1 2 Previous Next 13 Replies Latest reply on Jun 7, 2011 8:34 AM by JoeBidgood

    Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

      Hi,

       

      We have ePO 4.5 on Windows Server 2003 Standard.  It's been failing to update for a while.  The scheduled task to update all package (and move existing package to Previous branch) fails every day with 'Terminated' result.

      Manually 'Pull' the update package fails to run with same 'Terminated' status.

       

      We found that when the pull process runs, it kills "McAfee ePolicy Orchestrator 4.5.0 Application Server" service.  It has auto recovery settings to restart the service after one minute so it restart by itself.

       

      I have tried 'Pull" process on both McAfeeFtp and McAfeeHttp, All package update or selected pacakge updates (selected only DAT update) and they all failed with exactly same result - kill McAfee service and log shows "Terminated".

       

      Event logs does not record any errors regarding McAfee products when this happens.  It's been running okay for a long time and decided to give up all of a sudden.  SQL database size is about 500MB.

       

      The update servers are configured as:

      McAfeeFtp FTP ftp.nai.com/CommonUpdater

      McAfeeHttp HTTP update.nai.com/Products/CommonUpdater

       

      From the server when we browse update.nai.com/Products/CommonUpdater site it shows the update files no problem.

       

      I would really appreicate any comments on how to resolve the issue.

       

      Thanks,

       

      Isaac

        • 1. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service
          Sailendra Pamidi

          Please provide your ePO and OS version details along with DB\Logs\EPOApsvr.log file captured soon after the pull fails.

           

          Message was edited by: spamidi on 4/12/11 12:56:40 AM CDT
          1 of 1 people found this helpful
          • 2. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

            Hi Sailendra

            Thanks for the reply.  Sorry I haven't been able to get back to you sooner.  We only have very limited access to the system (a few hours a week or two).  Here's the logs you requested.  Please know that server names were changed from actual names.

             

            It's on Windows Server 2003 (SP2) 32-bit.  Version of ePO is 4.5.

             

            20110426135236 I #12732 SiteMgrWrap Created instance of Site Manager

            20110426135237 I #12732 SiteMgr  SetEPOMode: SiteMgr enter ePO mode, server=EPOSERVER, port=8443, EPOUser=, Password=********

            20110426135237 I #12732 SiteMgr  DALInit: Connected to DAL successful

            20110426135237 I #12732 SiteMgr  SetEPOMode: Set ePO mode successful

            20110426135237 I #12732 SiteMgr  DownloadSiteCatalogThreadProc: Download site catalog thread started

            20110426135237 I #12732 SIM_InetMgr Starting download session for site McAfeeHttp

            20110426135237 I #12732 naInet   HTTP Session initialized

            20110426135237 I #12732 naInet   Connecting to HTTP Server using Microsoft WinInet

            20110426135237 I #12732 naInet   Trying to connect to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

            20110426135237 I #12732 naInet   Connected to Server: update.nai.com on Port: 80 using WinInet

            20110426135237 I #12732 SIM_InetMgr Started download session 1 for site McAfeeHttp

            20110426135237 I #12732 SiteMgr  CheckSiteStatus: Downloading file SiteStat.xml from site McAfeeHttp

            20110426135237 I #12732 SIM_InetMgr Downloading file SiteStat.xml from session 1, LocalDir=C:\WINDOWS\TEMP\nai9BD5.tmp\00000001, RemoteDir=

            20110426135237 I #12732 naInet   Open URL: http://update.nai.com:80/Products/CommonUpdater/SiteStat.xml

            20110426135237 I #12732 naInet   Trying to download using Microsoft WinInet library

            20110426135237 I #12732 naInet   Conneting to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

            20110426135237 I #12732 naInet   No resume download needed, calling InternetOpenUrl

            20110426135237 I #12732 NAINET   Resolving name PROXYSERVER to address

            20110426135237 I #12732 NAINET   Name resolved to 192.168.168.19

            20110426135239 I #12732 naInet   Downloading a file of total size: 118, content-length: 118

            20110426135239 I #12732 naInet   Downloaded 118 bytes this time

            20110426135239 I #12732 naInet   Downloaded 0 bytes this time

            20110426135239 I #12732 SIM_InetMgr Downloaded file SiteStat.xml successfully in session 1, size=118, hash=CC9C0AE3CF89408BD89859116B12262E62990FE4

