cancel
Showing results for 
Search instead for 
Did you mean: 

Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Hi,

We have ePO 4.5 on Windows Server 2003 Standard.  It's been failing to update for a while.  The scheduled task to update all package (and move existing package to Previous branch) fails every day with 'Terminated' result.

Manually 'Pull' the update package fails to run with same 'Terminated' status.

We found that when the pull process runs, it kills "McAfee ePolicy Orchestrator 4.5.0 Application Server" service.  It has auto recovery settings to restart the service after one minute so it restart by itself.

I have tried 'Pull" process on both McAfeeFtp and McAfeeHttp, All package update or selected pacakge updates (selected only DAT update) and they all failed with exactly same result - kill McAfee service and log shows "Terminated".

Event logs does not record any errors regarding McAfee products when this happens.  It's been running okay for a long time and decided to give up all of a sudden.  SQL database size is about 500MB.

The update servers are configured as:

McAfeeFtp FTP ftp.nai.com/CommonUpdater

McAfeeHttp HTTP update.nai.com/Products/CommonUpdater

From the server when we browse update.nai.com/Products/CommonUpdater site it shows the update files no problem.

I would really appreicate any comments on how to resolve the issue.

Thanks,

Isaac

1 Solution

Accepted Solutions
McAfee Employee JoeBidgood
McAfee Employee
Report Inappropriate Content
Message 10 of 14

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Also, can you try this?

In the folder where ePO is installed, you should find a file called mlcf_tomcat5. Rename this file to mlcf_tomcat5.old, and then try a pull task again. It should work, and mlcf_tomcat5 should be recreated. If this is the case, immediately run another pull task: does it work?

Regards -

Joe

13 Replies
Highlighted
McAfee Employee spamidi
McAfee Employee
Report Inappropriate Content
Message 2 of 14

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Please provide your ePO and OS version details along with DB\Logs\EPOApsvr.log file captured soon after the pull fails.

Message was edited by: spamidi on 4/12/11 12:56:40 AM CDT

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Hi Sailendra

Thanks for the reply.  Sorry I haven't been able to get back to you sooner.  We only have very limited access to the system (a few hours a week or two).  Here's the logs you requested.  Please know that server names were changed from actual names.

It's on Windows Server 2003 (SP2) 32-bit.  Version of ePO is 4.5.

20110426135236 I #12732 SiteMgrWrap Created instance of Site Manager

20110426135237 I #12732 SiteMgr  SetEPOMode: SiteMgr enter ePO mode, server=EPOSERVER, port=8443, EPOUser=, Password=********

20110426135237 I #12732 SiteMgr  DALInit: Connected to DAL successful

20110426135237 I #12732 SiteMgr  SetEPOMode: Set ePO mode successful

20110426135237 I #12732 SiteMgr  DownloadSiteCatalogThreadProc: Download site catalog thread started

20110426135237 I #12732 SIM_InetMgr Starting download session for site McAfeeHttp

20110426135237 I #12732 naInet   HTTP Session initialized

20110426135237 I #12732 naInet   Connecting to HTTP Server using Microsoft WinInet

20110426135237 I #12732 naInet   Trying to connect to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

20110426135237 I #12732 naInet   Connected to Server: update.nai.com on Port: 80 using WinInet

20110426135237 I #12732 SIM_InetMgr Started download session 1 for site McAfeeHttp

20110426135237 I #12732 SiteMgr  CheckSiteStatus: Downloading file SiteStat.xml from site McAfeeHttp

20110426135237 I #12732 SIM_InetMgr Downloading file SiteStat.xml from session 1, LocalDir=C:\WINDOWS\TEMP\nai9BD5.tmp\00000001, RemoteDir=

20110426135237 I #12732 naInet   Open URL: http://update.nai.com:80/Products/CommonUpdater/SiteStat.xml

20110426135237 I #12732 naInet   Trying to download using Microsoft WinInet library

20110426135237 I #12732 naInet   Conneting to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

20110426135237 I #12732 naInet   No resume download needed, calling InternetOpenUrl

20110426135237 I #12732 NAINET   Resolving name PROXYSERVER to address

20110426135237 I #12732 NAINET   Name resolved to 192.168.168.19

20110426135239 I #12732 naInet   Downloading a file of total size: 118, content-length: 118

20110426135239 I #12732 naInet   Downloaded 118 bytes this time

20110426135239 I #12732 naInet   Downloaded 0 bytes this time

20110426135239 I #12732 SIM_InetMgr Downloaded file SiteStat.xml successfully in session 1, size=118, hash=CC9C0AE3CF89408BD89859116B12262E62990FE4

