This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Enterprise console4/client9 - all PCs greyed out and won't report back

I recently upgraded my servers to Server 2008 r2 and was surprised to find that Sophos wouldn't run on it, so I ended up having to setup a windows 2003 virtual drive specifically for Sophos. However, this was 6 weeks agao and Sophos has not worked since. I did a backup and restore according to the instruction sheet, but although my main site was OK, communication to our second site was lost. All the pcs at the remote site showed up but showed 'awaiting  policy transfer' on every single PC. After four weeks of calls to Sophos, they couldn't resolve it, so I installed a PC at the remote site and loaded a second copy of Enterprise console there which then worked, although I can no longer see the whole domain from the main site.

Some PCs were still not reporting back at the main site either, so following a tech sheet I removed the console from the main site, cleared all the files and registry settings out and did a clean reinstall. I then imported all the pcs again and did a reprotect. Result? All pcs remain greyed out and report "fffffd -This computer is not yet managed. The computer is protected but has not yet reported back". I've phoned Sophos almost every day for 6 weeks now and they still can't come up with a solution. I'm getting very frustrated with them -has anyone else ahd this problem?  (It occurs on both XP and Windows 7 PCs).

:2937


This thread was automatically locked due to age.
Parents
  • Thanks -I was wondering who I could contact to get things moving, but I didn't know I had an account manager -I must find out who they are if I have this sort of trouble again.

    As it happens i did get a call from them this afternoon -from third or fourth level support and the guy solved the matter very quickly. In essence what was wrong was this: Sophos uses certificates to enforce some sort of security between the console and clients. This seems to be a string of text which hides in the mrinit.conf file. Now when I reinstalled the console it assigned itself a new certificate which was different to all the certificates on the existing clients. For reasons I don't understand when I reprotected the clients from the new console it didn't automatically dish out a new certificate. The clients got the update but couldn't report back as their certificates didn't match. Once we'd established that, it was only a matter of copying the mrinit.conf to a folder then running the configCID.exe from a command prompt, then reprotecting all the clients. For some reason all the tech sheets I was sent didn't mention this.

    So, my case is resolved but I'm not impressed with the length of time its taken them to solve it -I've sent log files from both server and client three times during this, and I'm also surprised that they won't log in remotely to have a look themselves. This would save them loads of time and all the other companies i deal with do this routinely now through programs like logmein.

    :2946
Reply
  • Thanks -I was wondering who I could contact to get things moving, but I didn't know I had an account manager -I must find out who they are if I have this sort of trouble again.

    As it happens i did get a call from them this afternoon -from third or fourth level support and the guy solved the matter very quickly. In essence what was wrong was this: Sophos uses certificates to enforce some sort of security between the console and clients. This seems to be a string of text which hides in the mrinit.conf file. Now when I reinstalled the console it assigned itself a new certificate which was different to all the certificates on the existing clients. For reasons I don't understand when I reprotected the clients from the new console it didn't automatically dish out a new certificate. The clients got the update but couldn't report back as their certificates didn't match. Once we'd established that, it was only a matter of copying the mrinit.conf to a folder then running the configCID.exe from a command prompt, then reprotecting all the clients. For some reason all the tech sheets I was sent didn't mention this.

    So, my case is resolved but I'm not impressed with the length of time its taken them to solve it -I've sent log files from both server and client three times during this, and I'm also surprised that they won't log in remotely to have a look themselves. This would save them loads of time and all the other companies i deal with do this routinely now through programs like logmein.

    :2946
Children
No Data