This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SEC 5.1 on air-gapped network - delivery failed for software subscription

I installed SEC 5.1 on the server of an air-gapped network. It is the only server (and therefore the DC). It is a Windows Server 2008 R8. I have created an account that is a member of domain admins.

I followed the instruction for setting up updating in an air-gapped network. When updating the server itself, it fails. The first few tries (5 or so) it updated the time-stamp on the warehouse directory in the sophosupdate share but the contents of the share remain in the 500K area. I realise it will not copy the entire contents of the copied warhouse directory (230MB) but this seems a bit to small. The subscription is for Windows 2000 and up.

This night the threat detection data update failed as well.

To my knowledge the involved accounts have all necessary rights. When I deleted the Sophosupdate warehouse directory (as per http://www.sophos.com/en-us/support/knowledgebase/66176.aspx ) it did rebuild it (again with a very small size). It did not rebuild the Decoded-SDDM in the working directory. I'm inclined to think the source update location is available, despite the error message, as the warehouse is being rebuild, albeit incomplete.

Factoids:

- The application log of the server gives this message

Synchronize operation failed when synchronizing product release 'F26F7EC0-1302-4DA7-8B6B-A5383051D41A'. Details: Cannot create stream fa029446aec315089f873009cef7bda8x000.xml

It is followed up by 3 messages (all the same) which refer back to it. This happens each time I start an update.

- The bootstrap location refers to the non-existent \\server\sophosupdate\CIDs\S000

- The firewall is turned off, services are running

I can't see what might be wrong, i.e. why the software doesn't update and create the CIDs directory.

:25783


This thread was automatically locked due to age.
Parents
  • Hello satcapit,

    it just ends up with errors

    I'm not sure I understand correctly where the error is. delivery failed is seen in the Update managers view. You can't "click away" such errors (similar to the Download of ... failed for the endpoints). To deal with delivery failed you have to make note of the associated error code, use the LogViewer and/or the SUMTrace logs to determine the reason for the failure. 

    You won't be able to protect the clients before the initial download and deployment has successfully completed. You did not say how far the SEC on the W2k8 got.

    let me know if you have found any solution to this situation

    As said (and recent threads show), it depends on the nature of the error. It could be a small oversight, a misconfiguration or a glitch - hard to tell without the error details though.

    Christian

    :36885
Reply
  • Hello satcapit,

    it just ends up with errors

    I'm not sure I understand correctly where the error is. delivery failed is seen in the Update managers view. You can't "click away" such errors (similar to the Download of ... failed for the endpoints). To deal with delivery failed you have to make note of the associated error code, use the LogViewer and/or the SUMTrace logs to determine the reason for the failure. 

    You won't be able to protect the clients before the initial download and deployment has successfully completed. You did not say how far the SEC on the W2k8 got.

    let me know if you have found any solution to this situation

    As said (and recent threads show), it depends on the nature of the error. It could be a small oversight, a misconfiguration or a glitch - hard to tell without the error details though.

    Christian

    :36885
Children
No Data