Solved

Symantec LiveUpdate blocked by ISA2004

Posted on 2009-04-06
8
1,725 Views
Last Modified: 2013-11-22
I have an SBS2003 SP2 Premium install with ISA2004 that is running Symantec Endpoint Protection v11.0.4. My LiveUpdates have stopped working. When I monitor ISA2004 for denied connections, I see requests from Symantec servers denied with unidentified IP traffic.

I am not sure what has changed. This was working.

Anyone have any ideas?

0
Comment
Question by:dcadler
  • 3
  • 3
  • 2
8 Comments
 
LVL 14

Assisted Solution

by:Raj-GT
Raj-GT earned 200 total points
Comment Utility
I can't guess what might have changed, but this is what I would recommend.

1. Create a new domain name set with *.symantecliveupdate.com entry.
2. Create a new firewall policy and allow FTP, HTTP, HTTPS for All Users from internal to the new domain name set above.
3. Move this rule above your standard internet access rule.

This should allow LiveUpdate working again through ISA.

0
 

Author Comment

by:dcadler
Comment Utility
I set up the domain and rule with no luck. I have another server that is still using ISA2000. It is running the same version of Symantec and it updates just fine. I have the proxy parameters set the same, relative to the site specifics.

Dave
0
 
LVL 14

Expert Comment

by:Raj-GT
Comment Utility
Since ISA is saying unidentified IP traffic, can you change the rule to allow all outbound protocols and try again? I would also like to see the ISA logs for these attempts.
0
 
LVL 5

Assisted Solution

by:bRvO
bRvO earned 200 total points
Comment Utility
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 

Author Comment

by:dcadler
Comment Utility
Raj-GT, I opened up the rule to allow all outbound protocols and runing LiveUpdate from within SEPM still failed.

I beloieve now that the issue is not ISA2004 because...

From the SBS 2003 Server I was able to browse to http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=savce and download the most recent SEPM .jdb file

From the SBS 2003 Server, I was able to point my browser at ftp://ftp.symantec.com/public/english_us_canada/antivirus_definitions/symantec_antivirus_corp/jdb/ and also download the latest SEPM .jdb file.

I was able to do this with and without the specific Symantec firewall access rule enabled.

I am pointing the proxy to the LAN IP of the SBS2003 server and referencing ports 8080 for HTTP and 21 for FTP. This is similar to what I have configured for another client who is running SBS2003 with ISA2000.

To me, this seems to be an issue with Symantec. In SEPM rather than ISA.

Dave



0
 
LVL 5

Expert Comment

by:bRvO
Comment Utility
On your SEPM Server , check the liveupdate log file

C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Log.LiveUpdate

does it give any errors in here ?

Do you have SEP Firewall installed ? In version MR4 MP1 there are known issues with the Network Access Control component. That version was pulled from distribution just after release ( not acknowledged by Symantec to the general public though =p) ..

try MR4 MP1a from file.connect ( if you have a support agreement )
0
 
LVL 14

Expert Comment

by:Raj-GT
Comment Utility
When you launch the browser and access the update url, the browser will pass your credentials to ISA; this may not be the case with an autoupdate process. The rule should allow "All outbound protocols" to "All Users" and not "All Authenticated Users"; can you confirm this?
0
 

Accepted Solution

by:
dcadler earned 0 total points
Comment Utility
It turned out that I needed to reinstall LiveUpdate from the CD1 disk of SEP 11.0.4000 MR4. Once I did this, everything started working as expected. The process involved deleting all references to LiveUpdate in several folders before reinstalling. This problem was finally identified by a Symantec Engineer who remotely connected to the server and ran several tests. I believe that if LiveUpdate is in progress and you have a server crash or (in my case) the user power cycles the server, it can corrupt the process and require a complete re-installation of the LiveUpdate software.

I appreciate all of your feedback.

Dave
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

For those of you actively in the Malware fightling business, we now have available an amazing new tool in the malware wars (first recommended to me by rpggamergirl (http://www.experts-exchange.com/M_3598771.html), the Zone Advisor for the Virus and …
The articles for turning off the Client firewall policy on the internet are for SBS 2008 and don't really help for SBS 2011. They actually moved the Client firewall policy. In 2011, the client firewall policy has moved to the SBS computers conta…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now