This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Enterprise Console on XP SP3 in workgroup want to manage computers in workgroup and domain

Hello,

Our customer has installed Sophos Enterprise Console 5.1.0.1839 on a Windows XP SP3 Pro machine. The machine is in a workgroup. The Windwos firewall is turned off. There is also installed Endpoint Security and Control 10.0.

Everything works fine, but...

We want to manage computer in the same workgroup and in a domain too. The endpoint is installed fine on the computers and they can download the updates. They are also XP SP3 Professionals. On the Windows firewall TCP ports 8192, 8193 and 8194 are open. Simple file sharing is off. Everything is set fine. The clients can telnet to the console computer and the console can telnet to the clients.

The only problem is that they can't report back to the console. For a few hours there is a yellow down-arrow, and then it says that the computer is protected but has not yet reported back.

There is a computer in the same workgroup as the management console (previously it was in a domain, but was removed). The Windows firewall is turned off on both computers and no Sophos firewall is installed. Still the client doesn't  report back, but every setting is set as it should be. We are trying now for days but can't get it work. We reinstalled the client from the console multiple times but still nothing.

Can someone please help?

:28977


This thread was automatically locked due to age.
Parents
  • Hi jak,

    Thank you for replying!

    The mentioned registry keys exist on the unmanaged client, except for HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\ManagementAgent\Private\pkc, this key does not exists.
    The client can resolve the management server.

    "Can you telnet port 8192 and 8194 of the management server using the parent address value?"

    When I telnet 8192 then I get back the IOR. But with 8194 I only get a "blank screen".

    Now I checked the HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router\ParentAddress registry key on the server and it was empty. Is this normal? I entered the same values that are on the client ("localhost,servername"), but still nothing.

    The following Router log entry is repeated in every 30 seconds:

    31.08.2012 15:21:36 0E8C I Getting parent router IOR from localhost:8192
    31.08.2012 15:21:36 0E8C I Received parent router's IOR:
    IOR:010000002600000049444c3a536f70686f734d6573736167696e672f4d657373616765526f757465723a312e300000000100000000000000a0000000010102000d00000031302e362e3138302e313937000001204100000014010f004e5550000000210000000001000000526f6f74504f4100526f7574657250657273697374656e740003000000010000004d657373616765526f7574657200000003000000000000000800000001da8e00004f4154010000001400000001da8e0001000100000000000901010000000000140000000800000001daa60086000220
    31.08.2012 15:21:36 0E8C I Successfully validated parent router's IOR
    31.08.2012 15:21:36 0E8C I Accessing parent
    31.08.2012 15:21:36 0E8C E ParentLogon::RegisterParent: Caught CORBA system exception, ID 'IDL:omg.org/CORBA/NO_PERMISSION:1.0'
    Unknown vendor minor code id (0), minor code = 0, completed = NO

    Thanks for your help!

    :29023
Reply
  • Hi jak,

    Thank you for replying!

    The mentioned registry keys exist on the unmanaged client, except for HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\ManagementAgent\Private\pkc, this key does not exists.
    The client can resolve the management server.

    "Can you telnet port 8192 and 8194 of the management server using the parent address value?"

    When I telnet 8192 then I get back the IOR. But with 8194 I only get a "blank screen".

    Now I checked the HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router\ParentAddress registry key on the server and it was empty. Is this normal? I entered the same values that are on the client ("localhost,servername"), but still nothing.

    The following Router log entry is repeated in every 30 seconds:

    31.08.2012 15:21:36 0E8C I Getting parent router IOR from localhost:8192
    31.08.2012 15:21:36 0E8C I Received parent router's IOR:
    IOR:010000002600000049444c3a536f70686f734d6573736167696e672f4d657373616765526f757465723a312e300000000100000000000000a0000000010102000d00000031302e362e3138302e313937000001204100000014010f004e5550000000210000000001000000526f6f74504f4100526f7574657250657273697374656e740003000000010000004d657373616765526f7574657200000003000000000000000800000001da8e00004f4154010000001400000001da8e0001000100000000000901010000000000140000000800000001daa60086000220
    31.08.2012 15:21:36 0E8C I Successfully validated parent router's IOR
    31.08.2012 15:21:36 0E8C I Accessing parent
    31.08.2012 15:21:36 0E8C E ParentLogon::RegisterParent: Caught CORBA system exception, ID 'IDL:omg.org/CORBA/NO_PERMISSION:1.0'
    Unknown vendor minor code id (0), minor code = 0, completed = NO

    Thanks for your help!

    :29023
Children
No Data