            20110426135239 I #12732 SIM_InetMgr Downloading file catalog.z from session 1, LocalDir=C:\WINDOWS\TEMP\nai9BD5.tmp\00000000, RemoteDir=

            20110426135239 I #12732 naInet   Open URL: http://update.nai.com:80/Products/CommonUpdater/catalog.z

            20110426135239 I #12732 naInet   Trying to download using Microsoft WinInet library

            20110426135239 I #12732 naInet   Conneting to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

            20110426135239 I #12732 naInet   No resume download needed, calling InternetOpenUrl

            20110426135239 I #12732 naInet   Downloading a file of total size: 3380, content-length: 3380

            20110426135239 I #12732 naInet   Downloaded 3380 bytes this time

            20110426135239 I #12732 naInet   Downloaded 0 bytes this time

            20110426135239 I #12732 SIM_InetMgr Downloaded file catalog.z successfully in session 1, size=3380, hash=F25148D9531C76830D9DEEEA37E8CFB1AE8BF35C

            20110426135239 I #12732 naInet   HTTP Session closed

            20110426135239 I #12732 naInet   ------------------------------------------------------------

            20110426135239 I #12732 SIM_InetMgr Session 1 ended, result=1

            20110426135239 I #12732 SiteMgr  DownloadSiteCatalogThreadProc: Download site catalog thread ended

            20110426135239 x #12732 SiteMgr  SiteMgr main control final release...

            20110426135246 I #5480 SiteMgrWrap Created instance of Site Manager

            20110426135246 I #5480 SiteMgr  SetEPOMode: SiteMgr enter ePO mode, server=EPOSERVER, port=8443, EPOUser=, Password=********

            20110426135246 I #5480 SiteMgr  DALInit: Connected to DAL successful

            20110426135246 I #5480 SiteMgr  SetEPOMode: Set ePO mode successful

            20110426135246 I #5480 SiteMgr  MirrorThreadProc: Mirror thread started

             

             

            at this point the 'McAfee ePolicy Orchestrator 4.5.0 Applicatioin Server' service stops.  Then I find the following in the log

             

            20110426135426 I #6092 RManJNI  Starting RManJNI on computer EPOSERVER

            20110426135426 I #6092 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135426 I #6092 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135426 I #6092 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

            20110426135426 I #6092 NAISIGN  FIPS library initialized successfully

            20110426135426 I #6092 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135426 I #6092 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135426 I #6092 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

            20110426135426 I #6092 NAISIGN  FIPS library initialized successfully

            20110426135427 I #6092 RManJNI  Checking agent package: Current\EPOAGENT3000\Install\0409\

            20110426135427 I #6092 RManJNI  Checking agent package: Current\EPOAGENT3700MACX\Install\0409\

            20110426135427 I #6092 RManJNI  Checking agent package: Current\EPOAGENT3700LYNX\Install\0409\

            20110426135428 I #6092 RManJNI  Signaling Repository Manager open for business()

            20110426135528 I #13580 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135528 I #13580 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135528 I #13580 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

            20110426135528 I #13580 NAISIGN  FIPS library initialized successfully

            20110426135529 I #13580 SiteMgrWrap Created instance of Site Manager

            20110426135529 I #13580 SiteMgr  SetEPOMode: SiteMgr enter ePO mode, server=EPOSERVER, port=8443, EPOUser=, Password=********

            20110426135529 I #13580 SiteMgr  DALInit: Connected to DAL successful

            20110426135529 I #13580 SiteMgr  SetEPOMode: Set ePO mode successful

            20110426135529 I #13580 SiteMgr  GeneralInetRequestThreadProc: GeneralInetRequest thread started

            20110426135529 I #13580 SIM_InetMgr Starting download session for url myavert.avertlabs.com:8801

            20110426135529 I #13580 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135529 I #13580 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135529 I #13580 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

            20110426135529 I #13580 NAISIGN  FIPS library initialized successfully

            20110426135529 I #13580 NAISIGN  Loading fips module, current folder: E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135529 I #13580 NAISIGN  Checking for fips module in E:\PROGRA~1\McAfee\EPOLIC~1

