This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Updating Policy options for Initial Install Source (anything other than UNC/SMB?)

When looking at the Primary and Secondary Server options I see that there are options for HTTP, and UNC. Is it possible to use HTTP as an initial install source, or even "Sophos" as an initial install source?

I am seeking options for installation over a VPN connection and didn't want the install taking place through the tunnel. The VPN machines are not located in the same office, so a SUM or even local distribution point would do little good.

:57665


This thread was automatically locked due to age.
  • HI,

    Just in case it's helpful, Sophos Cloud managment for these machines would help.  That is a small installer that you download from the internet and the computer then updates from Sophos.

    What you could do with on-premise is zip up the CID.

    Create a self extractor that unpacks the CID and then runs setup.exe from the location with the required switches.

    https://www.sophos.com/en-us/support/knowledgebase/12570.aspx

    As soo as RMS kicks in, then the computer will get the updating policy and it will be configured to update from the CID.

    https://www.sophos.com/en-us/support/knowledgebase/67504.aspx may also help.

    This self extractor could be hosted on the internet and downloaded.

    Regards,

    Jak

    :57668
  • Hello LoXodonte,

    Is it possible to use HTTP as an initial install source

    the Initial Install Source is for deployment from the console (aka Protect Computers). They'd likely have to be on VPN and you'd have to be able to locate and contact them in order to perform a Protect.

    Protect normally uses the Primary location and (as the description in the policy says) if this is HTTP you must specify a (UNC) Initial Install Source.

    Sophos wouldn't work because you need your site's mrinit.conf for RMS.

    A custom package.is probably the better method for offsite endpoints - please see How to create a standalone or custom installer package.

    Christian

    :57669