Continuous "36888 Schannel Errors" in System Event Log when NOT connected to Internet

We are hoping someone will be able to assist with us this very strange issue please ?

We are using Windows 8.1 x64 Enterprise with Office 2013 and the latest Symantec Endpoint Proctecion v12.1.5 installed. They are managed using SCCM2012 in a large AD domain environment

When our workstations are NOT connected to the internet (only local intranet) the following errors appear in SYSTEM event log almost continuously (several times a minute).

Event ID:36888  User: SYSTEM  OpCode:Info  Level:Error  Source:SChannel 

"A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 70. The Windows Schannel error state is 11."

The process associated with these events is "Local Security Authority Process"

When an internet connection is enabled for these machines these 36888 errors will suddenly stop !.

An event "Error 36887 "A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40." Is also occurring on these machines but only occasionally.


As a result, We suspect there must be a process continuously attempting to connect to an internet service and failing ?.

Some of the things we have tried so far;

- We have disabled all non-essential services (e.g. Windows Store Service) one by one but this didn't fix.
- We have tried disabling Tile updates on Start 
- We have tried a bunch of different Group Policy settings to disable different combinations of TLS/SSL in IE config.
- We have searched the internet forums and tried some suggested fixes but this combination of error state and error code seems unique ?.

It doesn't happen on our Windows 7 x64 workstations that have much same apps & configuration.


Any advice or suggestions would be greatly appreciated !

Thanks.


  • Edited by Makes006 Thursday, March 05, 2015 7:08 AM
March 5th, 2015 6:57am

Hi Makes006,

This Event ID 36888 occurs if a user tries to access a web site using HTTP but specifies an SSL port in the URL.

We can try clean boot to troubleshoot whether this issue is caused by a third party program .
How to perform a clean boot in Windows
http://support.microsoft.com/kb/929135

If there is no sensible impacts on operating the machines ,we can try to disable this log by modify the following registry key value to 0.

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\EventLogging

For more information, please refer to the following link:
How to enable Schannel event logging in IIS
http://support.microsoft.com/kb/260729
 
Regards,

Free Windows Admin Tool Kit Click here and download it now
March 6th, 2015 3:46am

Hi,

I am Chetan Savade from Symantec Technical Support Engineer.

Symantec Endpoint Protection clients can be configured to only run scheduled LiveUpdates from the Symantec LiveUpdate server over the internet if one of the following conditions is met
  • Virus and spyware definitions on a client computer are more than two days old. Maximum duration can be 31 days.

  • A client computer is disconnected from Symantec Endpoint Protection Manager for more than eight hours.

If required configure SEPM liveupdate policy accordingly.

Refer this connect article to find more info: https://www-secure.symantec.com/connect/articles/configure-liveupdate-run-client-computers-part-1

Best Regards,

Chetan


March 6th, 2015 1:29pm

Hi,

I am Chetan Savade from Symantec Technical Support Engineer.

Symantec Endpoint Protection clients can be configured to only run scheduled LiveUpdates from the Symantec LiveUpdate server over the internet if one of the following conditions is met
  • Virus and spyware definitions on a client computer are more than two days old. Maximum duration can be 31 days.

  • A client computer is disconnected from Symantec Endpoint Protection Manager for more than eight hours.

If required configure SEPM liveupdate policy accordingly.

Refer this connect article to find more info: https://www-secure.symantec.com/connect/articles/configure-liveupdate-run-client-computers-part-1

Best Regards,

Chetan


Free Windows Admin Tool Kit Click here and download it now
March 6th, 2015 6:28pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics