This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

504 / 8001 MCS Client intermittently timing out connecting to mcs-push-server-eu-central-1.prod.hydra.sophos.com

There seem to be issues on the Sophos Coud Server mcs-push-server-eu-central-1.prod.hydra.sophos.com.

Can sophos please confirm, the server is running as fast as it should and that this issue is not server side? Please do not simply point to the https://centralstatus.sophos.com/ page - this is green.

Over the day we have many 8001 Errors in event log and the Sophos Agent reports Gateway Timeout 504.

The requests go through a SG Webfilter that does no HTTPS interception, and so no AV scanning of HTTPS, it does only logging and category checking. Also you can see that there are all Exceptions set for the Sophos URLs: exceptions="av,sandbox,auth,content,url,ssl,certcheck,certdate,mime,cache,fileextension,size,patience"

The internet connection is fast and available during that times.

Look here, some of the requests take over 2200 seconds for a size of only 53446 bytes!

FAIL 2020:11:10-13:02:36 dnstime="630" aptptime="89" cattime="0" avscantime="0" fullreqtime="2242635532"

FAIL 2020:11:10-13:02:36 dnstime="7271" aptptime="60" cattime="0" avscantime="0" fullreqtime="2237909027"

OK 2020:11:10-13:04:49 dnstime="4382" aptptime="60" cattime="0" avscantime="0" fullreqtime="60029834"

OK: 2020:11:10-13:04:49 dnstime="1" aptptime="76" cattime="0" avscantime="0" fullreqtime="60055172"

FAIL: 2020:11:10-13:27:08 dnstime="1163" aptptime="88" cattime="0" avscantime="0" fullreqtime="1472177632"

 

A normal web request of the Sophos Client usually only takes about 6 seconds:

(https://tf-edr-message-upload-eu-central-1-prod-bucket.s3.amazonaws.com) dnstime="5184" aptptime="60" cattime="0" avscantime="0" fullreqtime="6079874"

Logs for the 2020:11:10-13:02 Event:

Sophos SG Webfilter:
2020:11:10-13:02:36 fw-1 httpproxy[17259]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="CONNECT" 
srcip="1.2.3.4" dstip="52.29.36.14" user="" group="" ad_domain="" statuscode="200" cached="0" profile="REF_HttProContaInterNetwo5 (ServerNet-Proxy-Transparent)" 
filteraction="REF_HttCffServernetp (ServerNet-Proxy-Transparent)" size="53446" request="0xd6b1b100" url="https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com/" referer="" error="" 
authtime="0" dnstime="630" aptptime="89" cattime="0" avscantime="0" fullreqtime="2242635532" device="0" auth="0" ua="" exceptions="av,sandbox,auth,content,url,ssl,certcheck,certdate,mime,cache,fileextension,size,patience" 
Sophos AV Agent Log:
MCSClient.log

2020-11-10T12:02:43.847Z [ 3920: 4100] [v4.12.686.0] INFO  Establishing push connection
2020-11-10T12:02:43.850Z [ 3920: 4100] [v4.12.686.0] INFO  (async) GET https://mcs-push-server-eu-central-1.prod.hydra.sophos.com:443/ps/push/endpoint/7ba049fd-1cea-24fc-e954-b3c15e142fb0
2020-11-10T12:02:53.883Z [ 3920: 4804] [v4.12.686.0] INFO  (async) 504 Gateway Time-out: conntime=10032ms
2020-11-10T12:02:53.883Z [ 3920: 4100] [v4.12.686.0] WARN  (async) connection timeout
2020-11-10T12:02:53.883Z [ 3920: 4100] [v4.12.686.0] WARN  [push]: error creating async stream: 0
2020-11-10T12:02:53.884Z [ 3920: 4100] [v4.12.686.0] INFO  [push]: Dropping connection after error

I found this posts but they do not provide a solution but the issue is out there for some years now.

https://community.sophos.com/intercept-x-endpoint/f/discussions/111982/sophos-mcs-event-8001-the-sophos-mcs-cliens-service-has-received-an-http-status-504-503-from-the-server/441579#441579

https://community.sophos.com/intercept-x-endpoint/f/discussions/101233/event-id-8001-the-sophos-management-communications-system-client-service-has-received-an-http-status-503-from-the-server-this-might-indicate-that-action-is-necessary



This thread was automatically locked due to age.
Parents Reply Children
  • Hello, this is not for every connection. It's just randomly failing.

