Hi,
I have a number of W2K3 Servers that do not update their Virus Definitions. All of the Servers connect to our SEPM Servers and we use load balanced GUPs. This mechanism works for a vast majority of our servers (we have over 2500).
Version 11.0.6100.645
I have tried using my admin account to fire up SMC. removing the HTTP info in the .default users section in the registry, trashing the defs manually and using the rx4 defs util.Note that I can telnet to both sepm and gup servers using the relevant port.
Any ideas greatfully received.
The sylink monitor log looks like this:
01/07 09:20:23 [9920] <mfn_MakeGetGupListUrl:>Request is: action=320&hostid=B8A059340A8C501B00E0D16BF3E334C6&chk=DC4B7206B67CCA04EE6E595D15AB7EFA&ck=8CEE7DB3A7FD60124D6FBD246FBB70CA&uchk=6FAE4A54A6FCB6A6307FDACB798DD8EB&uck=8E56693671198EFBAB0F1C2260894D6B&groupid=5311980B0A4293150137742DB117F797&as=10997&cn=[hex]5733334E534D4531&lun=[hex]676F72646F6E2E6A616D65732E61646D&udn=[hex]4D454443
01/07 09:20:23 [9920] <GetGupList:>http://10.140.124.10:8014/secars/secars.dll?h=1794036B74F2CF3C21DE3191B4EE8423345B66E19C4391C029569966ABF44435F71264C42BB880221A877FFF3261F564C8FB5D6D7D5CF9130D705C437D837D78C30BE398EBAF712E8313AE70F5BE8E470F88F4CC85D346642729EC7E0E6E9F2CB67FF60092BE343B64F84C8BB074817846403503B3E693DC08CD25B97A9970BA68724255363CA97E14DE29C36D2A97C37CD17DF89711542A09B2F814661DE47BC293299925DD90FF2C9EB2512C8DB0964874571A3D9059B7D12B045FB6061FBCEAC018B91E1E57714411C91AF5D5B2D36632C4D2459893BD76EEA73A4323011B7040C03D4043570E8EB408D7FB33B3EDC5A4C3D5F985B432ED489A715303D7A93424E327B6D716680F6EBFC49C4611BAE83971FBE7BC8615EDC5A70C8AA99EB0B9B6865CD5D12083363AC68E2B41A747A3F54FB5B33EF0CE4C6D6FA3733E067D74D1ABDC5F07EA36EE14AC4BDBB8CD2051466CC82722B228AEABE5B39EFEFA0B
01/07 09:20:23 [9920] <GetGupList:>SMS return=200
01/07 09:20:23 [9920] <ParseHTTPStatusCode:>200=>200 OK
01/07 09:20:23 [9920] <mfn_DoGetGupList200>Content Lenght => 3236
01/07 09:20:23 [9920] <mfn_DoGetGupList200>Got Gup List from server, read bytes=3236
01/07 09:20:23 [9920] <mfn_DoGetGupList200>completed
01/07 09:20:23 [9920] <GetGupList:>RECEIVE STAGE COMPLETED
01/07 09:20:23 [9920] <GetGupList:>COMPLETED
01/07 09:20:23 [9920] SyLinkDeleteConfig => Deleting instance: 0189DAC8
01/07 09:20:23 [9920] <SetupTempLUFilePath:>NEW download: C:\Program Files\Symantec\Symantec Endpoint Protection\LiveUpdate\LUF{ECCC5006-EF61-4c99-829A-417B6C6AD963}20121114001.TMP
01/07 09:20:23 [9920] <CHttpFileDownload::CHttpFileDownload()>
01/07 09:20:23 [9920] </CHttpFileDownload::CHttpFileDownload()>
01/07 09:20:23 [9920] <CHttpFileDownload::Do()>
01/07 09:20:23 [9920] <CHttpFileDownload::getRemainingBytesToDownload()>
01/07 09:20:23 [9920] Remaining bytes to download: 886158
01/07 09:20:23 [9920] </CHttpFileDownload::getRemainingBytesToDownload()>
01/07 09:20:23 [9920] <CHttpConnector::SendRequest()>
01/07 09:20:23 [9920] Request> http://10.66.214.40:2967/content/{ECCC5006-EF61-4c99-829A-417B6C6AD963}/2012111400/Full.zip
01/07 09:20:35 [9912] <CSyLink::mfn_DownloadNow()>
01/07 09:20:35 [9912] </CSyLink::mfn_DownloadNow()>
01/07 09:20:44 [9920] SendRequest() failed.
