Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

Some of the Client are not taking update from gup

Created: 09 Jul 2013 | 22 comments
deepaknk's picture

HI All,

 

Some of Client are not taking update from gup

 

Sepm and gup version is RU3

Between Sepm and gup machine having no network firewall

Client can able to telnet of gup machine on port 2967

All sepm policy are replicating on client machine

 

 

A) I did below mention troubleshooting

 

  1. Change gup client version
  2. Delete all content  from gup machine and restarted
  3.  Uninstall on of the  machine client and reinstalled  

 

 

Operating Systems:

Comments 22 CommentsJump to latest comment

James007's picture

Hi,

Try to clear old virus defination may be Corrupt virus defination cause.

 

Troubleshooting the Group Update Provider (GUP) in Symantec Endpoint Protection (SEP)

http://www.symantec.com/docs/TECH104539

 

Check also this thread

https://www-secure.symantec.com/connect/forums/troubleshooting-sep-client-gup-conectivity-0#/comment-7941591

SameerU's picture

Hi

Please check whether the port 2967 is opened bi-directionally

Regards

 

Rafeeq's picture

Hi,

Enable the sylink log on the client. Most of the times it will be coz of incorrect proxy settings in the registry

http://www.symantec.com/business/support/index?page=content&id=TECH104758

Please post the logs.

raju123's picture

Few Question

How many clients are not getting update from GUP?

Rest of the clients are taking update from that GUP?

Have you seen the latest content in "Shared Updates" folder?

Check these for your help

https://www-secure.symantec.com/connect/articles/how-analyze-debug-logs-gup-determine-which-clients-are-taking-definitions-gup

How to confirm if SEP Clients are receiving LiveUpdate content from Group Update Providers (GUPs)

 

Article:TECH97190  |  Created: 2009-01-03  |  Updated: 2011-08-16  |  Article URL http://www.symantec.com/docs/TECH97190

 

deepaknk's picture

Hi Raju,

80 to 100 are not taking update from gup

yes

yes

deepaknk's picture

Hi,

Thanks to All

HI james007

i deleted old Definition and try but facing same issue

 

 

 

deepaknk's picture

Hi sameeru,

port is opened bi-directionally i checked

Same group some client taking update or some not

 

 

 

deepaknk's picture

Hi pete_4u

find attached logs

 

AttachmentSize
sylink monitor logs.txt 3.05 MB
Rafeeq's picture

from the logs I see that its getting a http 469 response.
SMS return=469
Follow this document

Clients are not getting updates from the Symantec Endpoint Protection Manager. The sylink.log has the following error: 469 CONTENT PENDING.
http://www.symantec.com/business/support/index?pag...

pete_4u2002's picture

is the log of affected client?

looks like the definition is either corrupted or not sending the correct information,

open a support ticket

Chetan Savade's picture

Hi,

Thank you for posting in Symantec community.

Could you please confirm if the setttings are set to bypass GUP if it's not avaialble?

According to the logs I don't see client is trying to attempt connection on 2967 port.

Make sure client and SEPM are having correct policy serial number.

Verify the Liveupdate policy in the SEPM console. Make sure GUP is assigned correctly.

Try to find out machine promoted as a GUP is really acting as a GUP or not?

How to search for the clients that act as Group Update Providers ?

http://www.symantec.com/docs/TECH96094

Test SEP to GUP and GUP to SEPM communication

http://www.symantec.com/docs/TECH153328 

Chetan Savade
Sr.Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |

Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<

deepaknk's picture

how to check this setting ?

bypass GUP if it's not avaialble.

client policy is serial number match with all client and gup is also assigned correctly

pete_4u2002's picture

ro check if it by pass GUP

  1. In the console, open the LU policy assigned.
  2. click on the server settings
  3. click on the griup update provider
  4. chec for the 'Maximum time that clients try to download updates from a Group Update Provider before trying the default management server:' value. if it's never it does not bypass.
deepaknk's picture

yes i mention the same setting

Maximum time that clients try to download updates from a Group Update Provider before trying the default management server i set it is never

 

deepaknk's picture

If I remove gup from remote location than all client can take update form  sepm server.

 

 

1 ) I uninstall exist gup and reinstall

2) assigned one more new gup.

but issue is there

 

pete_4u2002's picture

is the GUP assigned to the group where the client resides?

can you telnet to GUP frm client side on port 2967?

deepaknk's picture

yes gup in same group and client can able to telnet to 2967 prot.

pete_4u2002's picture

check the debug log on GUP and enable sylink log on client and see if any errors can be found.

open a support ticket as well.