Endpoint Protection

 View Only
  • 1.  Steps to fail over to Passive SEPM node

    Posted Dec 11, 2014 08:14 AM

    We just upgraded our passive SEPM node to 12.1.5 as we are having GUP issues.

    What are the proper steps to fail over to the updated passive node so we can confirm it is functioning properly before upgrading the primary node?



  • 2.  RE: Steps to fail over to Passive SEPM node

    Posted Dec 11, 2014 08:22 AM

    You would need to stop the SEPM service.

    Just make sure you configure your management server list correctly. Both SEPMs needs to be listed and you can set each with a Priority 1 or 2. Once you stop the service, clients should go to the next SEPM in the MSL.

    Configuring a management server list

    Managed Load Balancing: Setting up Management Server Lists based on locations in Symantec Endpoint Protection Manager.



  • 3.  RE: Steps to fail over to Passive SEPM node

    Posted Dec 11, 2014 08:31 AM

    Setup the MSL.. So that after you stop the SEPM service, the clients would start communicating witht the othe SEPM. 

    http://www.symantec.com/docs/TECH103175



  • 4.  RE: Steps to fail over to Passive SEPM node

    Posted Dec 11, 2014 08:46 AM

    To clarify, the SEPM services must be stopped on ALL SEPMs in the same site (i.e. sharing the same DB) prior to the upgrade anyway.

    This means that after the upgrade of your passive SEPM to RU5, it should be the only one with running services, and therefore the only one clients can connect to.  This means just logging into it should show you whether or not things are working.

    If all's cool, shut down the services on the passive SEPM (so that, again, services are stopped on all SEPMs) and upgrade the primary.  Once done, log in and check if clients are checking in, the startup the services on the passive SEPM (as they'll both be on the same version at this point).

    Replicating SEPM environments are slightly different.  Can you provide more info on the estate you're upgrading?