01/07 09:20:44 [9920] </CHttpConnector::SendRequest()>
01/07 09:20:44 [9920] </CHttpFileDownload::Do()>
01/07 09:20:44 [9920] <LUDownloader::GetContentToFile> completed.
01/07 09:20:44 [9920] <CHttpFileDownload::~CHttpFileDownload()>
01/07 09:20:44 [9920] </CHttpFileDownload::~CHttpFileDownload()>
01/07 09:20:44 [9920] <LUThreadProc>LU file download failed due to HTTP error:0
01/07 09:20:44 [9920] <CExpBackoff::Increment()>
The debug log looks like this
01/07 09:20:22 [9496:9920] AH: Setting the Browser Session end option & Resetting the URL session ..
01/07 09:20:23 [9496:9920] <ParseHTTPStatusCode:>200=>200 OK
01/07 09:20:23 [9496:9920] AH: Setting the Browser Session end option & Resetting the URL session ..
01/07 09:20:23 [9496:9920] <ParseHTTPStatusCode:>200=>200 OK
01/07 09:20:23 [9496:9920] AH: Setting the Browser Session end option & Resetting the URL session ..
01/07 09:21:20 [9496:9928] Saving SMC State
01/07 09:21:20 [9496:9928] chmod on file C:\Program Files\Symantec\Symantec Endpoint Protection\SerState.dat to read/write.
01/07 09:21:20 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\StdDef.dat: Not found.
01/07 09:21:20 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\trojan.dat: Not found.
01/07 09:21:20 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\metadata.dat: Not found.
01/07 09:21:20 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\metadata.dat.bak: Not found.
01/07 09:21:20 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\sigs.dat: Not found.
01/07 09:21:20 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\sigs.dat.bak: Not found.
01/07 09:21:20 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\wpshelper.sys.bak: Not found.
01/07 09:22:49 [9496:9704] DnsHelper: update DNS ServerList
01/07 09:24:42 [9496:9972] **** screensaver : 1
01/07 09:24:46 [9496:9972] **** screensaver : 0
01/07 09:25:36 [9496:9928] Saving SMC State
01/07 09:25:36 [9496:9928] chmod on file C:\Program Files\Symantec\Symantec Endpoint Protection\SerState.dat to read/write.
01/07 09:25:36 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\StdDef.dat: Not found.
01/07 09:25:36 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\trojan.dat: Not found.
01/07 09:25:36 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\metadata.dat: Not found.
01/07 09:25:36 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\metadata.dat.bak: Not found.
01/07 09:25:36 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\sigs.dat: Not found.
01/07 09:25:36 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\sigs.dat.bak: Not found.
01/07 09:25:36 [9496:9928] C:\Program Files\Symantec\Symantec Endpoint Protection\wpshelper.sys.bak: Not found.
01/07 09:26:36 [9496:9920] AH: Setting the Browser Session end option & Resetting the URL session ..
01/07 09:26:36 [9496:9920] <ParseHTTPStatusCode:>200=>200 OK
01/07 09:26:36 [9496:9920] AH: Setting the Browser Session end option & Resetting the URL session ..
01/07 09:26:36 [9496:9920] <ParseHTTPStatusCode:>200=>200 OK
01/07 09:26:36 [9496:9920] AH: Setting the Browser Session end option & Resetting the URL session ..
01/07 09:28:16 [9496:9972] SMCGui - 9944: SymCorpUI is not trusted