Client task agent keeps CEM Task Server reference after changing connection to LAN connection
search cancel

Client task agent keeps CEM Task Server reference after changing connection to LAN connection

book

Article ID: 384510

calendar_today

Updated On:

Products

IT Management Suite

Issue/Introduction

When SMA (Symantec Management Agent) starts in CEM (Cloud-enabled Management) mode, the Client task agent registers to its Internet facing Task Server (CEM TS).

Then when you changed WiFi connection from CEM (External WIFI) over to Local WIFI then Task Server (TS) registration keeps with CEM TS rather then changing over to Local TS. Causing unnecessary traffic in your environment.

Side-note:
Same thing happens when end-users sleep/hibernate the laptop at home and them move over to office.

 

Current workaround used is either restart SMA service or clicking on "reset agent" from "task status" tab on SMA UI.

Steps to re-produce:

  1. Connect machine via CEM mode
  2. Launch SMA. observe CEM connection active in SMA.
  3. Change network connection over to local. Observe SMA CEM connection inactive, confirm with simple package download.
  4. Check TS registration still connected to CEM TS until reset agent is performed.

Environment

ITMS 8.7.1, 8.7.2

Cause

By Design

Resolution

There is no such functionality now.

When you use SMA UI to reset Client Task Agent (CTA) then it always requests the list of TS servers from SMP Server.

When physical connection is established but the old one is intact, then CTA will not re-register so will not change TS.

When one physical connection is broken and the new connection is established, then CTA is trying to re-register on the previously used TS first and only if it fails it will request the list of TS servers from NS and may end up registering on another TS.

This helps reducing the number of connections to SMP/TS and re-registrations attempts, which are quite costly. We cannot re-register on every network adapter changes.

Recommendation:

We would recommend configuring the network the way when machines from LAN cannot access, they go to internet gateway. The gateway is supposed to be facing outside but not inside.