            20110426135529 I #13580 NAISIGN  Found fips module: E:\PROGRA~1\McAfee\EPOLIC~1\cryptocme2.dll

            20110426135529 I #13580 NAISIGN  FIPS library initialized successfully

            20110426135529 I #13580 naInet   HTTP Session initialized

            20110426135529 I #13580 naInet   Connecting to HTTP Server using Microsoft WinInet

            20110426135529 I #13580 naInet   Trying to connect to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

            20110426135529 I #13580 naInet   Connected to Server: myavert.avertlabs.com on Port: 8801 using WinInet

            20110426135529 I #13580 SIM_InetMgr Started download session 1 for site myavert.avertlabs.com:8801

            20110426135529 I #13580 SiteMgr  GeneralInetRequestThreadProc: Downloading /reportservice.asmx

            20110426135529 I #13580 SIM_InetMgr Downloading file reportservice.asmx from session 1, LocalDir=C:\WINDOWS\TEMP\nai9BE9.tmp\00000000, RemoteDir=

            20110426135529 I #13580 naInet   Open URL: http://myavert.avertlabs.com:8801/reportservice.asmx

            20110426135529 I #13580 naInet   Trying to download using Microsoft WinInet library

            20110426135529 I #13580 naInet   Conneting to Proxy Server PROXYSERVER:8082 using INTERNET_OPEN_TYPE_PROXY

            20110426135529 I #13580 naInet   No resume download needed, calling InternetOpenUrl

            20110426135529 I #13580 NAINET   Resolving name PROXYSERVER to address

            20110426135529 I #13580 NAINET   Name resolved to 192.168.168.19

            20110426135550 E #13580 naInet   HTTP Server returned Error : 502

            20110426135550 I #13580 naInet   Failed to download the URL /reportservice.asmx using Wininet

            20110426135550 I #13580 naInet   Trying to download using windows socket library

            20110426135550 I #13580 naInet   Connecting to Real Server: myavert.avertlabs.com on port: 8801

            20110426135550 I #13580 naInet   Connecting to Proxy Server: PROXYSERVER on port: 8082

            20110426135550 I #13580 naInet   Connected to Proxy Server: PROXYSERVE on port: 8082

            20110426135550 I #13580 naInet   Sending HTTP GET Request Header. No Authentication used

            20110426135550 I #13580 naInet   Sending HTTP POST Request Body.

            20110426135611 I #13580 SIM_InetMgr Download file reportservice.asmx failed in session 1, nainet ret=502

            20110426135611 e #13580 SiteMgr  GeneralInetRequestThreadProc: Download file http://myavert.avertlabs.com:8801/reportservice.asmx failed, hr=-2147467259

            20110426135611 I #13580 naInet   HTTP Session closed

            20110426135611 I #13580 naInet   ------------------------------------------------------------

            20110426135611 I #13580 SIM_InetMgr Session 1 ended, result=1

            20110426135611 I #13580 SiteMgr  GeneralInetRequestThreadProc: GeneralInetRequest thread ended

            20110426135611 x #13580 SiteMgr  SiteMgr main control final release...

             

             

            Thank you.

             

            Isaac

             

            Message was edited by: poetizer on 25/04/11 9:09:56 PM

             

            Message was edited by: poetizer on 25/04/11 9:11:03 PM
            • 3. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service
              Attila Polinger

              Hi Isaac,

               

              not wanting to replace Saliendra in any way, I just would like to advise that maybe there could be some additional useful info in orion.log at the time of such failure.

               

              Also I would test if the task fails with "Move existing packages in Previous branch" option disabled.

               

              The other portion of ePOAppsrv.log that you show here is related to ePO threat information collection from McAfee, which could be independently running every ~15 mins (do not think it has anything to do with ePO Application service crash, but who knows..)

               

              Attila

              • 4. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

                Thanks for the reply Attila

                 

                I have tried disabling 'Move existing packages in Previous branch'.  Same result - service stops and restarts after a minute.

                 

                How can I separate ePO threat information collection from the updates?

                 

                Below is the information from orion.log file at the time of the failure.

                 

                Thanks for all your help.

