Fix it now
LiveUpdate opened a session and could not carry it through. Your subscription is not involved and nothing here costs money. Norton’s own published remedy for LiveUpdate failing to connect names two culprits before any network work: a third-party VPN app, and a non-Norton security app.
netsh winhttp show proxy
w32tm /resync
- Restart the computer and run LiveUpdate again before changing anything. Norton lists this first, and sessions that fail once frequently complete on the next attempt.
- Disconnect and exit any third-party VPN app, then run LiveUpdate again. A kill switch or a reconnect mid-session ends the update cleanly from Norton’s point of view.
- Uninstall any non-Norton security app, using that vendor’s own removal tool rather than only the entry in Apps and Features, and restart.
- Check the clock. If the date is wrong the secure connection cannot be validated and every session fails; fix it, then use the
w32tm /resyncabove. - If it still fails, use the Norton 360 Remover tool, choosing its Reinstall option, and sign back in to your Norton account afterwards.
The tool is published as the Norton 360 Remover. It replaces the older Remove and Reinstall name at the same address, and its Reinstall option does both halves of the job in one run.
If LiveUpdate completes and reports nothing further needed, you are done. If it fails the same way after a clean installation, the next section explains why that is a network answer rather than a Norton one.
Why it happens
LiveUpdate is an updating framework rather than a simple downloader. It contacts Norton’s content servers over a secured connection, retrieves a catalogue of what your installed products need, downloads the packages, verifies their signatures, and applies them. A failure anywhere along that chain ends the session, and an LU code tells you roughly where it stopped rather than why.
That is why these numbers are worth treating as one family rather than five separate problems. Norton publishes a meaning for only one of them: LU1806 is titled as LiveUpdate not being able to install any of the updates that were selected. The rest are not published at all, and inventing distinctions between them wastes the time you should be spending on the three layers that actually break: the network path, certificate validation, and the local installation.
Norton’s own troubleshooting for LiveUpdate being unable to connect goes straight at two of those. It names a third-party VPN app and a non-Norton security app as the things to remove, then falls back to a clean reinstall. That ordering is not arbitrary – both of those interpose themselves in exactly the place an authenticated update session cannot tolerate interference.
A third-party VPN is breaking the session
You have this one if Updates fail while a VPN client is installed, and complete when it is disconnected or removed.
- Disconnect the VPN and exit the client fully, then run LiveUpdate.
- If that works, add an exception for Norton’s update traffic in the VPN client, or update with the tunnel down.
- Where a kill switch is in use, note that a reconnect mid-session ends the update as cleanly as a cut cable would.
Norton names this before anything else in its own published fix. It is not an edge case.
A second security product is in the path
You have this one if Another antivirus is installed, or one was removed without its vendor’s removal tool.
- Uninstall the other product with its vendor’s own removal utility and restart.
- Open Windows Security and confirm under Virus & threat protection that Norton is the registered antivirus.
- Run LiveUpdate again before doing anything more drastic.
A proxy or an inspecting firewall is rewriting the traffic
You have this one if The machine updates normally at home and fails on a managed network, or other updaters on the same machine also struggle.
- Confirm the proxy configuration with
netsh winhttp show proxyand in the LAN settings dialog under Internet Options. - Where TLS inspection is in use, ask for Norton’s update domains to be excluded. A re-signed certificate does not validate against what the client expects.
- On an authenticating proxy, ask whether the update traffic can be given a service exception.
- Retest from a phone hotspot to confirm the diagnosis before asking anyone to change a firewall rule.
The system clock is wrong
You have this one if The date or time zone is visibly off, often after a flat CMOS battery or a restored virtual machine snapshot.
- Open Settings, Time & language, Date & time, turn on the automatic time and time-zone settings, then choose Sync now.
- From an elevated Command Prompt run
w32tm /resyncand confirm it succeeds. - Replace the motherboard battery if the clock resets every time the machine is switched off at the wall.
- Run LiveUpdate again once the time is right.
A certificate that has not started or has expired according to your clock fails validation exactly as a forged one would. /force is not a parameter of w32tm /resync and passing it stops the command running at all.
The local update data is damaged
You have this one if Every session fails at the same point on a machine whose network is otherwise fine, often after a power loss during an update.
- Restart so nothing holds the update files open, then run LiveUpdate once more.
- Check free disk space on the system volume.
- Run the Norton 360 Remover with its Reinstall option, which lays down fresh program and update data.
