This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problems With SBS 2008 And Enterprise Console 4.0

We have recently moved onto a new network comprising of a SBS 2008 server with 20 Windows 7 32-bit clients. There is also a Windows 7 64-bit client and a Vista SP2 32-bit client in the office too. We have migrated the Sophos Enterprise Console, SUM and the PureMessage installation directly from our older SBS 2003 server.  Everything has gone ok except for Sophos Endpoint install on each new client which at the moment is in complete disarray. As of writing we have stand alone installations which means my organisation can't centrally manage security across our network.

From the start what has happened is my IT firm, with no prior experience of deploying Sophos endpoint on a Windows 7 client network, has tried to push each client through the enterprise console. This of course went and failed because they needed to start the remote registry service prior to installation. They decided due to time constraints to install each client from the network share. Adding each computer to the enterprise console shows each computer, despite that they all have endpoint installed, as unprotected.

I have downloaded the advanced startup guide and followed the instructions to the letter for a Windows 7 install on a test machine. Before I go on any further I must say how ridiculous it is to have to disable UAC (albeit temporarily), the firewall, 128-bit encryption, enable some firewall rules and remote registry on each and every computer we want to protect. That's a lot of configuration to work around our small network let alone a bigger one. Is this going to improve in future releases?

 I have observed that the client will install correctly but does not report back to enterprise console. The error message is eventually "fffffffd  This computer is not yet managed. It is protected but has not yet reported back its status."

Any suggestions or advice from anybody with a similar setup? Any indications on whether the upcoming enterprise console 4.5 is going to be any kinder to us?

:3538


This thread was automatically locked due to age.
Parents
  • Hello Hanny,

    Please try the following for deploying to windows machines. This will allow you to prepare the network so in the future any machine joining the domain is ready for the push install from teh console.

    Issue
    0000002e The computer can no longer be contacted. It may have been shut down, renamed or disconnected, or a required service may not be running. It may be running Windows XP Home.
    What to do

    Domain environment

    1. Open up the Group Policy and edit the Domain Group Policy
    2. Navigate through Computer Config -> Windows Settings -> Security Settings -> System Services and set the following two settings.

    Remote Registry: Automatic
    Computer browser: Automatic

    3. Navigate through Computer Config > Administrative Templates > network > Network Connections > Windows Firewall > Domain Profile

    Define inbound Port exceptions > Click on Show and add the rules

    8192:TCP:*:ENABLED:RMS8192
    8193:TCP:*:ENABLED:RMS8193
    8194:TCP:*:ENABLED:RMS8294

    Windows Server 2003

    Allow File and Print Sharing Exception : Enabled

    Windows Server 2008

    Allow inbound File and Print Sharing exception : Enabled
    Add the IP address of the SEC server


    4. Apply the Group Policy to the machines in the domain.
    5. Run through the Reprotect Wizard

    Let me know if that sorts out the issue, you should not need to disable UAC .

    :3556
Reply
  • Hello Hanny,

    Please try the following for deploying to windows machines. This will allow you to prepare the network so in the future any machine joining the domain is ready for the push install from teh console.

    Issue
    0000002e The computer can no longer be contacted. It may have been shut down, renamed or disconnected, or a required service may not be running. It may be running Windows XP Home.
    What to do

    Domain environment

    1. Open up the Group Policy and edit the Domain Group Policy
    2. Navigate through Computer Config -> Windows Settings -> Security Settings -> System Services and set the following two settings.

    Remote Registry: Automatic
    Computer browser: Automatic

    3. Navigate through Computer Config > Administrative Templates > network > Network Connections > Windows Firewall > Domain Profile

    Define inbound Port exceptions > Click on Show and add the rules

    8192:TCP:*:ENABLED:RMS8192
    8193:TCP:*:ENABLED:RMS8193
    8194:TCP:*:ENABLED:RMS8294

    Windows Server 2003

    Allow File and Print Sharing Exception : Enabled

    Windows Server 2008

    Allow inbound File and Print Sharing exception : Enabled
    Add the IP address of the SEC server


    4. Apply the Group Policy to the machines in the domain.
    5. Run through the Reprotect Wizard

    Let me know if that sorts out the issue, you should not need to disable UAC .

    :3556
Children
No Data