This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Hopelessly Broken

Sorry about the sensationalist headline!!, but this issue has had me running round in circles for the best part of a wewek now, with no hope of resolution in sight.

I have been trying to update my PC to use SAV 10.3. I first updated our management console server to 5.2.1. I then created a new subscription to download the 10.3 version. I then attempted to deploy it to my PC. I noticed that the console reported the statius of my PC as 'this computer is protected but has not yet reported it's status'.....since then I have been on an endless loop of uninstalling, reinstalling, tearing out a few more hairs, following the 'completely remove SAV' instructions provided by Sophos support, rebooting, rebooting, sacrificing a goat or two, then rinse and repeat ad-nauseum. So far NOTHING has helped.....

anyway, here's a list of the things I have tried all to no avail.

1. After initially contacting Sophos support, and getting the instructions for completely deleting SAV, and following those instructions, I started with what should have been considered a clean PC.

2. Deployed SAV from the management server to my PC. The 'setup.exe' process only ran for a few seconds, and at the end of it I had a Sophos icon in my system tray, but the 'open Sophos Endpoint protection' item was greyed out. The only available choices were 'update now', which did nothing....no 'update progress' dialog, zilch, zip, nada. I checked the Services on my PC and all I had was the Sophos Auto Update service. Tried rebooting, still nothing hapening.

3. Manually connected to the CID on our network and ran setup. Got a message indicating that SAV was being uninstalled.

4. Cleaned up my PC as perthe removal instructions....rebooted....sacrificed a goat

5. Connected to the CID on the LAN. Ran installed. This gave me the Sophos Agent, Auto Updater and Message Router in my Services panel, but still no SAV. Same deal with the tray icon. Rebooted....

6. Went to the CID on the lan, navigated down to the 'savxp' folder and ran 'sophos anti-virus.msi'. This appeared to work, and I thought I may have experienced the sweet taste of success.....however.....even though I was now able to open the SAV interface, there was no 'version' information, no 'last updated' information, and all the clickable links (update, scan, etc) were greyed out. Reboot again, sacrifice a chicken this time.....

7. After reboot, still no change. Also, NO updating logs available.....no 'alc.log' to be found anywhere on my PC. Also noticed at this stage that the Sophos Agent service was no longer present....also, clicking Update Now still does nothing.

8. Thought I'd try installing the standalone 10.3 installer downloaded from Sophos web site, but unsurprisingly this failed (I had forgotten a fresh sacrifice before trying this one...). Also noticed that after this the Sophos Remote Management service was now gone from my PC.

9. Uninstalled everything again, cleaned up as per instructions.....kicked the cat a few times

10. ran the standalone installer again. This installed this time. When I put in the details for updating, and then clicked Update Now, nothing happened. Tried both our Sophos credentials, and the local CID credentials, but nothing would trigger an update. Also, still no alc.log to be found anywhere, and 'last updated' in the Interface still showing 'unknown'

11. Killed the cat, ate the goat, installed Kaspersky

12. Only kidding.....didn't kill the cat.

13. Didn't really install Kaspersky.....but at the moment I still appear to have a completely non-functional SAV on my PC.I have also noticed that there are a couple more PCs with the 'protected but havent phoned home yet' status showing inthe management server.

I have an open case with support regarding this, but just thought I'd throw it out there to see if anyone has experienced similar, or can offer any suggestions. My PC has been unprotected for a few days now - well, I'm not sure if it's unprotected or not - and I'm starting to get a bit nervous...

:50486


This thread was automatically locked due to age.
Parents
  • Hello,

    The key here is log files.  

    From a clean slate... Run setup.exe on the client, either through a push (from SEC) or pull from the CID by running setup.exe.

    Cac.pem and mrinit.conf will be copied by setup.exe to the client computer to the "program files" directory of RMS and await the Remote Management System (RMS) install later.

    AutoUpdate will then be installed, possibly after running the CRT tool (the default).  AutoUpdate will pull down all the packages from the CID. E.g. RMS, SAV, SCF, SAU, etc, depending what options have been specified.  , I would expect this to be work, unless the updating credentials are wrong such that it can't get files from the CID.  

    The next phase is the installation of the downloaded packages.

    AutoUpdate will first install RMS: Alupdate.exe will be running as Local System and will orchestrate the install of the packages by loading the individual setup plugin (dlls) of each package. As the installs are running as system, all the logs will go to \windows\temp\.  You should therefore find 1 or more log per component.

    So I would expect, RMS to install first in order to report back in SEC as soon as possible and give feedback.  As long as the client can connect to port 8192 TCP and 8194 TCP of the server and the server can connect to port 8194 TCP of the client this should take a few seconds and the machine should appear as managed in SEC.  SAV info will be blank at this point until SAV is installed and another status message is sent from the client.

    The next package to install will be SAV, again install logs will appear in \windows\temp\.

    AutoUpdate will proceeed in this manor until all the packages are installed creating logs as it goes.  

    For each package that fails to install, the logs of that package are required, Each will have a MSI log and typically an accompanying custom action log files.

    I hope this helps find your issue.  

    Please feel free to post any logs you want checked.

    Regards,

    Jak

    P.S. Runnning the MSIs directly will not work.

    :50500
Reply
  • Hello,

    The key here is log files.  

    From a clean slate... Run setup.exe on the client, either through a push (from SEC) or pull from the CID by running setup.exe.

    Cac.pem and mrinit.conf will be copied by setup.exe to the client computer to the "program files" directory of RMS and await the Remote Management System (RMS) install later.

    AutoUpdate will then be installed, possibly after running the CRT tool (the default).  AutoUpdate will pull down all the packages from the CID. E.g. RMS, SAV, SCF, SAU, etc, depending what options have been specified.  , I would expect this to be work, unless the updating credentials are wrong such that it can't get files from the CID.  

    The next phase is the installation of the downloaded packages.

    AutoUpdate will first install RMS: Alupdate.exe will be running as Local System and will orchestrate the install of the packages by loading the individual setup plugin (dlls) of each package. As the installs are running as system, all the logs will go to \windows\temp\.  You should therefore find 1 or more log per component.

    So I would expect, RMS to install first in order to report back in SEC as soon as possible and give feedback.  As long as the client can connect to port 8192 TCP and 8194 TCP of the server and the server can connect to port 8194 TCP of the client this should take a few seconds and the machine should appear as managed in SEC.  SAV info will be blank at this point until SAV is installed and another status message is sent from the client.

    The next package to install will be SAV, again install logs will appear in \windows\temp\.

    AutoUpdate will proceeed in this manor until all the packages are installed creating logs as it goes.  

    For each package that fails to install, the logs of that package are required, Each will have a MSI log and typically an accompanying custom action log files.

    I hope this helps find your issue.  

    Please feel free to post any logs you want checked.

    Regards,

    Jak

    P.S. Runnning the MSIs directly will not work.

    :50500
Children
No Data