Endpoint Protection

 View Only
  • 1.  Yet another GUP issue

    Posted Apr 29, 2010 09:59 PM

    After looking at all the other GUP issues i now have the same problem.

    After reading and trying all the troubleshooting steps i have clients that will not download upgates from their local GUP.
    The GUP is a GUP and i can telnet to it from a client machine on port 2967 and with debug on at the GUP can see the connection.

    What i don't see and cant locate is any log on the client that shows the list of GUPs that it has. Documentation says they will get it from a file called globallist.xml from the management server. Looking at the management server i can see the file and it has all the GUP entries in it but it is NOT on the client anywhere. The registry on the client also shows a blank "MasterClientHost" key.

    Can anyone suggest what else to try? I have used sylink monitor but it doesn;t seem to be the issue - the issue is that the clients are not getting the list of GUPs so how can i debug that part of the problem.


  • 2.  RE: Yet another GUP issue

    Posted Apr 29, 2010 10:08 PM

    BTW all clients and SEPM servers are on RU5 and we aren't going to RU6x for a good 3-4 months until all the bugs are ironed out.


  • 3.  RE: Yet another GUP issue

    Posted Apr 29, 2010 10:21 PM
    I think the MasterClientHost should be populated with the GUP assigned to that group via your LU policy.
    Well it is on mine at least but this is just a test group with a single GUP and a backup (but they are set to the same host in my test group)
    I might need to find some other clients to confirm but don't have access right now.

    Are you positive your client has the right policy from the SEPM that speficies the GUP??



  • 4.  RE: Yet another GUP issue

    Posted Apr 29, 2010 10:26 PM
    All workstations are in a single group. All GUPS are entered into the GUP list for this group including the GUP servers that are in a different SEP group.

    The Structure is like this

    Domain
    |----------------- GUP Server Group with policy making them a GUP
    |
    |-----------------All workstations with GUP Server list and policy making some of them a GUP


    The globallist.xml file on the SEPM has the complete list of all Server and Workstation IP's that are GUP's

    Checking the client logs the policy which has the GUP list is being applied to the client workstation i am troubleshooting.

    What i really want is a way to debug the comms between the workstation and the SEPM where the GUP list is downloaded to the client.


  • 5.  RE: Yet another GUP issue



  • 6.  RE: Yet another GUP issue

    Posted Apr 30, 2010 09:38 AM
    If you want to check from a particular client, follow this.  If you want to check all clients from a GUP follow Aravind's psot above

    Following the first link will walk you through how to enable a log file that documents all your traffic.  You can then verify the IP or machine that the content is coming from.

    How to enable Sylink Debugging for Symantec Endpoint Protection in the registry
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008041812561948

    How to debug the Symantec Endpoint Protection 11.x client
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007090611252048