This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't activate Security Heartbeat

Hi, 

I've just created a  Sophos Central Admin user, activated my Subscription (Central Server Protection Advanced / Central InterceptX Endpoint Advanced) and installed on a couple of clients. The problem is that in my Cluster of XG330 (SFOS 17.0.6 MR-6) when i try to activate the  Hearthbeat and insert my credentialsi obtain a message saying "Sophos Central registration heartbeat failed, verify your account credentials".

Any idea or someone had the same trouble ?



This thread was automatically locked due to age.
Parents Reply Children
  • This seems to be kinda odd. At least hbtrust.log should display the activation. Can you take a look at applog.log with a tailf to see, if there is something happening? 

  • XG330_WP02_SFOS 17.0.6 MR-6# tail applog.log
    Oct 01 17:18:04 Request type = 1
    Oct 01 17:18:04 apiInterface:versionsupported: true.
    Oct 01 17:18:04 apiInterface:request mode -> 1323.
    Oct 01 17:18:04 apiInterface:Current ver :::'1700.1'
    Oct 01 17:18:04 apiInterface:entityjson::::::::heartbeat::hbcloudregistration=HASH(0xa7146d8)
    Oct 01 17:18:04 Info:: Transaction will not be rolled back for opcode SophosCentralRegistration. If any operation fails, request is part of multiple request :
    Oct 01 17:18:04 opcode:SophosCentralRegistration - starting
    Oct 01 17:18:04 opcode:SophosCentralRegistration - appliance key is C330***********
    Oct 01 17:18:05 opcode:SophosCentralRegistration - registering with Sophos Central failed

     

     

  • And there are no log entries what so ever in hbtrust.log and heartbeatd.log? 

    Can you verify it with tailf ? 

  • XG330_WP02_SFOS 17.0.6 MR-6# ls -1 -e -h h*
    -rw-r--r--    1       0 Nov 11  2017 hbtrust.log
    -rw-r--r--    1       0 Nov 11  2017 heartbeatd.log
    XG330_WP02_SFOS 17.0.6 MR-6#
    XG330_WP02_SFOS 17.0.6 MR-6# tail hbtrust.log
    XG330_WP02_SFOS 17.0.6 MR-6# tail heartbeatd.log

  • Do you work with an HA? And did you update this appliance from version X? Could be some kind of old bug which involves certificates. 

    https://community.sophos.com/kb/en-us/127642

     

  • Yes, i have 2 XG in HA, received new xg and upgraded to SFOS17.0.6 MR-6  4 months ago but never registered with Central prior this moment.

    PS on the link i read : The firmware versions below have the patch and no further action is required:

    • Firewalls running v17 must have at least firmware version 17.0.0.80

     

    don't know if this is related but :

    console> system diagnostics show subsystem-info
    SERVICE              STATUS
    =====================================
    heartbeat            UNREGISTERED
    =====================================
    console>

  • Unregistered is just "un-configured". 

    Can you tell me something about the history of both?

    How old is your Central Account, did you start with a "single" appliance and recently upgrade to HA? 

    How did you build up the HA? 

  • the history is very short.

     

    I've received the XG on Avril, upgraded, built the HA and deployed (NO CENTRAL).

    Yesterday i received the serial number of Endpoint Advanced and i licensed in Central, installed on some PC and then try to activate the Heartbeat with the result described in this thread

  • i think you have to go with Sophos Support in this case.

    Would assume something went wrong on the XG itself. But i cannot troubleshoot this without an session. So the best way is to contact the support or your sophos partner.