20110426135239 I #12732 SIM_InetMgr Downloading file catalog.z from session 1, LocalDir=C:\WINDOWS\TEMP\nai9BD5.tmp\00000000, RemoteDir=

20110426135239 I #12732 naInet   Open URL: http://update.nai.com:80/Products/CommonUpdater/catalog.z

20110426135239 I #12732 naInet   Trying to download using Microsoft WinInet library

20110426135239 I #12732 naInet   Conneting to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

20110426135239 I #12732 naInet   No resume download needed, calling InternetOpenUrl

20110426135239 I #12732 naInet   Downloading a file of total size: 3380, content-length: 3380

20110426135239 I #12732 naInet   Downloaded 3380 bytes this time

20110426135239 I #12732 naInet   Downloaded 0 bytes this time

20110426135239 I #12732 SIM_InetMgr Downloaded file catalog.z successfully in session 1, size=3380, hash=F25148D9531C76830D9DEEEA37E8CFB1AE8BF35C

20110426135239 I #12732 naInet   HTTP Session closed

20110426135239 I #12732 naInet   ------------------------------------------------------------

20110426135239 I #12732 SIM_InetMgr Session 1 ended, result=1

20110426135239 I #12732 SiteMgr  DownloadSiteCatalogThreadProc: Download site catalog thread ended

20110426135239 x #12732 SiteMgr  SiteMgr main control final release...

20110426135246 I #5480 SiteMgrWrap Created instance of Site Manager

20110426135246 I #5480 SiteMgr  SetEPOMode: SiteMgr enter ePO mode, server=EPOSERVER, port=8443, EPOUser=, Password=********

20110426135246 I #5480 SiteMgr  DALInit: Connected to DAL successful

20110426135246 I #5480 SiteMgr  SetEPOMode: Set ePO mode successful

20110426135246 I #5480 SiteMgr  MirrorThreadProc: Mirror thread started

at this point the 'McAfee ePolicy Orchestrator 4.5.0 Applicatioin Server' service stops.  Then I find the following in the log

20110426135426 I #6092 RManJNI  Starting RManJNI on computer EPOSERVER

20110426135426 I #6092 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

20110426135426 I #6092 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

20110426135426 I #6092 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

20110426135426 I #6092 NAISIGN  FIPS library initialized successfully

20110426135426 I #6092 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

20110426135426 I #6092 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

20110426135426 I #6092 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

20110426135426 I #6092 NAISIGN  FIPS library initialized successfully

20110426135427 I #6092 RManJNI  Checking agent package: Current\EPOAGENT3000\Install\0409\

20110426135427 I #6092 RManJNI  Checking agent package: Current\EPOAGENT3700MACX\Install\0409\

20110426135427 I #6092 RManJNI  Checking agent package: Current\EPOAGENT3700LYNX\Install\0409\

20110426135428 I #6092 RManJNI  Signaling Repository Manager open for business()

20110426135528 I #13580 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

20110426135528 I #13580 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

20110426135528 I #13580 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

20110426135528 I #13580 NAISIGN  FIPS library initialized successfully

20110426135529 I #13580 SiteMgrWrap Created instance of Site Manager

20110426135529 I #13580 SiteMgr  SetEPOMode: SiteMgr enter ePO mode, server=EPOSERVER, port=8443, EPOUser=, Password=********

20110426135529 I #13580 SiteMgr  DALInit: Connected to DAL successful

20110426135529 I #13580 SiteMgr  SetEPOMode: Set ePO mode successful

20110426135529 I #13580 SiteMgr  GeneralInetRequestThreadProc: GeneralInetRequest thread started

20110426135529 I #13580 SIM_InetMgr Starting download session for url myavert.avertlabs.com:8801

20110426135529 I #13580 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

20110426135529 I #13580 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

20110426135529 I #13580 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

20110426135529 I #13580 NAISIGN  FIPS library initialized successfully

20110426135529 I #13580 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

20110426135529 I #13580 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

20110426135529 I #13580 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

20110426135529 I #13580 NAISIGN  FIPS library initialized successfully

20110426135529 I #13580 naInet   HTTP Session initialized

20110426135529 I #13580 naInet   Connecting to HTTP Server using Microsoft WinInet

20110426135529 I #13580 naInet   Trying to connect to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

20110426135529 I #13580 naInet   Connected to Server: myavert.avertlabs.com on Port: 8801 using WinInet

20110426135529 I #13580 SIM_InetMgr Started download session 1 for site myavert.avertlabs.com:8801

20110426135529 I #13580 SiteMgr  GeneralInetRequestThreadProc: Downloading /reportservice.asmx

20110426135529 I #13580 SIM_InetMgr Downloading file reportservice.asmx from session 1, LocalDir=C:\WINDOWS\TEMP\nai9BE9.tmp\00000000, RemoteDir=

20110426135529 I #13580 naInet   Open URL: http://myavert.avertlabs.com:8801/reportservice.asmx

20110426135529 I #13580 naInet   Trying to download using Microsoft WinInet library

20110426135529 I #13580 naInet   Conneting to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

20110426135529 I #13580 naInet   No resume download needed, calling InternetOpenUrl

20110426135529 I #13580 NAINET   Resolving name PROXYSERVER to address

20110426135529 I #13580 NAINET   Name resolved to 192.168.168.19

20110426135550 E #13580 naInet   HTTP Server returned Error : 502

20110426135550 I #13580 naInet   Failed to download the URL /reportservice.asmx using Wininet

20110426135550 I #13580 naInet   Trying to download using windows socket library

20110426135550 I #13580 naInet   Connecting to Real Server: myavert.avertlabs.com on port: 8801

20110426135550 I #13580 naInet   Connecting to Proxy Server: PROXYSERVER on port: 8082

20110426135550 I #13580 naInet   Connected to Proxy Server: PROXYSERVE on port: 8082

20110426135550 I #13580 naInet   Sending HTTP GET Request Header. No Authentication used

20110426135550 I #13580 naInet   Sending HTTP POST Request Body.

20110426135611 I #13580 SIM_InetMgr Download file reportservice.asmx failed in session 1, nainet ret=502

20110426135611 e #13580 SiteMgr  GeneralInetRequestThreadProc: Download file http://myavert.avertlabs.com:8801/reportservice.asmx failed, hr=-2147467259

20110426135611 I #13580 naInet   HTTP Session closed

20110426135611 I #13580 naInet   ------------------------------------------------------------

20110426135611 I #13580 SIM_InetMgr Session 1 ended, result=1

20110426135611 I #13580 SiteMgr  GeneralInetRequestThreadProc: GeneralInetRequest thread ended

20110426135611 x #13580 SiteMgr  SiteMgr main control final release...

Thank you.

Isaac

Message was edited by: poetizer on 25/04/11 9:09:56 PM

Message was edited by: poetizer on 25/04/11 9:11:03 PM
apoling
Level 14
Report Inappropriate Content
Message 4 of 14

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Hi Isaac,

not wanting to replace Saliendra in any way, I just would like to advise that maybe there could be some additional useful info in orion.log at the time of such failure.

Also I would test if the task fails with "Move existing packages in Previous branch" option disabled.

The other portion of ePOAppsrv.log that you show here is related to ePO threat information collection from McAfee, which could be independently running every ~15 mins (do not think it has anything to do with ePO Application service crash, but who knows..)

Attila

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Thanks for the reply Attila

I have tried disabling 'Move existing packages in Previous branch'.  Same result - service stops and restarts after a minute.

How can I separate ePO threat information collection from the updates?

Below is the information from orion.log file at the time of the failure.

Thanks for all your help.

