This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is it possible to setup two Enterprise Consoles pointing to just one Sophos Endpoint Server?

Hi Guys,

I just wanted to ask if it's possible to have two Enterprise consoles pointing to just a single Sophos Endpoint Server? 

Here is our current setup.  Our Sophos Endpoint Security and Data Protection server is located at London.  We have different sub-groups across the different regions.  What we want to do is to manage the APAC sub-group via Singapore.  The problem is, our link to the London office is quite slow thus, we need to find a way on how to manage the APAC Sub-group from the Singapore office while streamlining the policies from that of the London site.  Is this possible?

Can we set-up another site in Singapore and have it connect to the London site as a replication server so that all policies and updates are consistent?

Thanks!

:17403


This thread was automatically locked due to age.
Parents
  • Hi,

    You can certainly install multiple Enterprise Consoles, each pointing at a single management server.

    Are you saying that you've tried installing a remote console in Singapore but the bandwidth required by the remote console connecting back to London was too high?

    The options you have are really:

    1. A Sophos Management Server at each site, to keep managment traffic contained within the site.  Downside being that the administrative overhead would be more and consolidating reports may require you to write your own reports, etc.. 
    2. A single Sophos Management Server at London, installing just a remote console in Singapore. Possibly using Role Based Administration to partition up the console, so only regional admins see their groups.
    3. A single Sophos Management Server at London, at Singapore install a local SUM and message relay.  The local SUM could update from Sophos, removing updating traffic from your internal network,  It would go to a local Akamai server, the clients would update locally. The endpoints in the region would all talk to a local message relay that would forward on the client management traffic to the London site.  This wouldn't cut down on the amount of data but would cut down on the number of connections.  Message relay article http://www.sophos.com/support/knowledgebase/article/14635.html .
    4. On the management server in London, if it's running 2008R2, you could enable the remote desktop services role and then just "publish" EnterpriseConsole.exe.   Doing this, the Singapore office could use SEC over HTTP or a RDP session just being able to see SEC.

    You could do a couple of these.  If you are running 2008R2 I would start with number 4 as that would be quite a quick test and I would think should perform well.

    Hope that helps.


    Regards,

    Jak 

    :17411
Reply
  • Hi,

    You can certainly install multiple Enterprise Consoles, each pointing at a single management server.

    Are you saying that you've tried installing a remote console in Singapore but the bandwidth required by the remote console connecting back to London was too high?

    The options you have are really:

    1. A Sophos Management Server at each site, to keep managment traffic contained within the site.  Downside being that the administrative overhead would be more and consolidating reports may require you to write your own reports, etc.. 
    2. A single Sophos Management Server at London, installing just a remote console in Singapore. Possibly using Role Based Administration to partition up the console, so only regional admins see their groups.
    3. A single Sophos Management Server at London, at Singapore install a local SUM and message relay.  The local SUM could update from Sophos, removing updating traffic from your internal network,  It would go to a local Akamai server, the clients would update locally. The endpoints in the region would all talk to a local message relay that would forward on the client management traffic to the London site.  This wouldn't cut down on the amount of data but would cut down on the number of connections.  Message relay article http://www.sophos.com/support/knowledgebase/article/14635.html .
    4. On the management server in London, if it's running 2008R2, you could enable the remote desktop services role and then just "publish" EnterpriseConsole.exe.   Doing this, the Singapore office could use SEC over HTTP or a RDP session just being able to see SEC.

    You could do a couple of these.  If you are running 2008R2 I would start with number 4 as that would be quite a quick test and I would think should perform well.

    Hope that helps.


    Regards,

    Jak 

    :17411
Children
No Data