This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote site takeover with SEC

Hi all, need some suggestions please.

Got a remote site that's had a standalone SEC 3.1 deploying v7.6 SAV to a CID and then clients in that office that update from that. All is well with this and running fine.

Obviously, I now want to migrate these to v9.5 as v7.6 is end of life shortly. The local server is not man enough for (and I don't want it to be destroyed by)  SEC4.x console and UM so I've deployed a CID from HQ down to the branch office via our own SEC 4.0 installation. The CID works fine and I can install new installations from it without any problem.

Now, the bit that's stumped me. From my SEC 4 console, I can 'find' machines in the branch office and they appear in the unassigned section. I've created a new group for this branch and configured updating pointing at my shiney new v9.5 CID. Only problem I have is that when I drag a machine from unassigned to the relevant group and it auto runs 'protect', feed in sufficient credentials........nothing :( Machine continues to update and inform the local SEC. Even if I remove the machine from the local SEC prior, a protect is simply ignored. I can happily protect machines that have never been part of that branch office SEC but I cannot grab control of a machine that has already seen the local SEC.

Without wanting to simply uninstall each client and reinstall from the new CID, is there an easy way to redirect a machine to the HQ SEC? Tech support are working on this too but at the moment seem dumbstruck by the question - guess I have to wait for it to escalate to get anywhere there.

Matt

:5975


This thread was automatically locked due to age.
Parents
  • Hello Matt,

    My thought train here is to replace the MRInit.conf and cac.pem

    Yup, very close but ... of course the removal tool doesn't remove Sophos. Then, Protect Computers - although it does an uninstall - doesn't "completely" uninstall. I think the concept behind it is to avoid a client being "ripped" from its management server. Apart from one or two registry keys you might encounter a file named mrinit.conf.orig in the Sophos %ProgramFiles% folder which - under certain circumstances - might also come in the way.

    RMS is constantly reworked and improved but I can see a good reason why it's not that easy to direct a client to a "foreign" management server. Dunno if there will be anything new in this area with 9.7 but I'm pretty sure that the take over a managed installation problem will be addressed rather sooner than later.

    As you sure know there are unofficial remedies - so just in case you should have turned on PM (no I haven't one for you). And please look which forums you have access to ...

    Christian

    :6001
Reply
  • Hello Matt,

    My thought train here is to replace the MRInit.conf and cac.pem

    Yup, very close but ... of course the removal tool doesn't remove Sophos. Then, Protect Computers - although it does an uninstall - doesn't "completely" uninstall. I think the concept behind it is to avoid a client being "ripped" from its management server. Apart from one or two registry keys you might encounter a file named mrinit.conf.orig in the Sophos %ProgramFiles% folder which - under certain circumstances - might also come in the way.

    RMS is constantly reworked and improved but I can see a good reason why it's not that easy to direct a client to a "foreign" management server. Dunno if there will be anything new in this area with 9.7 but I'm pretty sure that the take over a managed installation problem will be addressed rather sooner than later.

    As you sure know there are unofficial remedies - so just in case you should have turned on PM (no I haven't one for you). And please look which forums you have access to ...

    Christian

    :6001
Children
No Data