    Latest today for one of our machines here:

    2020-11-23T15:38:42.104Z [ 2376: 2716] [v4.12.686.0] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;FIM;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/xxxxxxxx-xxxx-xxxx-xxxx-4d316c617c9e
    2020-11-23T15:38:44.237Z [ 2376: 2716] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=2132ms
    2020-11-23T15:39:11.298Z [ 2376: 7884] [v4.12.686.0] INFO  (async) 200 OK: chunk=45 rcvd=7 conntime=2640083ms
    2020-11-23T15:39:39.243Z [ 2376: 2716] [v4.12.686.0] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;FIM;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/xxxxxxxx-xxxx-xxxx-xxxx-4d316c617c9e
    2020-11-23T15:39:49.249Z [ 2376: 2716] [v4.12.686.0] INFO  504 Gateway Time-out: sent=0 rcvd=132 elapsed=10005ms
    2020-11-23T15:39:49.249Z [ 2376: 2716] [v4.12.686.0] INFO  Dropping connection after error
    2020-11-23T15:39:49.250Z [ 2376: 2716] [v4.12.686.0] INFO  Disconnecting push connection
    2020-11-23T15:39:49.250Z [ 2376: 2920] [v4.12.686.0] INFO  Push connection has been lost. Trigger a command poll
    2020-11-23T15:39:49.250Z [ 2376: 2716] [v4.12.686.0] INFO  [backoff] waiting 182s (110s + 72s skew) after failures: 1
    2020-11-23T15:39:49.253Z [ 2376: 2716] [v4.12.686.0] INFO  The telemetry data is: {"mcs":{"agent":{"cloudPlatform":""},"flags":{"amsi.available":true,"behavioral-blocking.available":false,"behavioral-silent.available":false,"hmpa.amsiguard.enforce":false,"hmpa.amsiguard.silent":false,"hmpa.apisetguard.enforce":false,"hmpa.apisetguard.silent":true,"hmpa.branchtracing.enforce":false,"hmpa.branchtracing.silent":true,"hmpa.cryptoguardefs.enforce":true,"hmpa.cryptoguardefs.silent":true,"hmpa.ctfguard.enforce":false,"hmpa.ctfguard.silent":true,"hmpa.heapheaphooray.enforce":false,"hmpa.heapheaphooray.silent":true,"hmpa.lockdownautorun.v2.enforce":false,"ips.available":false,"ips.filter.inbound":false,"ips.filter.outbound":false,"livequery.network-tables.available":true,"mcs.push.available":true,"mlwindowsdir.available":true,"pinnedglobalreplocal.available":true,"pinnedglobalrepnetwork.available":true,"repair.available":false,"sed.tp2020.available":true,"ssp.instant-core-clean-items.available":true,"ssp.static.postanalysis.available":true,"su-setup.available":true,"vdldetections.available":true},"preferredServer":{"server":"mcs-cloudstation-eu-central-1.prod.hydra.sophos.com","viaProxy":false,"viaMessageRelay":false,"authScheme":0},"pushServer":{"server":"mcs-push-server-eu-central-1.prod.hydra.sophos.com","isConnected":false}}}
    2020-11-23T15:39:49.262Z [ 2376: 2716] [v4.12.686.0] INFO  [backoff] waiting 129s (110s + 19s skew) after failures: 1
    2020-11-23T15:41:59.233Z [ 2376: 2716] [v4.12.686.0] INFO  [connect] trying server https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com/sophos/management/ep
    2020-11-23T15:41:59.234Z [ 2376: 2716] [v4.12.686.0] INFO  [connect] trying direct connection without a proxy
    2020-11-23T15:41:59.234Z [ 2376: 2716] [v4.12.686.0] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep
    2020-11-23T15:41:59.270Z [ 2376: 2716] [v4.12.686.0] INFO  200 : sent=0 rcvd=168 elapsed=36ms

    200 followed by 504 followed by 200 again.

    same here, other request, other machine:

    latest 504 from today

    2020-11-23T15:04:53.793Z [ 3076: 3516] [v4.12.686.0] INFO  [connect: preferredRoute] using direct connection
    2020-11-23T15:04:53.793Z [ 3076: 3516] [v4.12.686.0] INFO  PUT https://tf-edr-message-upload-eu-central-1-prod-bucket.s3.amazonaws.com/WDyq/TrickleFeedData/1/plain/json/xxxxxxxx-xxxx-xxxx-xxxx-be7dd2a07095/xxxxxxxx-xxxx-xxxx-xxxx-af7ed362a847/xxxxxxx528/AbWSrvBYXh-8?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAS6xxxxDP3L4HG25P%xxxxxxxxxxxxxx%2Feu-central-1%2Fs3%2Faws4_request&X-Amz-...
    2020-11-23T15:04:53.931Z [ 3076: 3516] [v4.12.686.0] INFO  200 : sent=1129 rcvd=0 elapsed=138ms
    2020-11-23T15:04:53.931Z [ 3076: 3516] [v4.12.686.0] INFO  Upload of C:\ProgramData\Sophos\Management Communications System\Endpoint\Channels\EDR\Incoming\20201123T150450Z_66833.dat succeeded
    2020-11-23T15:05:15.989Z [ 3076: 7948] [v4.12.686.0] INFO  (async) 200 : chunk=13 rcvd=7 conntime=720134ms
    2020-11-23T15:05:21.445Z [ 3076: 3588] [v4.12.686.0] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;AMSI;CORC;CORE;EFW;HBT;HMPA;LiveQuery;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/xxxxxxxx-xxxx-xxxx-xxxx-fae73d268a74
    2020-11-23T15:05:31.453Z [ 3076: 3588] [v4.12.686.0] INFO  504 Gateway Time-out: sent=0 rcvd=132 elapsed=10006ms
    2020-11-23T15:05:31.453Z [ 3076: 3588] [v4.12.686.0] INFO  Dropping connection after error
    2020-11-23T15:05:31.454Z [ 3076: 3588] [v4.12.686.0] INFO  Disconnecting push connection
    2020-11-23T15:05:31.455Z [ 3076: 7948] [v4.12.686.0] INFO  Push connection has been lost. Trigger a command poll
    2020-11-23T15:05:31.455Z [ 3076: 3588] [v4.12.686.0] INFO  [backoff] waiting 128s (110s + 18s skew) after failures: 1
    2020-11-23T15:05:31.464Z [ 3076: 3588] [v4.12.686.0] INFO  The telemetry data is: {"mcs":{"agent":{"cloudPlatform":""},"flags":{"amsi.available":true,"behavioral-blocking.available":false,"behavioral-silent.available":false,"hmpa.amsiguard.enforce":false,"hmpa.amsiguard.silent":false,"hmpa.apisetguard.enforce":false,"hmpa.apisetguard.silent":true,"hmpa.branchtracing.enforce":false,"hmpa.branchtracing.silent":true,"hmpa.credguard.v2.enforce":false,"hmpa.credguard.v2.silent":false,"hmpa.cryptoguard.v5.enforce":false,"hmpa.cryptoguardefs.enforce":true,"hmpa.cryptoguardefs.silent":true,"hmpa.ctfguard.enforce":false,"hmpa.ctfguard.silent":true,"hmpa.heapheaphooray.enforce":false,"hmpa.heapheaphooray.silent":true,"hmpa.heapheaphooray.v2.enforce":false,"hmpa.heapheaphooray.v2.silent":false,"hmpa.lockdownautorun.v2.enforce":false,"hmpa.lockdownmemory.v2.enforce":false,"hmpa.lockdownmemory.v2.silent":true,"ips.available":false,"ips.filter.inbound":false,"ips.filter.outbound":false,"livequery.network-tables.available":true,"mcs.push.available":true,"mlwindowsdir.available":true,"pinnedglobalreplocal.available":true,"pinnedglobalrepnetwork.available":true,"repair.available":false,"sed.tp2020.available":true,"ssp.instant-core-clean-items.available":true,"ssp.static.postanalysis.available":true,"su-setup.available":true,"vdldetections.available":true},"preferredServer":{"server":"mcs-cloudstation-eu-central-1.prod.hydra.sophos.com","viaProxy":false,"viaMessageRelay":false,"authScheme":0},"pushServer":{"server":"mcs-push-server-eu-central-1.prod.hydra.sophos.com","isConnected":false}}}
    2020-11-23T15:05:31.466Z [ 3076: 3588] [v4.12.686.0] INFO  [backoff] waiting 128s (110s + 18s skew) after failures: 1
    2020-11-23T15:07:39.651Z [ 3076: 3588] [v4.12.686.0] INFO  [connect] trying server https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com/sophos/management/ep
    2020-11-23T15:07:39.652Z [ 3076: 3588] [v4.12.686.0] INFO  [connect] trying direct connection without a proxy
    2020-11-23T15:07:39.652Z [ 3076: 3588] [v4.12.686.0] INFO  GET https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep
    2020-11-23T15:07:39.698Z [ 3076: 3588] [v4.12.686.0] INFO  200 : sent=0 rcvd=168 elapsed=45ms
    2020-11-23T15:07:39.698Z [ 3076: 3588] [v4.12.686.0] INFO  [connect] using server https://mcs-cloudstation-eu-central-1.prod.hydra.sophos.com/sophos/management/ep without a proxy (peer address 3.120.49.45)
    

