Error 0x8D048029: Scheduled LiveUpdate DNS timeout on cloud-managed SEP agents
search cancel

Error 0x8D048029: Scheduled LiveUpdate DNS timeout on cloud-managed SEP agents

book

Article ID: 447640

calendar_today

Updated On:

Products

Endpoint Security Complete Endpoint Protection

Issue/Introduction

Administrators may observe that cloud-managed Symantec Endpoint Protection (SEP) agents fail scheduled LiveUpdate sessions while manual updates succeed. This leads to definitions becoming outdated on endpoints in restricted network environments.

Review of the LUE.log or agent logs shows the following errors during a scheduled task:

REQUEST_ERROR - error 12152 (0x00002F78), result API_RECEIVE_RESPONSE 
DnsQuery() for (liveupdate.symantec.com) with DNS server (8.8.4.4), failed; err = 1460
DnsQuery() for (liveupdate.symantec.com) with DNS server (8.8.8.8), failed; err = 1460
Error downloading files. Error Code: 0x8D048029

Environment

  • Product: Endpoint Security Complete (SESC) / Symantec Endpoint Protection (SEP)
  • Management: Cloud-Managed (ICDm)
  • Operating System: Windows

Cause

A defect in the LiveUpdate Engine fallback logic causes scheduled sessions to bypass local DNS settings and attempt resolution via public Google DNS (8.8.8.8/8.8.4.4) if the initial connection fails. In environments where outbound DNS (port 53) to public servers is blocked, these queries time out (Error 1460).

Resolution

Targeted to be fixed in release SEP 14.3 RU10 Patch 2.

Workaround:

  1. Trigger a manual "LiveUpdate" command from the ICDm console.
  2. Instruct users to manually click the "LiveUpdate" button in the local SEP agent UI. These methods utilize local DNS and are not impacted by the scheduled fallback defect.

Additional Information