Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SGN 5.6 - Configuration Protection

Hi all,

I'm new to SGN, but learning fast.

Have installed the Server (IIS), created the Database, MSO, certificates, etc..., Server package, PC Package.

All looking good.

Have the clients software (preinstallation, client_x64, and PC Package - updating policies from SGN sucessfully), installed.

Have defined the appropriate Policy Items and Policy Groups, White Lists, etc...

But I can not get Configuration Protection to take effect - anything USB is allowed - even though policies are set to Restrict.

I have even created a test policy, Blocking everything, with a Test Policy Group, and assigned them to specific AD OU's, along with the Test User and Test PC. Blocked inheritance at the OU level, and selected 'No override'.

Then resynched AD to make sure everything was upto date AD wise...

But the test machine still happily allows any USB device to be plugged in and used.

Each time I change the policy and Synchronise from the PC to the SGN Server, I get the information balloon saying that the new policies have been recieved.

I assuming I'm missing something simple, but I've no idea what.

I've followed the PDF's, looked on the Sophos site and forum, but just can't get anywhere with it.


Can anyone help?

Thanks, Mark

:19397


This thread was automatically locked due to age.
Parents
  • On the clients, you need to make sure you're installing the configuration protection part of the SGN client, as well as the port protector client itself.

    So, for the SGN client, if you're scripting, make sure you're adding ADDLOCAL=ALL to your msi install command.  If you're using the GUI, do a complete install (or a custom install and include the configuration protection part).

    As for the port protection client, as long as the CP part of the SGN client is there, it should install without any problems.  I just use a standard msiexec /passive command to install on our machines.

    Hope this helps.

    :19459
Reply
  • On the clients, you need to make sure you're installing the configuration protection part of the SGN client, as well as the port protector client itself.

    So, for the SGN client, if you're scripting, make sure you're adding ADDLOCAL=ALL to your msi install command.  If you're using the GUI, do a complete install (or a custom install and include the configuration protection part).

    As for the port protection client, as long as the CP part of the SGN client is there, it should install without any problems.  I just use a standard msiexec /passive command to install on our machines.

    Hope this helps.

    :19459
Children
No Data