Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Confirmation of STAS Setup

Hi

 

I'm currently evaluating Sophos XG for a fairly large installation of 5-10k users and about 1Gb of internet traffic. I'm trying to work out the requirements for STAS installation and it _looks_ like I would need to manually install the agent on every single domain controller for it to work properly. I can't find any command line options to automate that nor can I find any way to not have to install it on every DC.

 

To be fair I may have missed something as the documentation seems fragmented and old in a lost of cases. For example the Admin Guide for v16 here points to a document from Feb 2016 for V9 of UTM with an obviously different interface

 

The Watchguard solution didn't require an agent on every DC so I'm hoping i'm just missing something, but if not then at the very least would be an automated installation option.

 

Am I missing something or is the above actually correct?

 

Thanks



This thread was automatically locked due to age.
  • Hi John

     

    Users are scattered over a lot of sites, some with Domain Controllers, some without, depending on site size and requirements to have a local server. All sites are connected over MPLS at decent speeds, so no remote firewalls. Everyone routes back to our Date Center for internet access where the firewalls actually are.

     

    If there is a /verysilent command line option then presumably there are others. Maybe a silent install is possible it's just the options aren't published. In saying that if we have multiple collectors anyway and the DC's can't all point to the same IP having an automated install may not help a great deal since you'd still have to go and tell it where to send it's data

     

    I haven't gotten deep enough yet to understand the collector design and layout so can't answer the question there. Ideally the collectors would live in our Data Center and the Domain Controller's that mostly live out on the sites would all pass to them.

     

    On the up side we did just manage to unlock IPS so it wasn't only using a single core so now we can turn that on and not cripple our bandwidth, so there has been one success today :)

     

    Dave

  • Hi all,

    I suggest you to vote the feature request:

    https://ideas.sophos.com/forums/330219-xg-firewall/suggestions/17262818-stas-install-on-server-core

    I hope they will introduce STAS cmd installation options.

    Thanks for your feedbacks.

  • Voted.  Thanks for pointing out the feature request Luk!