Do you have the network thrat layer and SEP firewall enabled?
you can create a test policy and disbale these or as otehr poster said, go to windows update and note if anything appears in client logs or the SEP inof balloon in the system tray "SEP blocked //x//y//z"