Error: Symantec Management Agent crashes in AeXNetComms.dll when HTTP to HTTPS redirection is enabled in IIS
search cancel

Error: Symantec Management Agent crashes in AeXNetComms.dll when HTTP to HTTPS redirection is enabled in IIS

book

Article ID: 452887

calendar_today

Updated On:

Products

Client Management Suite

Issue/Introduction

Symantec Management Agent (SMA) crashes repeatedly after enabling Persistent Connections or updating connection profiles. This occurs specifically in environments where IIS is configured to redirect HTTP traffic to HTTPS.

Symptoms

  • The Symantec Management Agent service (AeXNSAgent.exe) crashes shortly after starting.
  • Agent logs show a fatal error in AeXNetComms.dllFatal error occured in module 'AeXNetComms.dll (8.8.2396.0)' in 'AeXNSAgent.exe'. Exception Code: C00000FD (Stack Overflow)
  • Jobs and Tasks remain in a "Queued" status and do not execute.
  • The issue is reproducible when the Notification Server (NS) has "Redirect HTTP to HTTPS" enabled in IIS Manager.

Environment

  • IT Management Suite (ITMS) 8.8.1
  • Windows endpoints with Symantec Management Agent installed
  • Notification Server configured with IIS HTTP to HTTPS redirection

Cause

Known issue. A defect in the agent's redirection handling code causes a loop.
When a connection profile update is required, the agent attempts to download it via HTTP, receives a redirect to HTTPS, and then incorrectly re-attempts the update via HTTP again, creating a dead loop that results in a stack overflow crash.

Resolution

This issue has been reported to our Broadcom Development team. A fix has been targeted for our ITMS 8.8.2 Release.

A pointfix is available for the following ITMS versions:

"CUMULATIVE POST ITMS 8.8.1 POINT FIXES"
"CUMULATIVE POST ITMS 8.8 RTM (GA) POINT FIXES"
"CUMULATIVE POST ITMS 8.7.3 POINT FIXES"

Workaround:

To stop the agent crash loop and restore task communication, disable the IIS redirection on the Notification Server:

  1. Open IIS Manager on the Notification Server.
  2. Navigate to the Default Web Site.
  3. Open the HSTS settings or HTTP Redirect module (depending on how redirection is implemented).
  4. Disable the Redirect HTTP to HTTPS option.
  5. Restart the Symantec Management Agent service on affected endpoints.

Note: Agents configured for HTTP will automatically switch to HTTPS when Persistent Connection is successfully established, provided the redirect loop is not triggered at the IIS level.

For updates on the fix status, please subscribe to this article by following the steps in .

If further assistance is needed, see .