Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[9.001-18] Update error

The clients are reporting "ERROR: SAVXP could not be downloaded from Sophos server".
As primary server is "sophos:d3.sophosupd.com/.../cat..." configured, the secondary is empty.

Any configuration issue?


This thread was automatically locked due to age.
  • If you have the proxy enabled on your UTM, add the d3.sophosupd.com entry to the list of site in the built in "Sophos Liveconnect" exception rule.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • NO...is trying to download some .dat => no connection to server
  • M$, what mode is the proxy in?  What related lines do you see in several live logs when this happens: Firewall, Intrusion Prevention, Web Filtering?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    the proxy is running in "Standard Mode" and the logs didn't contain anything regarding d3.sophosupd.com (no fail, no success ???)

    Does the Endpoint use the proxy settings from IE? (If yes I'll try to bypass)
  • I was having the exact same issue.  I just disabled proxy (was in transparent mode), disabled intrusion protection, and made firewall any/any allow and now the updates are working.  So I am going back and doing them one at a time to narrow it down, will report back.
  • ...have tried now at home (no astaro) => I can access http://d3.sophosupd.com/

    Today I found some entrie at the Firewall log (searched for IP of d3.shophosupd.com):
    2012:08:15-08:03:54 HOST ulogd[4318]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="eth0" srcmac="90:fb:a6:21:41:98" srcip="2.21.246.79" dstip="10.123.1.183" proto="6" length="40" tos="0x00" prec="0x00" ttl="64" srcport="80" dstport="1170" tcpflags="ACK RST" 


    Have created now a FW-Rule to allow ... continue trying
  • Hi, 
    ACK RST packets in the firewall log are usually a red herring and should be ignored.

    You can also check the IPS log and the http / web security / content filter log.

    Barry
  • When I try to download either of the deployment packages I am getting a "Not Found  the requested URL /agent was not found on this server.

    It was working a few weeks ago, but I just noticed that the few computers that I deployed the end point to all say that they are off line on the UTM even though the agent on the client PC is not reporting any errors.

    Any ideas?
  • Have tried now bypassing the Astaro (different LAN with direct internet access) ==> the update is working perfect.

    IPS / content filter doesn't show any hint...will continue search [;)]
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?