This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Manually Adding Clients to Console (no AD)

We've installed Sophos Enterprise Console 5.2.1 on a Windows 7 Pro pc .

There is not an active directory in the network, and our desktops were running Sophos as stand alone / unmanaged clients before .

We try to add the clients in the console, but we have two issues .

1/ When the console scans the network subnet, it finds about 60% of the clients that are online .(Maybe it's a firewall issue ? but Sophos Firewall was installed only on a couple of desktops..

Anyway this is not a big issue, as even if a client is discovered and joined manually in the console we can't actually click 'protect pc' as no matter what combination of username pass we use we can't proceed ..

2/ the big issue is that we try to manually add the clients, many clients seem to update and getting the auto update policy (with the correct primary and secondary location, the correct amount of minutes interval in schedule etc but it's not shown as managed in the console..

We try the manual install by running the setup.exe from the \\SERVERNAME\SophosUpdate\CIDs\S000\SAVSCFXP

we enter in the username credentials the username and password of the sophosupdate user we created on the pc running the console and in the group path

\servername\groupname

do we do something wrong ?

:41335


This thread was automatically locked due to age.
Parents
  • Hi,

    In order to use the protect wizard you have to enter an account that can logon to the computer where the management server is installed and is an administrator on the target client.  Typically, in a workgroup to use SEC to deploy you would ideally need a common account on all computers which is a memeber of the local administrators group on each.

    I'm not sure why bootrapping the clients isn't turning them to managed.  Here are a few things to check:

    Does the Remote Management System (RMS) application get installed by AutoUpdate?  

    You should see this in Add/Remove Programs.

    If so. can the clients resolve the address they are using to contact the server, to check, on a client, look at:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router

    ParentAddress.

    I suspect you should have 2 addresss in there.  The IP of the manageemtn server, unless the management server is running DHCP and the NetBIOS name.  The clients should try all in turn, but can the client resolve the server using these addresses?

    If that's ok, the next thing to check is if the client has its certificates from the server.

    Under:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\Private

    do you have a pkc and pkp value?

    If that's there, do you have a pkc and pkp under:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private

    Check that port 8194 (TCP) is open on the client and the management server can connect to that.

    Check that pots 8192 and 8194 (both TCP) on the management server are available to the client.

    You could use Telnet to test these.

    These should do for starters.

    Regards,

    Jak

    :41341
Reply
  • Hi,

    In order to use the protect wizard you have to enter an account that can logon to the computer where the management server is installed and is an administrator on the target client.  Typically, in a workgroup to use SEC to deploy you would ideally need a common account on all computers which is a memeber of the local administrators group on each.

    I'm not sure why bootrapping the clients isn't turning them to managed.  Here are a few things to check:

    Does the Remote Management System (RMS) application get installed by AutoUpdate?  

    You should see this in Add/Remove Programs.

    If so. can the clients resolve the address they are using to contact the server, to check, on a client, look at:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router

    ParentAddress.

    I suspect you should have 2 addresss in there.  The IP of the manageemtn server, unless the management server is running DHCP and the NetBIOS name.  The clients should try all in turn, but can the client resolve the server using these addresses?

    If that's ok, the next thing to check is if the client has its certificates from the server.

    Under:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\Private

    do you have a pkc and pkp value?

    If that's there, do you have a pkc and pkp under:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private

    Check that port 8194 (TCP) is open on the client and the management server can connect to that.

    Check that pots 8192 and 8194 (both TCP) on the management server are available to the client.

    You could use Telnet to test these.

    These should do for starters.

    Regards,

    Jak

    :41341
Children
No Data