This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall policy problems when upgrading from Sophos 9.5 to 9.7

Hi,

Recently we have started looking to deploy upgrades of 9.7 out to our existing base of 9.5 users. For any of our on-premises staff, it's been quite straightforward , we would put the users into a "9.7 recommended" update group, and the users update accordingly, we would issue an alert to the users PCs advising them to reboot within 24 hours.

But with that said, we have a high number of users who are remote workers, their main means to connect back to our systems is via a IPsec VPN.

From our testing when we attempt to upgrade a 9.5 user (operating remotely), it appears the Sophos update packages download to the PC and the upgrade process begins, but when it gets to the stage of upgrading the firewall, the installation process appears to reset the firewall policy ruleset. From speaking with Sophos Support, the sophos install/update procedure, expects the PC to be on the LAN and be able to see our sophos update servers. But if you're off-site this isn't possible, unless you go to setting up an internet facing update point (which I really don't want to have to do, or see the need for the additional costs to set this up).

Has anyone had this situation before? Can you advise how you resolved it?

The response we received from support was to simply not good enough. The advice given was to disable the firewall, and get the user to retry the VPN connection, then perform a sophos update - to get our firewall rule to download.  This is not a suitable resolution, as we are dealing with large number of employees around the globe. The thoughts of requesting, let alone showing, an employee how to turn off their firewall, is a scary prospect. 

I don't see why the updater/installer process cannot utilise the already cached policy ruleset? Is there a way to force the installer to use the rules already in place on the 9.5 firewall version?

If you can think of any suggestions, it would be much appreciated.

:15771


This thread was automatically locked due to age.
Parents
  • Hi,

    The AdapterStorage ("\ProgramData\Sophos\Remote Management System\3\Agent\AdapterStorage \") and Envelopes ("\ProgramData\Sophos\Remote Management System\3\Router\Envelopes\" ) along with a few other things should be backed-up up to "\windows\temp\" and then restored as part of the update to conserve the config on update of RMS and to prevent a no-ref causing a new policy to be sent from SEC.

    If you create a directory under:

    "\ProgramData\Sophos\Remote Management System\3\"

    just called for example:

    "\ProgramData\Sophos\Remote Management System\3\test\"

    and then upgrade do you see the same thing or does this enable the backed up files to be restored?

    Note: change "\ProgramData \" to "\documents and settings\all users\application data\" as required.

    It might be worth running Process Monitor during an update to see what happens.

    Hope it helps.

    Regards,

    Jak

    :15803
Reply
  • Hi,

    The AdapterStorage ("\ProgramData\Sophos\Remote Management System\3\Agent\AdapterStorage \") and Envelopes ("\ProgramData\Sophos\Remote Management System\3\Router\Envelopes\" ) along with a few other things should be backed-up up to "\windows\temp\" and then restored as part of the update to conserve the config on update of RMS and to prevent a no-ref causing a new policy to be sent from SEC.

    If you create a directory under:

    "\ProgramData\Sophos\Remote Management System\3\"

    just called for example:

    "\ProgramData\Sophos\Remote Management System\3\test\"

    and then upgrade do you see the same thing or does this enable the backed up files to be restored?

    Note: change "\ProgramData \" to "\documents and settings\all users\application data\" as required.

    It might be worth running Process Monitor during an update to see what happens.

    Hope it helps.

    Regards,

    Jak

    :15803
Children
No Data