If you attempt to synchronize clients over a public network, you receive an error: "SSL peer certificate or SSH remote key was not ok", but you don't get this error if the client is on a local network. SSL peer certificate or SSH remote key was not ok
A publicly accessible Symantec Endpoint Protection Manager (SEPM).
The SSL certificate is only valid for a local hostname, or the SEPM does not have a publicly resolvable hostname. At this time, the reason that the issue is triggered by an upgrade to SEP 14.2 is under investigation.
Create a cert for the SEPM with a public hostname.