Hello.
I have upgraded the ePO server to 5.3.3.
I can't upgrade the Agent Handler to 5.3.2. I managed to upgrade it from 5.3.0 to 5.3.1 to 5.3.2 as I did with the ePO server.
I get the message: Setup was unable to connect to the specified server.
Help me please.
Best Regards
Peter
Solved! Go to Solution.
Reorder the ciphers to have the following at the top:
There are several ways to accomplish this task; the quickest and easiest involves using the third-party tool IISCrypto. You can download this tool from www.nartac.com/Products/IISCrypto and execute it without installation on the impacted Handler(s).
Is that agent handler in any dmz or firewalled environment? Refer to KB66797 for required ports. It appears the agent handler is not able to reach the epo server on all the required ports. It needs 8443, 8444, 80 and 443 open as a minimum to the epo server and sql port to sql server. It is either the epo or sql server that it is failing to connect to. The logs would show better which server it is referring to.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Ok. Which logs should I look at? And where are they?
I'm puzzled because the upgrade to 5.3.2 worked and yes the Agent is in a DMZ.
Best Regards
Peter
%temp%\mcafeelogs directory should contain the agent handler logs. Sometimes firewall rules can get changed without notification to system admins that require specific rules. You can try to telnet to the epo and sql servers on the required ports to see if the agent handler can get through.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Well. I moved the Agent Handler VM to the same subnet as the ePO server and gave the Agent Handler VM an IP address in that subnets scope and got the same error.
The log AH530-ahsetupdll_EPO-AGENT.log shows at the end of it:
20180509135526 I #05528 AHSETUP Determine if 'admin' is an ePO Admin
20180509135526 E #05528 MCUPLOAD SecureHttp.cpp(697): Failed to send HTTP request to server epo-01.au.local for command name epo.command.isAdmin on port 8444. (error=12029)
20180509135526 E #05528 MCUPLOAD SecureHttp.cpp(886): Failed to process the secure communication request (error=12029)
20180509135526 E #05528 AHSETUP ahsetup.cpp(257): Received an error from the ePO server. Error=12029
Any Idea?
Best regards
Peter
can you telnet to port 8444 from ah to epo? Rather than posting sensitive info here, email me the orion logs from the epo server and the agent handler install logs. Zip them up please.
caryn_dinet@mcafee.com
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
UHHH!
Bingo. I might be unto something there https://community.mcafee.com/t5/forums/replypage/board-id/epolicy-orchestrator/message-id/58255
for some reason I can't pull that up. What does it say?
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Reorder the ciphers to have the following at the top:
There are several ways to accomplish this task; the quickest and easiest involves using the third-party tool IISCrypto. You can download this tool from www.nartac.com/Products/IISCrypto and execute it without installation on the impacted Handler(s).
Bingo!
Bonga Bonga Party!
Just follow the instructions in https://kc.mcafee.com/corporate/index?page=content&id=KB89858
and apply the order or those cipher suites on the Agent Handler.
Best Regards
Peter
Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center
Corporate Headquarters
2821 Mission College Blvd.
Santa Clara, CA 95054 USA