Right now, I am trying to troubleshoot one of our GUPs (SEP 11) that Netflow Analyzer has shown to transmit "Unknown Application"
While I was in the process of configuring Wireshark on GUP, on the lower right hand side a pop-up from SEP shield says "Location has been changed to GUP_OFF_LOCATION", and the green dot disappeared ---- I had previously configured locations based on whether GUP can connect to SEPM or not.
So when I opened the Client Management Logs, here is the record:
6166 1/14/2014 4:26:43 AM Information 12070900 Start serving as the Group Update Provider (proxy server).
6167 1/14/2014 4:26:43 AM Information 1207020E Location has been changed to GUP_ON_LOCATION.
6168 1/14/2014 4:28:09 AM Information 12071007 New virus definition file loaded. Version: 160113v.
6169 1/14/2014 6:12:52 AM Information 120B0007 Failed to connect to all GUPs, now trying to connect SEPM
6170 1/14/2014 12:33:33 PM Information 12070304 Disconnected from Symantec Endpoint Protection Manager
6171 1/14/2014 12:33:35 PM Information 12070301 Connected to Symantec Endpoint Protection Manager
6172 1/14/2014 1:33:37 PM Information 12070304 Disconnected from Symantec Endpoint Protection Manager
6173 1/14/2014 1:33:40 PM Information 12070900 Stop serving as the Group Update Provider (proxy server).
6174 1/14/2014 1:33:40 PM Information 1207020E Location has been changed to GUP_OFF_LOCATION.
6175 1/14/2014 1:37:05 PM Information 12070301 Connected to Symantec Endpoint Protection Manager
6176 1/14/2014 1:37:09 PM Information 12070900 Start serving as the Group Update Provider (proxy server).
6177 1/14/2014 1:37:09 PM Information 1207020E Location has been changed to GUP_ON_LOCATION.
6178 1/14/2014 1:37:10 PM Information 12070301 Connected to Symantec Endpoint Protection Manager
6179 1/14/2014 1:37:10 PM Information 12071007 New virus definition file loaded. Version: 160114b.
6180 1/14/2014 6:38:10 PM Information 120B0007 Failed to connect to all GUPs, now trying to connect SEPM
6181 1/14/2014 9:37:36 PM Information 12070304 Disconnected from Symantec Endpoint Protection Manager
6182 1/14/2014 9:37:40 PM Information 12070900 Stop serving as the Group Update Provider (proxy server).
6183 1/14/2014 9:37:40 PM Information 1207020E Location has been changed to GUP_OFF_LOCATION.
6184 1/15/2014 12:46:52 AM Information 12070301 Connected to Symantec Endpoint Protection Manager
6185 1/15/2014 12:46:52 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager
6186 1/15/2014 12:46:57 AM Information 12070301 Connected to Symantec Endpoint Protection Manager
6187 1/15/2014 12:46:59 AM Information 12070900 Start serving as the Group Update Provider (proxy server).
6188 1/15/2014 12:46:59 AM Information 1207020E Location has been changed to GUP_ON_LOCATION.
6189 1/15/2014 12:47:02 AM Information 12071007 New virus definition file loaded. Version: 160114i.
6190 1/15/2014 12:47:11 AM Information 12070301 Connected to Symantec Endpoint Protection Manager
6191 1/15/2014 8:47:43 AM Information 12070304 Disconnected from Symantec Endpoint Protection Manager
6192 1/15/2014 8:48:58 AM Information 12070900 Stop serving as the Group Update Provider (proxy server).
6193 1/15/2014 8:48:58 AM Information 1207020E Location has been changed to GUP_OFF_LOCATION.
Is there any explanation to this erratic behavior?