In SEPM, I have configured my LU policies to not use a Live Update server and to only use the default management server or a GUP. I'm looking at my firewall logs and seeing lots of clients still trying to hit http://liveupdate.symantecliveupdate.com.
The client PCs are showing the resource they're trying to hit as http://liveupdate.symantecliveupdate.com/minitri.flg but the SEPM servers are showing http://liveupdate.symantecliveupdate.com/liveupdate_3.3.100.15_english_livetri.zip. So, it looks like the clients are not actually trying to pull updates from it but are still trying to contact Live Update in some regard. I also see the clients getting updates from the SEPM server or a GUP in the sylink log.
Is it normal for this to happen, and what might this traffic be? Thanks for any help on this.