- Sign back in to your Norton account afterwards so the subscription reattaches.
Full reference
Which of these numbers Norton actually publishes
| Code | Status | What is known |
|---|---|---|
LU1806 |
Published | Norton’s own solution article is titled for LiveUpdate not being able to install any of the updates that were selected |
LU1801 |
Not published | Appears on sessions that started and did not complete |
LU1803 |
Not published | Same family; discussed only in community threads, which are not a source |
LU1810 |
Not published | Same family |
LU1813 |
Not published | Same family |
There is a practical consequence to that table. If you are searching for a specific LU number and finding only forum threads and content farms, you are not missing a page – Norton has not written one. Diagnose by layer instead.
Diagnosing by layer
| Test | Result | What it tells you |
|---|---|---|
| Load any website on the same machine | Nothing loads | Fix the connection first; LiveUpdate is not the problem |
| Run LiveUpdate on a phone hotspot | Completes | The fixed network is filtering it |
| Run LiveUpdate with the VPN client exited | Completes | The VPN was ending the session |
netsh winhttp show proxy |
A proxy is configured | Ask whether update traffic can bypass it |
| Check the date and time zone | Visibly wrong | Certificate validation cannot succeed until it is corrected |
| Reinstall with the Norton 360 Remover | Still fails identically | The fault is in the path, not the installation |
What a clean reinstall does and does not do
The Norton 360 Remover replaces the program and its update data. That fixes damaged local files and nothing else. If a proxy, an inspecting appliance or a VPN client is the cause, a clean installation fails in exactly the same way, which is why it belongs at the end of the list rather than the start. Norton also states that uninstalling the application does not automatically cancel your subscription, so the reinstall costs you nothing but time – and any local configuration you have not written down.
How long you can safely leave it
Not long, and this is the part worth taking seriously. The engine keeps working with the definitions it already has, so nothing on screen looks urgent, but detection of anything new degrades from the day updates stop. A week of failed sessions is a real exposure rather than a cosmetic complaint. If you cannot fix the path quickly, it is better to remove Norton and let Windows re-enable Microsoft Defender – Microsoft documents that it does so automatically when the non-Microsoft product stops providing real-time protection – than to leave a registered scanner running on stale content.
Where else to look
- Check whether the connection is set as metered under Settings, Network & internet. A metered connection defers large downloads.
- Check whether the machine sleeps mid-session. A laptop that suspends during a download produces exactly this class of failure.
- Look for router-level DNS filtering or parental controls, which block update endpoints by category without telling the client why.
- Confirm the system volume is not nearly full. Update content has to land somewhere before it is applied.
- If Windows Update works and Norton does not, that proves nothing about your connection – they use different endpoints and different validation, and a filtering appliance that permits Microsoft’s domains by default may never have been asked about Norton’s.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
LU1801 |
An update session that started and did not complete. Norton publishes no meaning | not published by the vendor |
LU1803 |
Same family; no published meaning | not published by the vendor |
LU1806 |
LiveUpdate was not able to install any of the updates that were selected | Norton support |
LU1810 |
Same family; no published meaning | not published by the vendor |
LU1813 |
Same family; no published meaning | not published by the vendor |
Confirm the fix worked
- LiveUpdate runs to completion and reports that no further updates are needed.
- The definitions date shown in the Norton app is today or very recent.
- Run LiveUpdate a second time after a restart, to prove the fix holds across reboots.
- The Norton app reports protection as on with no outstanding warnings.
- Repeat the update a day later on the same connection that failed before.
Questions people ask about this
Does this cost anything to fix?
No. Update failures are a network or local file problem, never a licence problem. An expired subscription produces a renewal message instead, which is a different article.
Should I just reinstall straight away?
No. Reinstalling fixes damaged local update data and nothing else. Norton’s own order puts a restart, a VPN check and a rival-antivirus check ahead of it, and if one of those is the cause a clean installation fails identically.
Norton updates fail but Windows Update works. Why?
They use different endpoints and different validation. A filtering appliance that permits Microsoft’s update domains by default may well never have been asked about Norton’s.
What does LU1806 actually mean?
It is the one number in this family Norton publishes: LiveUpdate was not able to install any of the updates that were selected. The session got as far as choosing what to fetch and applied none of it.
Will removing and reinstalling lose my subscription?
No. Norton states that uninstalling the application does not automatically cancel your subscription. Sign back in afterwards and the entitlement reattaches. Local configuration such as custom settings and exclusions is what you lose.
