Endpoint Protection

 View Only
Expand all | Collapse all

duplicate clients name in SEPM

Srikanth_Subra

Srikanth_SubraJan 25, 2012 06:25 AM

Migration User

Migration UserJan 25, 2012 01:34 PM

  • 1.  duplicate clients name in SEPM

    Posted Jan 23, 2012 11:10 AM

    Hi, I noticed that whenever I uninstalled and reinstalled SEP 12 client on the machine, SEPM will not remove/update the previous installation's Unique ID/Hardware key on the console, instead it created a new Unique/Hardware key for the same client. This leads to the problem of having 2 clients (or more if I do more uninstall/reinstall ) with same name but different unique ID/Hardware key on the same machine. I knew SEPM, by default, will remove inactive client for a specified period of time, but is there anyway I can get rid of the old installation from SEPM right after I uninstall it.

    Thanks



  • 2.  RE: duplicate clients name in SEPM

    Trusted Advisor
    Posted Jan 23, 2012 11:14 AM

    Hello,

    Are these Clients Cloned?

    Check these Article:

    How to repair duplicate IDs on cloned Symantec Endpoint Protection 12.1 clients

    http://www.symantec.com/docs/TECH163349

    How to prepare a Symantec Endpoint Protection 12.1 client for cloning

     
    Also, check this Thread:
     
    Upgrading to SEP 12.1 creates duplicate enteries.
     
    Hope that helps!!


  • 3.  RE: duplicate clients name in SEPM

    Broadcom Employee
    Posted Jan 23, 2012 11:26 AM

    Clean up the client view in Symantec Endpoint Protection Manager

    Resetting the client IDs will result in invalid offline clients being left in the client view in Symantec Endpoint Protection Manager. This could affect licensing and reporting. There are two options for removing the clients:
    Let the clients time out according to the Symantec Endpoint Protection Manager site's aging criteria. This is 30 days by default.
     
    Manually delete the offline clients from the client view page.
     
    Run the SEPMRepairTool.zip on SEPM machine.
     
    How to repair duplicate IDs on cloned Symantec Endpoint Protection 12.1 clients
     
    http://www.symantec.com/docs/TECH163349


  • 4.  RE: duplicate clients name in SEPM

    Posted Jan 23, 2012 11:48 AM

    ...there is no automatic way to remove the duplicate client entires in the DB other than letting them be purged after the (default) 30 days without contact.

    The closest process I've found to a solution is only really applicable in SEP11 implementations using AD synch'd groups, and even then this is a manually run command.  Just in case you want to read about it, I've lnked it below:

    http://www.symantec.com/docs/TECH97371

    Another option is it try to maintain the same Hardware ID after a reinstall (kinda link Mithun's article in reverse).  I.E. Take a backup of the client's hwid, do the uninstall/reinstall, then put them back.  This has the added benefit of ensuring the entry on the SEPM keeps all the historical records for the client too (should you need it)



  • 5.  RE: duplicate clients name in SEPM

    Posted Jan 23, 2012 01:59 PM

    What I found is that the duplicate client issue only occurs on virtual machines, physcial machine doesn't seem to have the same problem. As for the virtual machines goes, neither the Symantec installation nor the operation system were cloned. They were all built from scratch, so there will not be any SID duplication. Is there any fix for vm environment. We use Hyper-V for VM platform.

    Thanks

     



  • 6.  RE: duplicate clients name in SEPM

    Posted Jan 23, 2012 11:54 PM

    Iam also faced the same issue at starting..but now it resolved.



  • 7.  RE: duplicate clients name in SEPM

    Posted Jan 24, 2012 01:28 AM

     

    Cause


    Duplicate Endpoint Protection client IDs occur if the base image was not prepared for cloning. For more information, read the article How to prepare a Symantec Endpoint Protection 12.1 client for cloning.


    Solution


    There are three high-level steps to repair duplicate Symantec Endpoint Protection client IDs.

    1. Identify the clients
    2. Repair the clients
    3. Clean up the client view in Symantec Endpoint Protection Manager
       

    Step 1: Identify the clients

    If you already know the IP addresses or names of the systems affected by this issue you can skip to the next section. If you have multiple managers, disable any replication relationships between them and perform the steps below on each manager. You should do this process on all servers before re-enabling replication.

    1. Stop the Symantec Endpoint Protection Manager service and the Symantec Endpoint Protection Manager Webserver service. When these services are stopped, delete the client connection log file: <Symantec Endpoint Protection Manager install folder>\data\inbox\log\ersecreg.log.  Restart the services after the log file has been deleted.
    2. Wait 1 heartbeat period so clients can reconnect to the manager.  If your communication settings have a 30 minute heartbeat then wait for at least 30 minutes. In the Symantec Endpoint Protection Manager, the heartbeat settings are under Clients >Policies Communication settings.
    3. Run the SEPM Repair Tool, using the instructions provided in ReadMe.txt.  The output file from the SEPM Repair Tool is the list of clients affected by the duplicate ID issue.  Save this file.
       

