cancel
Showing results for 
Search instead for 
Did you mean: 

e000846b can not connect to agent only when adbo is engaged

dfeifer
Level 4

   Backup Exec is installed on a server 2003 utility server and is trying to backup a 2003 file server with all shares on the equallogic san. In my test, if I create a job selecting any item located on the san to a b2d location without activating adbo, everything works as expected. As soon as i check adbo and select hardware like documented, the backup fails within 2 seconds. the equallogic event viewer shows no activity and I have no errors in the normal windows event viewer other then the backup failure. Can't think of anything I would be doing wrong. Any ideas?

4 REPLIES 4

newsolutionBE
Level 6

Hi

Please check the link below to see if that helps in resolving

http://www.symantec.com/docs/TECH168861

Thanks

dfeifer
Level 4

  The account actually was part of it, using the global domain administrator account would fail out on adbo, switched to a beservice account and now the job will actually create the snapshot on the equallogic ps4100x san and make it active, but then the beremote and server agent services crash failing the job.

 

Event Type: Information
Event Source: BEDBG
Event Category: (1)
Event ID: 257
Date:  11/1/2011
Time:  8:18:45 AM
User:  N/A
Computer: media server
Description:
A memory dump has been captured C:\Program Files\Symantec\Backup Exec\BEDBG\beremote.exe_4388_0.dmp

-----------------------------------------------------------------------------------------------------------

Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date:  11/1/2011
Time:  8:19:25 AM
User:  N/A
Computer: media server
Description:
Faulting application beremote.exe, version 13.0.5204.114, faulting module msvcr80.dll, version 8.0.50727.6195, fault address 0x000149d1.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 62 65 72   ure  ber
0018: 65 6d 6f 74 65 2e 65 78   emote.ex
0020: 65 20 31 33 2e 30 2e 35   e 13.0.5
0028: 32 30 34 2e 31 31 34 20   204.114
0030: 69 6e 20 6d 73 76 63 72   in msvcr
0038: 38 30 2e 64 6c 6c 20 38   80.dll 8
0040: 2e 30 2e 35 30 37 32 37   .0.50727
0048: 2e 36 31 39 35 20 61 74   .6195 at
0050: 20 6f 66 66 73 65 74 20    offset
0058: 30 30 30 31 34 39 64 31   000149d1

-------------------------------------------------------------------------------------------------------------

Event Type: Error
Event Source: Symantec AntiVirus
Event Category: None
Event ID: 45
Date:  11/1/2011
Time:  8:19:26 AM
User:  NT AUTHORITY\SYSTEM
Computer: media server
Description:
 

SYMANTEC TAMPER PROTECTION ALERT

Target:  C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe
Event Info:  Open Process
ActionTaken:  Logged
Actor Process:  C:\WINDOWS\SYSTEM32\DRWTSN32.EXE (PID 6052)
Time:  Tuesday, November 01, 2011  8:19:26 AM

----------------------------------------------------------------------------------------------------------------

Event Type: Error
Event Source: Symantec AntiVirus
Event Category: None
Event ID: 45
Date:  11/1/2011
Time:  8:19:26 AM
User:  NT AUTHORITY\SYSTEM
Computer: media server
Description:
 

SYMANTEC TAMPER PROTECTION ALERT

Target:  C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\Smc.exe
Event Info:  Open Process
ActionTaken:  Logged
Actor Process:  C:\WINDOWS\SYSTEM32\DRWTSN32.EXE (PID 6052)
Time:  Tuesday, November 01, 2011  8:19:26 AM

----------------------------------------------------------------------------------------------------------------

Event Type: Error
Event Source: Symantec AntiVirus
Event Category: None
Event ID: 45
Date:  11/1/2011
Time:  8:19:26 AM
User:  NT AUTHORITY\SYSTEM
Computer: media server
Description:
 

SYMANTEC TAMPER PROTECTION ALERT

Target:  C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe
Event Info:  Open Process
ActionTaken:  Logged
Actor Process:  C:\WINDOWS\SYSTEM32\DRWTSN32.EXE (PID 6052)
Time:  Tuesday, November 01, 2011  8:19:26 AM

----------------------------------------------------------------------------------------------------------------

Event Type: Information
Event Source: DrWatson
Event Category: None
Event ID: 4097
Date:  11/1/2011
Time:  8:19:26 AM
User:  N/A
Computer: media server
Description:
The application, C:\Program Files\Symantec\Backup Exec\beremote.exe, generated an application error The error occurred on 11/01/2011 @ 08:19:26.003 The exception generated was c0000005 at address 781449D1 (MSVCR80!wcslen)

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
00000: 0d 00 0a 00 0d 00 0a 00   ........
00008: 41 00 70 00 70 00 6c 00   A.p.p.l.
00010: 69 00 63 00 61 00 74 00   i.c.a.t.
00018: 69 00 6f 00 6e 00 20 00   i.o.n. .
00020: 65 00 78 00 63 00 65 00   e.x.c.e.
00028: 70 00 74 00 69 00 6f 00   p.t.i.o.
00030: 6e 00 20 00 6f 00 63 00   n. .o.c.
00038: 63 00 75 00 72 00 72 00   c.u.r.r.
00040: 65 00 64 00 3a 00 0d 00   e.d.:...
00048: 0a 00 20 00 20 00 20 00   .. . . .
<<snip>>

----------------------------------------------------------------------------------------------------------------

Event Type: Warning
Event Source: Backup Exec
Event Category: None
Event ID: 57755
Date:  11/1/2011
Time:  8:19:27 AM
User:  N/A
Computer: media server
Description:
Backup Exec Alert: Job Completed with Exceptions
(Server: "media server") (Job: "Backup 00118") The job completed successfully.  However, the following conditions were encountered:

A snapshot operation required by this job was unsuccessful. Check the job log and the Windows Event Viewer for additional information.
 

 For more information, click the following link:
http://eventlookup.veritas.com/eventlookup/EventLookup.jhtml


----------------------------------------------------------------------------------------------------------------

Event Type: Error
Event Source: SQLSERVERAGENT
Event Category: Alert Engine
Event ID: 318
Date:  11/1/2011
Time:  8:19:33 AM
User:  N/A
Computer: media server
Description:
Unable to read local eventlog (reason: The data area passed to a system call is too small).

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


 

 

VJware
Level 6
Employee Accredited Certified

Have you set Symantec Endpoint Protection Tamper Protection or Application control policies which block access or terminate process for read/write/access attempt on system files ?

Also, would suggest to configure SEP exclusions for backup exec...

dfeifer
Level 4

I uninstalled symantec endpoint protection just to rule it out and with sep removed i still recieve the same errors minus the tamper protection references.