Cheers,

2011-05-03 09:46:40,943 INFO  [Thread-1] core.StandardService  - Starting service Catalina

2011-05-03 09:46:40,975 INFO  [Thread-1] core.StandardEngine  - Starting Servlet Engine: Apache Tomcat/5.5.27

2011-05-03 09:46:40,975 INFO  [Thread-1] core.StandardHost  - XML validation disabled

2011-05-03 09:46:49,428 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8443

2011-05-03 09:46:49,725 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8444

2011-05-03 09:46:49,787 INFO  [Thread-1] storeconfig.StoreLoader  - Find registry server-registry.xml at classpath resource

2011-05-03 09:46:50,568 WARN  [Thread-1] email.EmailServiceConfig  - username was null. assuming no username or password

2011-05-03 09:47:08,412 WARN  [http-8444-Processor25] servlet.SensorMessageServlet  - Server is shutting down, rejecting client message from 192.168.173.3

2011-05-03 09:47:14,568 INFO  [Thread-1] startup.Catalina  - Server startup in 34828 ms

2011-05-03 09:48:46,006 ERROR [pool-6-thread-1] daemon.AvertService  - Exception while executing the AvertAlerts command

com.mcafee.orion.core.cmd.CommandException: POST Command got unexpected HTTP Status:502

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:862)

at com.mcafee.orion.core.cmd.CommandInvoker.invokeCommand(CommandInvoker.java:607)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:596)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:482)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:457)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:624)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:632)

at com.mcafee.epo.avertalerts.daemon.AvertService$AvertDaemon.run(AvertService.java:93)

at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:441)

at java.util.concurrent.FutureTask$Sync.innerRunAndReset(FutureTask.java:317)

at java.util.concurrent.FutureTask.runAndReset(FutureTask.java:150)

at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$101(ScheduledThreadPoolExecutor.java:98)

at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.runPeriodic(ScheduledThreadPoolExecutor.java:181)

at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:205)

at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:886)

at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:908)

at java.lang.Thread.run(Thread.java:619)

Caused by: java.io.IOException: POST Command got unexpected HTTP Status:502

at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.sendSoapRequest(AvertAlertsClient.java:112)

at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReport(AvertAlertsClient.java:145)

at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReportByName(AvertAlertsClient.java:206)

at com.mcafee.epo.avertalerts.command.AvertWebService.invoke(AvertWebService.java:85)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:825)

... 16 more

2011-05-03 09:51:04,990 INFO  [Thread-1] core.StandardService  - Starting service Catalina

2011-05-03 09:51:05,006 INFO  [Thread-1] core.StandardEngine  - Starting Servlet Engine: Apache Tomcat/5.5.27

2011-05-03 09:51:05,006 INFO  [Thread-1] core.StandardHost  - XML validation disabled

2011-05-03 09:51:11,021 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8443

2011-05-03 09:51:11,256 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8444

2011-05-03 09:51:11,475 INFO  [Thread-1] storeconfig.StoreLoader  - Find registry server-registry.xml at classpath resource

2011-05-03 09:51:11,896 WARN  [Thread-1] email.EmailServiceConfig  - username was null. assuming no username or password

2011-05-03 09:51:29,428 INFO  [Thread-1] startup.Catalina  - Server startup in 25578 ms

2011-05-03 09:53:04,271 ERROR [pool-6-thread-1] daemon.AvertService  - Exception while executing the AvertAlerts command

com.mcafee.orion.core.cmd.CommandException: POST Command got unexpected HTTP Status:502

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:862)

at com.mcafee.orion.core.cmd.CommandInvoker.invokeCommand(CommandInvoker.java:607)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:596)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:482)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:457)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:624)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:632)

at com.mcafee.epo.avertalerts.daemon.AvertService$AvertDaemon.run(AvertService.java:93)

at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:441)

at java.util.concurrent.FutureTask$Sync.innerRunAndReset(FutureTask.java:317)

at java.util.concurrent.FutureTask.runAndReset(FutureTask.java:150)

at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$101(ScheduledThreadPoolExecutor.java:98)

at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.runPeriodic(ScheduledThreadPoolExecutor.java:181)

at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:205)

at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:886)

at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:908)

at java.lang.Thread.run(Thread.java:619)