    Step 2: Repair the clients

    In the first steps below, you disable SMC password protection for the affected clients.  If you do not have SMC password protection enabled, skip to step 4 of this section. 

    1. Using the output list from the SEPM Repair Tool, find the affected clients in Symantec Endpoint Protection Manager and move them to a new temporary group.
    2. In Clients Policies General Settings Security Settings, disable SMC password protection.
    3. Wait for one heartbeat interval to make sure the policy is updated for each client.
    4. Copy RepairClonedImage.exe to the computer that runs Symantec Endpoint Protection Manager.
    5. Rename RepairClonedImage.exe to Setup.exe.
    6. In the Client Deployment Wizard, deploy the renamed tool to the affected computers, using the output file from the SEPM Repair Tool as the list of clients.

      If you do not wish to use the Client Deployment Wizard, you may use any software deployment method of your choice, or you can run the tool manually on the target computers.  If you do not use the Client Deployment Wizard, administrator rights will be required when running the tool

      By default, the RepairClonedImage tool will run silently, with no response to the user for success or failure. You may specify the -v commmand line option to show notification on success or failure.
    7. After the tool has been deployed, the clients should show up as online in the manager console.

      If you moved the clients to a temporary group, you may now move all of the online clients from the temporary group back to their original group.
       

    Step 3: Clean up the client view in Symantec Endpoint Protection Manager

    Resetting the client IDs will result in invalid offline clients being left in the client view in Symantec Endpoint Protection Manager. This could affect licensing and reporting. There are two options for removing the clients:

    1. Let the clients time out according to the Symantec Endpoint Protection Manager site's aging criteria. This is 30 days by default.
    2. Manually delete the offline clients from the client view page.

     



  • 8.  RE: duplicate clients name in SEPM

    Trusted Advisor
    Posted Jan 24, 2012 01:43 AM

    Hello,

    Check this Article:

    Upgrading a Symantec Endpoint Protection 11 client to 12.1 or repairing a SEP 12.1 client results in duplicate client entries created in the SEPM console if the client is on a Guest OS of Hyper-V.
     
     
    This is a Known Issue and resolved in Symantec Endpoint Protection 12.1 RU1 MP1
     
    As of now, you can try deleting the clients from the Groups and the clients may re-register themselves.
     
    Hope that helps!!


  • 9.  RE: duplicate clients name in SEPM

    Posted Jan 24, 2012 08:49 AM

    Are these Citrix clients?

    Try this.

    http://www.symantec.com/business/support/index?page=content&id=TECH96808



  • 10.  RE: duplicate clients name in SEPM

    Posted Jan 24, 2012 05:18 PM

    This is actually my testing env. for SEP 12. I am using Hyper VM for testing purpose. So they are not citrix clients. And as I mentioned again, these Windows installations were setup from scratch and no imaging software and SEP client upgrade were involved.



  • 11.  RE: duplicate clients name in SEPM

    Trusted Advisor
    Posted Jan 25, 2012 03:52 AM

     

    Hello,

    Check this Article:

    Upgrading a Symantec Endpoint Protection 11 client to 12.1 or repairing a SEP 12.1 client results in duplicate client entries created in the SEPM console if the client is on a Guest OS of Hyper-V.
     
     
    This is a Known Issue and resolved in Symantec Endpoint Protection 12.1 RU1 MP1
     
    As of now, you can try deleting the clients from the Groups and the clients may re-register themselves.
     
    Hope that helps!!


  • 12.  RE: duplicate clients name in SEPM

    Posted Jan 25, 2012 04:41 AM

    Whether 12.1 RU1 is the new version or 12.1 RU1 MP1 is new one? what is that MP1 means?



  • 13.  RE: duplicate clients name in SEPM
    Best Answer

    Trusted Advisor
    Posted Jan 25, 2012 05:23 AM

    Hello,

    As of now, the Latest Version of Symantec Endpoint Protection (SEP) version 12.1, is SEP 12.1 RU1

    SEP 12.1 RU1 MP1 is the upcoming Latest version which is not yet released.

    Check this Article:

    What are the Symantec Endpoint Protection (SEP) versions released officially?

    https://www-secure.symantec.com/connect/articles/what-are-symantec-endpoint-protection-sep-versions-released-officialy

     

    RTM - Release To Manufacturing

    MR - Maintenance Release (replaced by RU)

    RU - Release Update

    MP - Maintenance Patch

    PP - Point Patch

    Hope that helps!!



  • 14.  RE: duplicate clients name in SEPM

    Posted Jan 25, 2012 06:25 AM

    Thanks for the updates!!! Mithun..



  • 15.  RE: duplicate clients name in SEPM

    Posted Jan 25, 2012 01:34 PM

    Thanks for the info.