Updating defs on clients and remote admin problems
Updated: 22 May 2010 | 14 comments
Good afternoon,
I seem to be having 2 problems. The server is getting the latest updates, but not distributing them to the clients. If I manually invoke an update process, the definitions are downloaded and installed on the clients. There are no errors with liveupdate on the server, and looking at the liveupdate logs, it logs in every 4 hours as it's set to do. The clients are set to download from the management server (default), should I select the liveupdate server instead and schedule the clients to check every x hours? What is the update schedule when set to get updates from the management server. The time setting is greyed out.
Secondly, when I try and remotely administer the server from another PC, I get as far as the Endpoint Protection manager login page, but it never accepts my login information. I get a failed to connect to the server. I am using default ports (8443) and I've tried with Network threat protection off on both client and server with the same results. I am able to install the java application from http://svr-septest:9090, so I'm not sure what I'm missing.
Thank you,
Ned Cipollini
discussion Filed Under:
Comments
November 8, 2007 6:24:55 AM EST: LUALL.EXE finished running. [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:55 AM EST: LiveUpdate will start next at Thursday, November 8, 2007 10:24:55 AM EST on svr-septest [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:55 AM EST: LUALL.EXE successfully updated the content. Return code = 0; [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:47 AM EST: Symantec Network Access Control Win64 11.0 (English) is up-to-date. [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:46 AM EST: Symantec Network Access Control Win32 11.0 (English) is up-to-date. [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:45 AM EST: Symantec Endpoint Protection Win64 11.0 (English) is up-to-date. [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:45 AM EST: Symantec Endpoint Protection Win32 11.0 (English) is up-to-date. [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:45 AM EST: Proactive Threat Scan engine Win32 11.0 is up-to-date. [Site: Legere SEP Test] [Server: svr-septest]
November 8, 2007 6:24:44 AM EST: Proactive Threat Scan commercial application list Win32 11.0 is up-to-date. [Site: Legere SEP Test] [Server: svr-septest]
Ned -
What are the current defs on your server? (Nov 7th, r18?)
The symnatec guys can correct me if I'm wrong...
I'm guessing that they probably are 11/7 r18 and here's the reason why you're not seeing them update to Nov 8.
Rapid Release definitions are the most currenty available defs...they are streamlined through the 'system' to allow for immediate mitigation of 'new' threats...however, their QA process isn't quite as 'rigorous' as the process that 'normal' LU defs go through.
Its not recommended, or appropriate in my opinion, to use Rapid Release on a consistent basis. Generally speaking the defs are of good quality, however, I'm sure others will tell you stories of how RR defs had issues that caused them problems.
If I recall correctly, there are generally only 1 or 2 updates to LU defs per day...so you really don't need to configure your server to check every four hours. Best practice is just to have defs update once per day. I generally will schedule the LU updates to occur sometime between midnight and 3 AM so there's some time for the defs to deploy to systems that are powered on prior to the morning rush.
Hope some of this is helpfull....
Message Edited by AMoss on 11-08-2007 09:27 AM
I'm not sure if I understand the question completely...but let me give it a shot and maybe I'll get it somewhere :)
It's important to remember that the SEP client installed on the SEPM server OS is a client to the SEPM server...with that in mind....
On the console, you can see the latest defs downloaded via LU by selecting 'Admin', then 'Servers', then 'Local Site', then 'Show Live Update Downloads'.
While still on the 'Admin', 'Servers' page, select a specific server and you'll see when it last updated, but it doesn't tell you with what version here....just when it checked in and processed defs/content/etc
The first time I was trying to find which client was the one slice in that defintion pie chart that wasn't updating...I got a little frustrated. Then I remembered '...go to the logs...' If you've never used SAV reporter, you won't exactly know what I'm talking about...but you'll soon become familiar. The home page and reports are GREAT for high level information, but they're not going to give you the detail you need when you run into an issue. Remember, reports are for trending and exposing a potential issue...the logs are where you actually trace them down.
To find defs on individual clients (including server clients)...
In the SEPM console, select 'Monitors', then the 'Logs' tab. Under 'Log Type', select 'Computer Status'. If you select 'Advanced', you'll see many options for narrowing your search (so..you could search for clients whos defs were older than 30 day, as opposed to seeing all clients and having to sort through them). Then click on 'View Log' Now you'll see all your machines and their individual def dates.
We can go deeper into the system logs...but I'm hoping this answers your question...
Message Edited by AMoss on 11-08-2007 12:16 PM
Gotcha, now I think we're on the same page....let's hope your server updates tonight!
you can quickly find which 'regular' defs are the most recent and available from Symantec by clicking on the 'Definitions' Link next to the ThreatCon logo/bar in the Security Response section...if your not trusting the information under the Virus Defs section (mine was just out of synch, but now I see it's updated)
Would you like to reply?
Login or Register to post your comment.