Endpoint Protection

 View Only
Expand all | Collapse all

Symantec Endpoint Manager 11.1 (not internet access) not manually updating

Migration User

Migration UserAug 15, 2013 11:25 AM

ℬrίαη

ℬrίαηAug 15, 2013 11:30 AM

Migration User

Migration UserAug 15, 2013 11:42 AM

  • 1.  Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:08 AM

    Hello,

    Windowns server 2003 is running SEPM ver 11. It has no internet acces and will never have it. Everything has to be done manually. I download the .jdb and follow the instructions to manually update:

    Copy the .JDB file to the "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\data\inbox\content\incoming"

    Wait 10 minutes - 5 days (lol)

    1. To verify that the SEPM content has been updated, look in the following folders:
      32-bit definitions: "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\Inetpub\content\{C60DC234-65F9-4674-94AE-62158EFCA433}"
      64-bit definitions: "C:\Program Files\Symantec\Symantec Endpoint Protection Manager\Inetpub\content\{1CD85198-26C6-4bac-8C72-5D34B025DE35}"

    Nothing. Only the older version virus definition update folders

    This is what I have tried for solution:

    http://www.symantec.com/business/support/index?page=content&id=TECH102609&locale=en_US

    Which everyone says to uninstall LiveUpdate and then reinstall and register.

    Another solution was to update the version of SEPM, but the server doesn't have access to the internet. I need a solution as to why I cannot manually update. This should be very straight forward and it is not working. This is a major problem and will cause many individuals within my company to blow there lid due to security requirements of updating staying current on virus definitions.

     V/R

    Need Help

     



  • 2.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:12 AM

    Are you able to post the logs mentioned here:

    LiveUpdate and content troubleshooting for the Symantec Endpoint Protection Manager

    Article:TECH105924  |  Created: 2008-01-16  |  Updated: 2012-03-29  |  Article URL http://www.symantec.com/docs/TECH105924

     



  • 3.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:25 AM

    error.JPG



  • 4.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Trusted Advisor
    Posted Aug 15, 2013 11:27 AM

    Hello,

    Check these Articles:

    Symantec Endpoint Protection Manager 11.x is not updating 32 or 64 bit virus definitions.

    http://www.symantec.com/docs/TECH104721

    How to update definitions for Symantec Endpoint Protection Manager (SEPM) using a .jdb file

    http://www.symantec.com/docs/TECH102607

    How to update content on a Symantec Endpoint Protection Manager that does not have Internet access

    http://www.symantec.com/docs/TECH104893

    Hope that helps!!



  • 5.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:30 AM

    Do you have enough free space on C:?



  • 6.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:42 AM

    The HDD has 11 GB of free space......



  • 7.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:57 AM

    I appreciate the feedback, but the 2 LUA work arounds will not be feasible. I would have to setup another PC as a "LUA server" that the SEPM can connect to for updates. This is not in the approved required configuration for our 'statement of work'. I have strict guidelines and it was agreed upon to have 1 server (no internet acess) that is manually updated with .jdb and pushes out all the VirusDef to the nodes.

    I must adhere to this approved architecture....... Any additions/modifications will require additional approval and the overhead is too much. 



  • 8.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:57 AM

    I see that its Giving error code 4.

    did you try downloading a fresh copy of JDB?

    Before doing that clear out all the defs and drop a new jdb

    Symantec Endpoint Protection Manager 11.x is not updating 32 or 64 bit virus definitions.

     

     



  • 9.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 11:59 AM

    When you say "clear out all the defs" does this mean delete both 32 & 64 bit folders? or just the contents within the folders?



  • 10.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 12:37 PM

    Can you check that document . I'm not sure where 32 /64 folder is mentioned. in any case Just contents inside the folders

     



  • 11.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating
    Best Answer

    Broadcom Employee
    Posted Aug 15, 2013 01:10 PM

    Hi,

    Check this article to clear the corrupt definitions manually

    Article: How to clear corrupt Virus Definitions from SEPM

    https://www-secure.symantec.com/connect/articles/how-clear-corrupt-virus-definitions-sepm



  • 12.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 01:16 PM

    http://www.symantec.com/business/support/index?page=content&id=TECH102607

    Oh, I just assumed by the 'how to' file that it describes 2 folders being created for 32 bit & 64 bit that you wanted me to delete/clear contents inside both folders. I probably misspoke.



  • 13.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 01:30 PM

    Inside content folder there will be lot of alphanumneric folders

    delete whatever inside Alpahanumeric folder ( Not the Alphnumeric folder)

    when you download JDB from Symantec website . The JDBs are for 32 / 64 bit. Make sure you have selected the appropriate one.



  • 14.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 02:57 PM

    Give an update:

    I finished clearing all the corrupt Virus Definitions from SEPM. https://www-secure.symantec.com/connect/articles/how-clear-corrupt-virus-definitions-sepm

    1. Stopped SEPM service

    2. Delete all the files and registries

    3. Start SEPM service

    Note: after SEPM service... I waited a few minutes and checked the content folder:

     \Symantec Endpoint Protection Manager\Inetpub\content\{C60DC...}  & \{1CD85.....}

    Both of these subfolders had the old virus definitions populated in them again....

    Am I missing something? I stopped SEPM, deleted all the files and registry keys and when I started SEPM they repopulated them with folders of the old virus definitions.....????????

    -----------------------------------------------------------------------------------------------------------------------------------------

    Not knowing what to do next, I decided to upload the 'newly' downloaded 32 bit .jdb file into the 'incoming' file

    \Symantec\Symantec Endpoint Protection Manager\data\inbox\content\incoming

    2 things happened that haven't happened before....

    1. As it was processing the .jdb file it started to create a file in the directory \Symantec Endpoint Protection Manager\Inetpub\content\{C60DC...}  & \{1CD85.....} (Both folders by the way).... This is the first time its done this so I think it was a corrupt .jdb file. In the past it acted like it was processing it, clean up/delete the .jdb file from the 'incoming' folder, but no virus definition folder would be created in \Symantec Endpoint Protection Manager\Inetpub\content\{C60DC...}  or \{1CD85.....}
    2. Its been running for about 15 minutes.... hung

    Any thoughts?



  • 15.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Broadcom Employee
    Posted Aug 15, 2013 03:12 PM

    Hi,

    Still hung? Try to stop and start Symantec Endpoint Protection Manager service.

    Try to repair the Symantec Endpoint Protection Manager through add/remove programs.



  • 16.  RE: Symantec Endpoint Manager 11.1 (not internet access) not manually updating

    Posted Aug 15, 2013 03:14 PM

    I am happy to report the problem is solved. Well, to say that SEPM finally updated.

     

    Thank you for all of your help and support.

    I still had a few open questions, but the problem is solved. Thank you.

    1. After all the old definitions were deleted, why did they repopulate after SEPM was restarted?

    2. Why does SEPM duplicate 32 bit defs in  \Symantec Endpoint Protection Manager\Inetpub\content\{C60DC...}  & \{1CD85.....}

     

    Thank you again for your support. Huge weight off my shoulders