Hi,
Thank you for posting in Symantec community.
Could you please confirm if the setttings are set to bypass GUP if it's not avaialble?
According to the logs I don't see client is trying to attempt connection on 2967 port.
Make sure client and SEPM are having correct policy serial number.
Verify the Liveupdate policy in the SEPM console. Make sure GUP is assigned correctly.
Try to find out machine promoted as a GUP is really acting as a GUP or not?
How to search for the clients that act as Group Update Providers ?
http://www.symantec.com/docs/TECH96094
Test SEP to GUP and GUP to SEPM communication
http://www.symantec.com/docs/TECH153328