Administrators may observe that cloud-managed Symantec Endpoint Protection (SEP) agents fail scheduled LiveUpdate sessions while manual updates succeed. This leads to definitions becoming outdated on endpoints in restricted network environments.
Review of the LUE.log or agent logs shows the following errors during a scheduled task:
REQUEST_ERROR - error 12152 (0x00002F78), result API_RECEIVE_RESPONSE
DnsQuery() for (liveupdate.symantec.com) with DNS server (8.8.4.4), failed; err = 1460
DnsQuery() for (liveupdate.symantec.com) with DNS server (8.8.8.8), failed; err = 1460
Error downloading files. Error Code: 0x8D048029
A defect in the LiveUpdate Engine fallback logic causes scheduled sessions to bypass local DNS settings and attempt resolution via public Google DNS (8.8.8.8/8.8.4.4) if the initial connection fails. In environments where outbound DNS (port 53) to public servers is blocked, these queries time out (Error 1460).
Targeted to be fixed in release SEP 14.3 RU10 Patch 2.
Workaround: