Continuous "36888 Schannel Errors" in System Event Log when NOT connected to Internet

We are hoping someone will be able to assist with us this very strange issue please ?

We are using Windows 8.1 x64 Enterprise with Office 2013 and the latest Symantec Endpoint Proctecion v12.1.5 installed. They are managed using SCCM2012 in a large AD domain environment

When our workstations are NOT connected to the internet (only local intranet) the following errors appear in SYSTEM event log almost continuously (several times a minute).

Event ID:36888  User: SYSTEM  OpCode:Info  Level:Error  Source:SChannel 

"A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 70. The Windows Schannel error state is 11."

The process associated with these events is "Local Security Authority Process"

When an internet connection is enabled for these machines these 36888 errors will suddenly stop !.

An event "Error 36887 "A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40." Is also occurring on these machines but only occasionally.


As a result, We suspect there must be a process continuously attempting to connect to an internet service and failing ?.

Some of the things we have tried so far;

- We have disabled all non-essential services (e.g. Windows Store Service) one by one but this didn't fix.
- We have tried disabling Tile updates on Start 
- We have tried a bunch of different Group Policy settings to disable different combinations of TLS/SSL in IE config.
- We have searched the internet forums and tried some suggested fixes but this combination of error state and error code seems unique ?.

It doesn't happen on our Windows 7 x64 workstations that have much same apps & configuration.


Any advice or suggestions would be greatly appreciated !

Thanks.


  • Edited by Makes006 Thursday, March 05, 2015 7:08 AM
March 5th, 2015 6:57am

Hi,

I am Chetan Savade from Symantec Technical Support Engineer.

Symantec Endpoint Protection clients can be configured to only run scheduled LiveUpdates from the Symantec LiveUpdate server over the internet if one of the following conditions is met
  • Virus and spyware definitions on a client computer are more than two days old. Maximum duration can be 31 days.

  • A client computer is disconnected from Symantec Endpoint Protection Manager for more than eight hours.

If required configure SEPM liveupdate policy accordingly.

Refer this connect article to find more info: https://www-secure.symantec.com/connect/articles/configure-liveupdate-run-client-computers-part-1

Best Regards,

Chetan


Free Windows Admin Tool Kit Click here and download it now
March 6th, 2015 6:28pm

Thanks so much for this info. I will check it out.

March 12th, 2015 6:19pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics