This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Clients can't contact console or update

After the recent  Shh/Updater-B false positive problem we have manually unistalled Sophos from the affected clients. We were running an older verison of Enterprise console and could not upgrade because of a persistent error when it attempted to use the current database (we also deleted the database to no avail). So now we have a clean install of EC 5.1. Clients that were not affect by Shh/Updater-B have reported in fine and are updating after running SophosReInit.vbs to point them at the new Enterprise Console.

We are having two problems –

1. The console cannot seem to push Sophos down to clean clients i.e. clients that have had no Sophos on them before. You just get an amber egg timer on the client name in the Enterprise Console and nothing happens. No events are logged on either client or server. Have followed http://www.sophos.com/en-us/support/knowledgebase/111180.aspx

2. Using a standalone installer have manually installed Sophos on clients that previously suffered the Shh/Updater-B problem.  Have used the SophosReInit.vbs script to direct these clients to the console. They remain greyed out in the console and doing a manual update from the client results in ‘‘‘‘Could not contact server’’’’. The server is recording authentication failures for these clients:

Log Name:      Security

Task Category: Logon

Level:         Information

Keywords:      Audit Failure

Computer:      SAVserver.domain.org

An account failed to log on.

Subject:

                Security ID:                           NULL SID

                Account Name:                    -

                Account Domain:                 -

                Logon ID:                               0x0

Logon Type:                                          3

Account For Which Logon Failed:

                Security ID:                           NULL SID

                Account Name:                    SophosSAUComputer100

                Account Domain:                 Computer100

Failure Information:

                Failure Reason:                    Unknown user name or bad password.

                Status:                                    0xc000006d

                Sub Status:                            0xc0000064

Any help with any of this would be greatly appreciated.

:33755


This thread was automatically locked due to age.
  • Hello bbnpa1957,

    1. article 111180 is specifically for Domain environments and SEC versions up to 5.0 - for 5.1 you should follow 116754 (Domain) or 116755 (workgroup). Not that they differ much but they do. SEC should eventually return some error - either that it could not contact the computers or that the install did not start. Please see also How does the 'Protect computers wizard' perform an installation? as it might give you an idea where to look for a hint why it fails.

    2. Actually there seem to be two problems - a) the clients do still not report after using SophosReInit.vbs and b) the clients can not update from the server.

    For a) - could you please post (parts of) the logs created (SophosReinit.txt and  ClientMRInit-....log)?

    For b) - the ALUpdate log ([%ProgramFiles%|%ProgramData%]\Sophos\AutoUpdate\Logs) should contain the error as seen from the client's side. Did you install SEC5.1 on the same server where the older version ran?

    Christian

    :33803
  • Hi thanks for the reply Christian, I've resorted to using a different and completely clean install of W28kR2 x64 to get this to work. There must have been something on the other server preventing it working. Have created a new SophosReInit script and have successfully pointed existing clients and protected new clients. I'm yet to protect a client that has under going false positive shh/updater-b but should that fail it will mean a new post.

    Thanks again

    :33897