This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

problem with connected computer not showing as connected

Hello,

I'm having a problem with one of our machines. It is connected, but doesn't show as connected in the console. The firewall isn't on and I can ping the ip-address. And it seems the machine is till doing his update, probably via the sophos server (I set it up to be the second update server) instead of our server. What could it be?

Jo

:13235


This thread was automatically locked due to age.
Parents
  • Time again for a few words about the architecture and components and some common misconceptions:

    AutoUpdate (AU) and Remote Management System (RMS) are independent. The former uses NetBIOS and/or HTTP to connect to the updating source. The latter connects to ports 8192 and 8194. The updating source might be a server different from the management server. RMS in turn might be using a relay. The Sophos Agent service manages the "internal" communication on a client. It receives the status messages from the various components (AU, SAV, ...) and hands them over to RMS for passing it to the server. RMS receives requests and commands (like for setting a policy) and passes them to the Agent which delivers it to the appropriate component.

    AU gets it's update source(s) from either

    the installer (defaults, GUI or sauconf.xml)

    the GUI -or -

    the console

    Thus it doesn't need RMS to update from the correct location.

    I can/can't ping the machine - by itself this doesn't say much. A machine (its network card) might respond to a ping even though no OS is loaded. V.v. both the ICMP request and the reply might be discarded at various points and if you don't get a reply it doesn't necessarily mean the machine is offline. Even if the machine responds this has no significance re application connectivity.  

    apparently the computer gets his updates from the server [...] it just doesn't show up in the console - from the above it is clear that AU can work correctly even though RMS is in error

    it is connected, but doesn't show as connected in the console - to get any further we have to agree in the meaning of connected. As we are talking about management I prefer the definition used by SEC. Obviously the client's RMS hasn't successfully logged on to the server's message router. Regardless of the fact that it can make a NetBIOS connection to the CID and download the updates (something SEC can't/doesn't check from the server side anyway) connected is defined as having a working RMS communication established. 

    Jak has already referred to the logs in case RMS is still not working after deletion of the keys. As they are recreated "first contact" obviously succeeds but there's likely an error immediately afterwards. What it is can only be determined by taking a look at the mentioned logs.  Repeated attempts to reinstall will likely only confirm that there is a persistent error but won't make it magically go away.

    Christian

    :13259
Reply
  • Time again for a few words about the architecture and components and some common misconceptions:

    AutoUpdate (AU) and Remote Management System (RMS) are independent. The former uses NetBIOS and/or HTTP to connect to the updating source. The latter connects to ports 8192 and 8194. The updating source might be a server different from the management server. RMS in turn might be using a relay. The Sophos Agent service manages the "internal" communication on a client. It receives the status messages from the various components (AU, SAV, ...) and hands them over to RMS for passing it to the server. RMS receives requests and commands (like for setting a policy) and passes them to the Agent which delivers it to the appropriate component.

    AU gets it's update source(s) from either

    the installer (defaults, GUI or sauconf.xml)

    the GUI -or -

    the console

    Thus it doesn't need RMS to update from the correct location.

    I can/can't ping the machine - by itself this doesn't say much. A machine (its network card) might respond to a ping even though no OS is loaded. V.v. both the ICMP request and the reply might be discarded at various points and if you don't get a reply it doesn't necessarily mean the machine is offline. Even if the machine responds this has no significance re application connectivity.  

    apparently the computer gets his updates from the server [...] it just doesn't show up in the console - from the above it is clear that AU can work correctly even though RMS is in error

    it is connected, but doesn't show as connected in the console - to get any further we have to agree in the meaning of connected. As we are talking about management I prefer the definition used by SEC. Obviously the client's RMS hasn't successfully logged on to the server's message router. Regardless of the fact that it can make a NetBIOS connection to the CID and download the updates (something SEC can't/doesn't check from the server side anyway) connected is defined as having a working RMS communication established. 

    Jak has already referred to the logs in case RMS is still not working after deletion of the keys. As they are recreated "first contact" obviously succeeds but there's likely an error immediately afterwards. What it is can only be determined by taking a look at the mentioned logs.  Repeated attempts to reinstall will likely only confirm that there is a persistent error but won't make it magically go away.

    Christian

    :13259
Children
No Data