This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Enterprise Console on XP SP3 in workgroup want to manage computers in workgroup and domain

Hello,

Our customer has installed Sophos Enterprise Console 5.1.0.1839 on a Windows XP SP3 Pro machine. The machine is in a workgroup. The Windwos firewall is turned off. There is also installed Endpoint Security and Control 10.0.

Everything works fine, but...

We want to manage computer in the same workgroup and in a domain too. The endpoint is installed fine on the computers and they can download the updates. They are also XP SP3 Professionals. On the Windows firewall TCP ports 8192, 8193 and 8194 are open. Simple file sharing is off. Everything is set fine. The clients can telnet to the console computer and the console can telnet to the clients.

The only problem is that they can't report back to the console. For a few hours there is a yellow down-arrow, and then it says that the computer is protected but has not yet reported back.

There is a computer in the same workgroup as the management console (previously it was in a domain, but was removed). The Windows firewall is turned off on both computers and no Sophos firewall is installed. Still the client doesn't  report back, but every setting is set as it should be. We are trying now for days but can't get it work. We reinstalled the client from the console multiple times but still nothing.

Can someone please help?

:28977


This thread was automatically locked due to age.
Parents
  • Hi,

    The indication that a client has what it needs to communicate are the certificates it obtains from the server.  On the client the local agent service "Sophos Agent" and router service "Sophos Message Router" request them from the server.

    The router gets its first and then gets the agents.

    The router certs are:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\Private\pkc

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\Private\pkp

    The agent certs are:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private\pkc

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private\pkp

    So on an unmanaged client, do any of the above exist?

    Other things to check on the client is the ParentAddress registry value:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\ParentAddress

    Can the client resolve the management server using these values, it tries them all in turn?

    Can you telnet port 8192 and 8194 of the management server using the parent address value?

    Maybe if you can paste here the lines from a Router log on the client that would also help.

    Regards,

    Jak

    :28983
Reply
  • Hi,

    The indication that a client has what it needs to communicate are the certificates it obtains from the server.  On the client the local agent service "Sophos Agent" and router service "Sophos Message Router" request them from the server.

    The router gets its first and then gets the agents.

    The router certs are:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\Private\pkc

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\Private\pkp

    The agent certs are:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private\pkc

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Remote Management System\ManagementAgent\Private\pkp

    So on an unmanaged client, do any of the above exist?

    Other things to check on the client is the ParentAddress registry value:

    HKEY_LOCAL_MACHINE\SOFTWARE\[Wow6432Node]\Sophos\Messaging System\Router\ParentAddress

    Can the client resolve the management server using these values, it tries them all in turn?

    Can you telnet port 8192 and 8194 of the management server using the parent address value?

    Maybe if you can paste here the lines from a Router log on the client that would also help.

    Regards,

    Jak

    :28983
Children
No Data