Hello,
I've found a few posts with this same exact issue, however none of the fix actions have worked for me.
I'm attempting to get Endpoint protection working from my UTM (SG430's in HA), I successfully downloaded and installed the client, however at the end of the install it mentions it's not able to communicate with the registration server first red flag there.
After installation, if I try to force a manual update, it will give me an error that says "Could not contact server". Within the not so very descriptive log, this is the error I get.
Time: 4/4/2018 12:31:53
Message: ERROR: Download of Endpoint Security and Control failed from server Sophos
Module: Update
Process ID: 16792
Thread ID: 16512
I've seen on the forums that you need to test to see if the website is accessible, so I checked and I can browse directly to the site, I'm prompted with "Connection successful"
When I ran a wireshark, I noticed this.
Transmission Control Protocol, Src Port: 51976, Dst Port: 80, Seq: 1446, Ack: 2081, Len: 0
Source Port: 51976
Destination Port: 80
[Stream index: 146]
[TCP Segment Len: 0]
Sequence number: 1446 (relative sequence number)
Acknowledgment number: 2081 (relative ack number)
0101 .... = Header Length: 20 bytes (5)
Flags: 0x014 (RST, ACK)
000. .... .... = Reserved: Not set
...0 .... .... = Nonce: Not set
.... 0... .... = Congestion Window Reduced (CWR): Not set
.... .0.. .... = ECN-Echo: Not set
.... ..0. .... = Urgent: Not set
.... ...1 .... = Acknowledgment: Set
.... .... 0... = Push: Not set
.... .... .1.. = Reset: Set
[Expert Info (Warning/Sequence): Connection reset (RST)]
.... .... ..0. = Syn: Not set
.... .... ...0 = Fin: Not set
[TCP Flags: ·······A·R··]
Window size value: 0
[Calculated window size: 0]
[Window size scaling factor: 256]
Checksum: 0x5ee0 [unverified]
[Checksum Status: Unverified]
Urgent pointer: 0
It's a connection reset. So I went to look at what the request was for the server.
Hypertext Transfer Protocol
GET /cloudupdate/0/2d/02d3d1ce06efdb1ef6e967ba31eafe71.dat HTTP/1.1\r\n
I tried to browse directly to the server, with that update in the URL dci.sophosupd.com/cloudupdate/0/2d/02d3d1ce06efdb1ef6e967ba31eafe71.dat
And I'm hit with a not found.
I don't know where to go to download this .dat file, but these are default settings that I've applied here. Nothing is out of the ordinary on my network. How can this program be requesting updates from a server that doesn't even have the right updates, by default?
If there's some quick turnkey thing I'm missing please let me know, any help is greatly appreciated.
This thread was automatically locked due to age.