Symantec Endpoint Encryption FD 7.0.3 on an ISA Server 2006 Web Caching server

manutitus's picture

Dear all,

Recently I implmeneted a SEE FD 7.0.3 on an ISA Server 2006 Server which is acting as a ISA Server Web Cache.

After creating the FRamework,Fulldisk and Removable storage clients, all these packages are deployed to the test PC using  Group Policy

I can see the SEE USer Client GUI

I can see under Registered Users - the current user

Account seetings - I can see

Password -  windows login password
Authenticheck -   the wuestions that are asked
Onetime Password - the help  desk names (first name ,last name)

Under Full Disk

Encryption - ITs shows disk is encrypted
Decryption - No access
Check- In -

Here is the Problem - When I click  Check-In

It shows

Last communication with the SEE Server - never connected
Next communication due by - Not applicable

If  I check In now -  It will say

TRYING TO COMMUNICATE WITH THE SEE SERVER without any success message.

Can anyone shed light on this ?

IS ISA blocking  something ?  Or is it normal since it says  no applicable ?

What are the ports that check in using to communicate   with the IIS server ?

Regards
Manu

nlal@guardianedge.com's picture

 Hey Manu, There are several

 Hey Manu,

There are several possible reasons that access to a server might be denied. Some are easy to fix, but others might require a little more investigation on your part. Here are some steps you can try to remediate this query. 

1)       First check to be sure whether machine is able to resolve the DNS. Ping your server via FQDN and see if you are getting replies.

2)       Check to be sure if the user is having the correct proxy setting under “Lan Setting”

3)       Modify 'Symantec Services' website to allow Anonymous Authentication.

4)       Check the tech logs and see if there is any error message showing up.

5)       Have you performed an upgrade from one version to another?

6)       How many Endpoints are affected?

7)       Check the Adsync service status on the server. Check to be sure if service is started or stopped.

Regarding your second question, we are using the standard http and https protocol to communicate with IIS. Whatever the ports your admin has configured during the server setup, client machine only uses that port for communication.

Regards
Nitin

Long's picture

Hi Nitin, I have the same

Hi Nitin,

I have the same issue with my client PC not "Checking In".

I've check and done everything you mentioned above, but still won't check in.  We did do an upgrade from SEE 7.0.2 to ver SEE 7.0.3.

I look in the IIS log, it sees that the client tries to access the IIS server.

2009-11-18 22:54:39 W3SVC1118681577 163.233.5.59 POST /GECommunicationWS.asmx - 8080 - 163.233.6.51 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3603) 401 2 2148074254
2009-11-18 22:54:39 W3SVC1118681577 163.233.5.59 POST /GECommunicationWS.asmx - 8080 COMCARE\SEE-IIS 163.233.6.51 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3603) 200 0 0

(above lines show first with anonymous access, second is via authenication)

We only have one client PC at the moment, as we're only testing/trialing it before pushing it out to all PCs.

Is there any setting or Policy needed to be created before the client can check in?

On the server, in the SEE Manager, under SEE Managed Computers I don't see any PCs, and under SEE Unassigned, nothing there too.

Any advice will be welcomed.

Thanks.

Regards,
Long