Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Migration from SEC to Central

Just wandered if anyone has any real life experience of migrating from SEC to Central, any tips etc?

Also, if say the migration tool failed and we need to manually script the uninstall - is there a sample script which takes into account bitlocker?

Thanks



This thread was automatically locked due to age.
Parents
  • I've just been through this process, and it's fairly painless.  The main issue is that the migration tool doesn't work if you have any additional SUMs set up, so in my case I had to switch everything to update from our main site before I could start the process.  You also have to disable tamper protection and application control, but this will all be re-enabled once the machines have migrated.

    If you have any specific application control lists or settings you need, you'll want to set these up in Central first.  Settings will not migrate! Common exclusions are set automatically though, so you don't need to worry about things like SQL and Exchange servers.

    If you have any 2003 servers, they won't migrate as this is no longer supported.

    I'm afraid I haven't migrated any machines protected by Bitlocker though, so can't help there. In theory it shouldn't make any difference, but you might want to test it on an expendable machine first!

  • Another thing worth watching for is if you have more than one site, you might want to set up Update Cache servers first to save bandwidth (similar to SUMs in SEC), and then either set firewall rules to block clients from trying to update from another site or manually assign each machine to a Cache Server - details are at https://community.sophos.com/kb/en-us/122577

    Personally, I prefer the firewall route as it means machines will update from the local server if they move from one site to another (laptops, etc...). It depends on your network setup, but I found that without the firewall rules I had clients in one site trying to update over a VPN from a Cache Server located at the other end of a satellite link!

  • Many Thanks RBGE, that's good info. to know. Much appreciated.

Reply Children
No Data