Caused by: java.io.IOException: POST Command got unexpected HTTP Status:502

at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.sendSoapRequest(AvertAlertsClient.java:112)

at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReport(AvertAlertsClient.java:145)

at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReportByName(AvertAlertsClient.java:206)

at com.mcafee.epo.avertalerts.command.AvertWebService.invoke(AvertWebService.java:85)

at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:825)

... 16 more

apoling
Level 14
Report Inappropriate Content
Message 6 of 14

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Hello,

interestingly it seems if maybe the threat information collection would be related to the crash as these entries suggest:

2011-05-03 09:53:04,271 ERROR [pool-6-thread-1] daemon.AvertService  - Exception while executing the AvertAlerts command

com.mcafee.orion.core.cmd.CommandException: POST Command got unexpected HTTP Status:502

and after a while the Catalina servlet restarts.

I assume you are using Microsoft proxy server (do not ask me why, everyone does, its very common) and here are a link to troubleshoot http 502 errors regarding MS proxy use: http://technet.microsoft.com/en-us/library/bb794799.aspx

Also please make sure that your proxy allows anonymous access to *.avertlabs.com:8801 from ePO server.

Plus: I noticed that you used PROXYSERVER on port 8082. Is not that a port assigned to a certain function (agent broadcast port) in ePO configuration?

Attila

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Hi,

Thanks for the response.

Unfortunately we do not use microsoft proxy.  We use WebMarshal.

We configured WebMarshal to allow all traffic to myavert.avertlabs.com.  However there is another firewall and this one we do not have access to configuration.  We believe this firewall is blocking the traffic on port 8801.  We're in process of requesting our HQ to make changes to this firewall for allowing 8801 traffice to myavert.avertlabs.com.  We'll see if it removes 502 error.

Althouth I find it hard to believe 502 error can cause the shut down of McAfee ePO Application service.  I'd like to hear your opinion on this.

Regarding port 8082 for proxy, this is a remote port so it should not confilict with local port 8082 for ePO service.  Anyhow we changed the proxy port to 8080 to eliminate the possibility.  Service still crashes when 'start pull' button is clicked.

I'll update the status again once we have the firewall rules configured.

Thank you.

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Hi Attila

We have created an allow rule on our firewall to aceept connections to *.avertlabs.com:8801 from epo server.  Tested browsing it using a web browser and confirmed it's connecting.

However as soon as we hit 'Start Pull' button, "McAfee ePolicy Orchestrator 4.5.0 Application Server" service dies and there will be no update performed.

Server task log shows all update tasks being 'terminated'

I highly doubt it's being caused by connection issue to *.avertlabs.com:8801, rather by internal problem.

I'd appreciate you thoughts on this one.

Thank you.

Isaac

McAfee Employee spamidi
McAfee Employee
Report Inappropriate Content
Message 9 of 14

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Hi Isaac,

  This looks like something that requires investigation on a support case. The Logs don't seem to point the exact nature of why the application server stops unexpectedly. If it's infact crashing then a crash dump should be generated by enabling the following registry key on the ePO server:

Open Registry Editor (RegEdit.exe) and navigate to the following key:

HKLM\Software\Network Associates\ePolicy Orchestrator

CreateCrashDump – REG_DWORD
Set this value to 1 to automatically generate a crash dump file. If the key does not exist, create a new DWORD value called CreateCrashDump and set it to 1.

Attempt to reproduce the issue and check if a dump file is generated under the ePO or DB\Logs folders.

Log a case with Support once you get this dump file and a MER captured at the same time.

Regards,

Sailendra

McAfee Employee JoeBidgood
McAfee Employee
Report Inappropriate Content
Message 10 of 14

Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

Jump to solution

Also, can you try this?

In the folder where ePO is installed, you should find a file called mlcf_tomcat5. Rename this file to mlcf_tomcat5.old, and then try a pull task again. It should work, and mlcf_tomcat5 should be recreated. If this is the case, immediately run another pull task: does it work?

Regards -

Joe

More McAfee Tools to Help You
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • Visit: Business Service Portal
  • More: Search Knowledge Articles
  • ePolicy Orchestrator Support
  • The McAfee ePO Support Center Plug-in is now available in the Software Manager. Follow the instructions in the Product Guide for more.