Endpoint Protection

 View Only
  • 1.  WIndows 2008 DC stopped functioning properly after installing SEP v11.0.6005.562

    Posted Nov 22, 2011 07:33 PM

    Hi People,

    Does anyone ever got into this problem of Windows AD stopped functioning properly with the SEP client v11.0.6005.562 installed ?

    from the PortQuery software, I got so many port closed when I tries to communicate to the Other DC as follows:

     

    Winsock error 10055
    portqry.exe -n Prod-DC-01 -e 135 -p TCP exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 389 -p BOTH exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 636 -p TCP exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 3268 -p TCP exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 3269 -p TCP exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 53 -p BOTH exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 88 -p BOTH exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 445 -p TCP exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 139 -p TCP exits with return code 0x00000063.
    portqry.exe -n Prod-DC-01 -e 42 -p TCP exits with return code 0x00000063.
     
    portqry.exe -n Prod-DC-01 -e 137 -p UDP exits with return code 0x00000000.
    portqry.exe -n Prod-DC-01 -e 138 -p UDP exits with return code 0x00000002.
     
    Any kind of assistance would be greatly appreciated.

    Thanks.



  • 2.  RE: WIndows 2008 DC stopped functioning properly after installing SEP v11.0.6005.562

    Posted Nov 22, 2011 07:34 PM

    So at the moment, my onlywork around for this recurring problem is to restart the domain controller when it happens on either ProdDC1 or ProdDC2.



  • 3.  RE: WIndows 2008 DC stopped functioning properly after installing SEP v11.0.6005.562

    Posted Nov 22, 2011 08:10 PM

    Do you have the Network Threat Protection component installed (firewall and IPS)?

    You can check the logs to what they show and add exceptions as needed.

    Or you can remove the NTP component altogether.