    I re-checked my answer from above: "there are some days without these 8001 events in event log, not only weekends, and the next day again a dozend or more"

    It looks like the issue does mostly not happen on weekends.

  • 2020-11-23T16:49:19.158Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f7
    2020-11-23T16:49:19.208Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=48ms
    2020-11-23T16:50:14.209Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:50:14.299Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=94ms
    2020-11-23T16:51:09.309Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:51:09.359Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=54ms
    2020-11-23T16:52:04.370Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:52:04.480Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=106ms
    2020-11-23T16:52:59.480Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:52:59.530Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=50ms
    2020-11-23T16:53:54.540Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:53:54.630Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=92ms
    2020-11-23T16:54:49.640Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:54:49.700Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=60ms
    2020-11-23T16:55:44.710Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:55:44.810Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=97ms
    2020-11-23T16:56:39.810Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:56:39.860Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=51ms
    2020-11-23T16:57:34.872Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:57:34.942Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=65ms
    2020-11-23T16:58:29.946Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:58:29.996Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=46ms
    2020-11-23T16:59:24.999Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T16:59:25.049Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=53ms
    2020-11-23T17:00:20.063Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T17:00:41.385Z [ 4016: 3356] [v4.12.686.0] ERROR Request: WinHttpReceiveResponse failed: 12002 (mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443)
    2020-11-23T17:00:41.385Z [ 4016: 3356] [v4.12.686.0] INFO  Dropping connection after error
    2020-11-23T17:00:41.385Z [ 4016: 3356] [v4.12.686.0] INFO  [backoff] waiting 189s (110s + 79s skew) after failures: 1
    2020-11-23T17:03:50.631Z [ 4016: 3356] [v4.12.686.0] INFO  [connect] trying server https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com/sophos/management/ep
    2020-11-23T17:03:50.631Z [ 4016: 3356] [v4.12.686.0] INFO  [connect] trying direct connection without a proxy
    2020-11-23T17:03:50.631Z [ 4016: 3356] [v4.12.686.0] INFO  failed to set WinHttp TCP timeout: error=12009
    2020-11-23T17:03:50.631Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep
    2020-11-23T17:03:50.781Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=168 elapsed=141ms
    2020-11-23T17:03:50.781Z [ 4016: 3356] [v4.12.686.0] INFO  [connect] using server https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com/sophos/management/ep without a proxy (peer address 3.124.143.82)
    2020-11-23T17:03:50.781Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T17:03:50.841Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=56ms
    2020-11-23T17:04:45.852Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T17:04:45.902Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=47ms
    2020-11-23T17:05:40.903Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T17:05:40.943Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=39ms
    2020-11-23T17:06:35.955Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T17:06:35.985Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=34ms
    2020-11-23T17:07:30.995Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T17:07:31.035Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=39ms
    2020-11-23T17:08:26.036Z [ 4016: 3356] [v4.12.686.0] INFO  GET https://mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com:443/sophos/management/ep/commands/applications/ALC;CORC;CORE;EFW;HBT;HMPA;LiveTerminal;MCS;NTP;SAV;SDU;SHS;SWC;UI;APPSPROXY/endpoint/c2c8f71b
    2020-11-23T17:08:26.076Z [ 4016: 3356] [v4.12.686.0] INFO  200 : sent=0 rcvd=140 elapsed=43ms

    We have similar issue, both with company LAN and domestic WiFi.

    Is it normal?

  • Hi, I closed the ticket with Sophos. Very slow and superficial support. They blame our corporate network, for me it's the Sophos servers that have some problems. However it is a sporadic issue.
  • Hi,

    the Error is not at overnight at my logs. This is a sophos problem.