                 

                Cheers,

                 

                 

                 

                2011-05-03 09:46:40,943 INFO  [Thread-1] core.StandardService  - Starting service Catalina

                2011-05-03 09:46:40,975 INFO  [Thread-1] core.StandardEngine  - Starting Servlet Engine: Apache Tomcat/5.5.27

                2011-05-03 09:46:40,975 INFO  [Thread-1] core.StandardHost  - XML validation disabled

                2011-05-03 09:46:49,428 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8443

                2011-05-03 09:46:49,725 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8444

                2011-05-03 09:46:49,787 INFO  [Thread-1] storeconfig.StoreLoader  - Find registry server-registry.xml at classpath resource

                2011-05-03 09:46:50,568 WARN  [Thread-1] email.EmailServiceConfig  - username was null. assuming no username or password

                2011-05-03 09:47:08,412 WARN  [http-8444-Processor25] servlet.SensorMessageServlet  - Server is shutting down, rejecting client message from 192.168.173.3

                2011-05-03 09:47:14,568 INFO  [Thread-1] startup.Catalina  - Server startup in 34828 ms

                2011-05-03 09:48:46,006 ERROR [pool-6-thread-1] daemon.AvertService  - Exception while executing the AvertAlerts command

                com.mcafee.orion.core.cmd.CommandException: POST Command got unexpected HTTP Status:502

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:862)

                at com.mcafee.orion.core.cmd.CommandInvoker.invokeCommand(CommandInvoker.java:607)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:596)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:482)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:457)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:624)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:632)

                at com.mcafee.epo.avertalerts.daemon.AvertService$AvertDaemon.run(AvertService.jav a:93)

                at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:441)

                at java.util.concurrent.FutureTask$Sync.innerRunAndReset(FutureTask.java:317)

                at java.util.concurrent.FutureTask.runAndReset(FutureTask.java:150)

                at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$101 (ScheduledThreadPoolExecutor.java:98)

                at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.runPeriodi c(ScheduledThreadPoolExecutor.java:181)

                at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(Schedu ledThreadPoolExecutor.java:205)

                at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java: 886)

                at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:908)

                at java.lang.Thread.run(Thread.java:619)

                Caused by: java.io.IOException: POST Command got unexpected HTTP Status:502

                at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.sendSoapRequest(AvertAlert sClient.java:112)

                at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReport(AvertAlertsClien t.java:145)

                at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReportByName(AvertAlert sClient.java:206)

                at com.mcafee.epo.avertalerts.command.AvertWebService.invoke(AvertWebService.java: 85)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:825)

                ... 16 more

                2011-05-03 09:51:04,990 INFO  [Thread-1] core.StandardService  - Starting service Catalina

                2011-05-03 09:51:05,006 INFO  [Thread-1] core.StandardEngine  - Starting Servlet Engine: Apache Tomcat/5.5.27

                2011-05-03 09:51:05,006 INFO  [Thread-1] core.StandardHost  - XML validation disabled

                2011-05-03 09:51:11,021 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8443

                2011-05-03 09:51:11,256 INFO  [Thread-1] http11.Http11BaseProtocol  - Starting Coyote HTTP/1.1 on http-8444

                2011-05-03 09:51:11,475 INFO  [Thread-1] storeconfig.StoreLoader  - Find registry server-registry.xml at classpath resource

                2011-05-03 09:51:11,896 WARN  [Thread-1] email.EmailServiceConfig  - username was null. assuming no username or password

                2011-05-03 09:51:29,428 INFO  [Thread-1] startup.Catalina  - Server startup in 25578 ms

                2011-05-03 09:53:04,271 ERROR [pool-6-thread-1] daemon.AvertService  - Exception while executing the AvertAlerts command

                com.mcafee.orion.core.cmd.CommandException: POST Command got unexpected HTTP Status:502

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:862)

                at com.mcafee.orion.core.cmd.CommandInvoker.invokeCommand(CommandInvoker.java:607)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:596)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:482)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:457)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:624)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:632)

                at com.mcafee.epo.avertalerts.daemon.AvertService$AvertDaemon.run(AvertService.jav a:93)

                at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:441)

                at java.util.concurrent.FutureTask$Sync.innerRunAndReset(FutureTask.java:317)

                at java.util.concurrent.FutureTask.runAndReset(FutureTask.java:150)

                at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$101 (ScheduledThreadPoolExecutor.java:98)

                at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.runPeriodi c(ScheduledThreadPoolExecutor.java:181)

                at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(Schedu ledThreadPoolExecutor.java:205)

                at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java: 886)

                at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:908)

                at java.lang.Thread.run(Thread.java:619)

