55:38.344 [5340] <IndexHeartbeatProc>Done, Heartbeat=2048seconds
    06/01 09:55:38.361 [5340] </CSyLink::IndexHeartbeatProc()>

     

    Troubleshoot client/server connectivity in Endpoint Protection

    https://support.symantec.com/en_US/article.TECH105894.html



  • 6.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 01:00 AM

    The clients are trying to communicate on port 50100, is this the right port you have set?

     <SendRegistrationRequest:>http://192.168.9.15:50100
     

    Please confirm this first,

     



  • 7.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 01:09 AM

    Hi James,

    Part of the checking that i already did was below. Please let me know if there is any specific checking you want me to try. Thanks

    Client to SEPM communication:

    1. Ping is good from both end, client >< SEPM communication

    2. RDP is good from SEPM to client

    3. Tracert was successful

    4. Client communication port was open

     

    Best Regards,

     



  • 8.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 01:12 AM

    Yes that is the right port



  • 9.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 01:51 AM

    Ok , please try these two things and share the results, 

    1) Secars test, to make sure IE is not blocking anything

     

    https://support.symantec.com/en_US/article.TECH102682.html

     

    2) Proxy Block issue

    https://www-secure.symantec.com/connect/blogs/troubleshoot-method-offline-clients



  • 10.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 01:52 AM

    Check it

    https://www-secure.symantec.com/connect/forums/client-not-connect-sepm-server

     

    Try to one client

    Check in the registry (HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings) those keys
    "ProxyEnable"=dword:00000001
    "ProxyServer"="test:80"

    2. Change ProxyEnable to 0
    3. Delete ProxyServer key

    These settings are also cached in Hex format in the following location: HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
    -DefaultConnectionSettings
    -SavedLegacySettings

    If DefaultConnectionSettings and SavedLegacySettings are present, they will re-populate the proxy settings. If they are NOT present, they will be generated with the current proxy settings. This can cause issues if the customer tries to alter just "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable" without also purging DefaultConnectionSettings/SavedLegacySettings before a reboot.



  • 11.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 02:06 AM

    The result for Secars is "Page cannot be displayed". Also, we are not using Proxy here 



  • 12.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 02:27 AM

    Most probabally this issue is occur becaure of port is not open or not connected either it show ok.

    Telnet the port 8014 from client or from server.

    If it not work then require to open from firewall



  • 13.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 02:27 AM

    I suggest you can raised support ticket,

    I hope soe thing changes in network side.



  • 14.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 02:29 AM

    the problem is on the client side then... or with port,

    can you do a 

    telnet SEPMIP PortNumber, does that open?

    You are not using proxy but from the log it says

    NextProxySetting: Will now use proxy setting 2

    can you verify those proxy registry settings I posted above, you may need to delete and restart



  • 15.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 03:27 PM

    FYI:  I've got the same issue after installing the May Microsoft updates on a 2008 server and rebooting.



  • 16.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 03:52 PM

    Update: I uninstalled KB3061518, rebooted the server, and the clients came back online.



  • 17.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 09:45 PM

    I've tried running telnet from SEPM to client and the result was "Connect failed".

     

    I also tried to run update communication from SEPM to some clients and result was below..Capture.JPG

    Clients are still not reporting back to SEPM server.

     

    Best Regards,

     



  • 18.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 01, 2015 09:59 PM

    Are your clients also affected by this issue when you install the update? Thanks

     

    Best Regards,



  • 19.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 02, 2015 01:22 AM

    Telnet from SEPM to client on port will fail because there is no service listening on that port.

    Did you delete the Proxy settings as I mentioned above? Is IE configured to WorkOffline?



  • 20.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 02, 2015 03:51 AM

    We had similar issues in the past, still don't now how we solved it. I'm not an expert here but what happens if you reboot the server or services? Do the clients stay offline or are the clients online and after a while they go offline? We saw this with us, clients came online but not for long.
     



  • 21.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 07, 2015 09:15 PM

    Update:

     

    As verified, there was no Proxy configured.As per checking and validated, the listening port is not open. With this we requested and open the listening port for SEP communication.

    But currently clients are still not reporting to SEPM server with the following error on the client

    Error: Application level WinInet error 12019

     

    Hope you can help me with this one. Thanks

     

    Best Regards,



  • 22.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 07, 2015 09:21 PM

    Have you engaed support? May need to enable advanced debugging within Symhelp and start looking at packet traces...



  • 23.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 08, 2015 12:03 AM

    I haven't engaged with support yet.

    Another question, just to clarify my thoughts. In my situation, clients from remote site are not connecting on the SEPM server.

    Question are:

    1. Is it necessary to open communication port both ways? SEPM to remote site and vise versa? Or it is ok to just open port communication from remote site to SEPM?

    2. Is the communication traffic both ways? or from client to SEPM only?

     

    Please advise. Thanks

     

    Best Regards,



  • 24.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 08, 2015 05:09 AM

    connection is initiated by client. 

    its one-way



  • 25.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 08, 2015 06:32 AM

    Depends. Are  you in push or pull mode?

    In push mode the SEPM will push down data and if in pull mode the client will initiate.



  • 26.  RE: SEP client offline status and not reporting to SEPM

    Posted Jun 08, 2015 08:57 PM

    I'm in pull mode. Meaning to say i don't have any issue now in communication port since I can already telnet the SEPM on the remote site. Maybe i should now engaged with support.

     

    Best Regards,