                Caused by: java.io.IOException: POST Command got unexpected HTTP Status:502

                at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.sendSoapRequest(AvertAlert sClient.java:112)

                at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReport(AvertAlertsClien t.java:145)

                at com.mcafee.epo.avertalerts.myavert.AvertAlertsClient.getReportByName(AvertAlert sClient.java:206)

                at com.mcafee.epo.avertalerts.command.AvertWebService.invoke(AvertWebService.java: 85)

                at com.mcafee.orion.core.cmd.CommandInvoker.invoke(CommandInvoker.java:825)

                ... 16 more

                • 5. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service
                  Attila Polinger

                  Hello,

                   

                  interestingly it seems if maybe the threat information collection would be related to the crash as these entries suggest:

                   

                  2011-05-03 09:53:04,271 ERROR [pool-6-thread-1] daemon.AvertService  - Exception while executing the AvertAlerts command

                  com.mcafee.orion.core.cmd.CommandException: POST Command got unexpected HTTP Status:502

                   

                  and after a while the Catalina servlet restarts.

                   

                  I assume you are using Microsoft proxy server (do not ask me why, everyone does, its very common) and here are a link to troubleshoot http 502 errors regarding MS proxy use: http://technet.microsoft.com/en-us/library/bb794799.aspx

                   

                  Also please make sure that your proxy allows anonymous access to *.avertlabs.com:8801 from ePO server.

                  Plus: I noticed that you used PROXYSERVER on port 8082. Is not that a port assigned to a certain function (agent broadcast port) in ePO configuration?

                   

                  Attila

                  1 of 1 people found this helpful
                  • 6. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

                    Hi,

                     

                    Thanks for the response.

                     

                    Unfortunately we do not use microsoft proxy.  We use WebMarshal.

                    We configured WebMarshal to allow all traffic to myavert.avertlabs.com.  However there is another firewall and this one we do not have access to configuration.  We believe this firewall is blocking the traffic on port 8801.  We're in process of requesting our HQ to make changes to this firewall for allowing 8801 traffice to myavert.avertlabs.com.  We'll see if it removes 502 error.

                     

                    Althouth I find it hard to believe 502 error can cause the shut down of McAfee ePO Application service.  I'd like to hear your opinion on this.

                     

                    Regarding port 8082 for proxy, this is a remote port so it should not confilict with local port 8082 for ePO service.  Anyhow we changed the proxy port to 8080 to eliminate the possibility.  Service still crashes when 'start pull' button is clicked.

                     

                    I'll update the status again once we have the firewall rules configured.

                     

                    Thank you.

                    • 7. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service

                      Hi Attila

                       

                      We have created an allow rule on our firewall to aceept connections to *.avertlabs.com:8801 from epo server.  Tested browsing it using a web browser and confirmed it's connecting.

                      However as soon as we hit 'Start Pull' button, "McAfee ePolicy Orchestrator 4.5.0 Application Server" service dies and there will be no update performed.

                      Server task log shows all update tasks being 'terminated'

                       

                      I highly doubt it's being caused by connection issue to *.avertlabs.com:8801, rather by internal problem.

                       

                      I'd appreciate you thoughts on this one.

                       

                      Thank you.

                       

                      Isaac

                      • 8. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service
                        Sailendra Pamidi

                        Hi Isaac,

                         

                          This looks like something that requires investigation on a support case. The Logs don't seem to point the exact nature of why the application server stops unexpectedly. If it's infact crashing then a crash dump should be generated by enabling the following registry key on the ePO server:

                         

                        Open Registry Editor (RegEdit.exe) and navigate to the following key:

                        HKLM\Software\Network Associates\ePolicy Orchestrator

                        CreateCrashDump – REG_DWORD
                        Set this value to 1 to automatically generate a crash dump file. If the key does not exist, create a new DWORD value called CreateCrashDump and set it to 1.

                        Attempt to reproduce the issue and check if a dump file is generated under the ePO or DB\Logs folders.

                         

                        Log a case with Support once you get this dump file and a MER captured at the same time.

                         

                        Regards,

                        Sailendra

                        • 9. Re: Pull update packages from McAfeeHttp or McAfeeFtp fails and kills McAfee service
                          JoeBidgood

                          Also, can you try this?

                           

                          In the folder where ePO is installed, you should find a file called mlcf_tomcat5. Rename this file to mlcf_tomcat5.old, and then try a pull task again. It should work, and mlcf_tomcat5 should be recreated. If this is the case, immediately run another pull task: does it work?

                           

                          Regards -

                           

                          Joe

                          1 2 Previous Next