This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Deploying Sophos Across Slow Link to Individual Clients

Hello,

I have completed a quick search of the forum but could not find any answers that may fix my problem.  If there is already an answer then please accept my apologies.

I have a SEC 4.5 installation at a London site which services all my clients both locally and remotely.  Some of my remote clients connect over very slow links and there is no local infrastructure where my clients are and generally there is only one client in a particular location.

I was hoping to send/post a CD with the latest installation of Sophos 9.5 so a local installation could be completed without the need for the slow link and then when this was completed I could access the SEC and then 'Protect' the client computer from then on with my London SEC server.

I contacted Sophos support and the very helpful guy from Sophos put me onto the steps found in knowledgebase article 67504 which can be found at the following link;

http://www.sophos.com/support/knowledgebase/article/67504.html

I followed these steps and successfully installed a local version of Sophos which worked well.  When the client was disconnected it complained it could not update itself and when the comms was back online, the local Sophos install happily reported the last check for updates : date and time etc.

But... when I looked in SEC, the client appeared grey and unmanaged.  I attempted to place the client in a managed group and cancelled the installation hoping this may prompt the client to talk back to SEC but this did not work.  I then right clicked the client in SEC and selected 'protect' but my guess is this will attempt to download and install Sophos from scratch which defeats the object of the CD deployment in the first place.

So my question is...

Can I use a CD to deploy Sophos and then configure the managed/protected connection within SEC without having to initiate a complete install of Sophos?

Sorry for the length of my question, I just wanted to give as much information about my scenario as possible. 

Thanks in advance for your help.

:11613


This thread was automatically locked due to age.
  • HI,

    What sort of network connection do these remote clients have to the SEC management server?  Do they connect to a VPN, or are they reliant purely on web based services via the Internet?

    There are a few options in terms of updating interms of CID distribution and minor updates thereafter in either scenario as for management using RMS this can get quite complicated depending on the network infrastructure if not using VPN.


    Regards,
    Jak 

    :11617
  • Buzz, I created a standalone installer that sets update path as per an update policy on the server using article 67504 as a basis. I changed the command line (SFX options) as such...

    ;The comment below contains SFX script commands

    Path=:%SystemRoot%\Temp\savinst
    SavePath
    Setup=SAVSCFXP\setup.exe -mng yes -updp %SystemRoot%\Temp\savinst\SAVSCFXPXML\
    Silent=1
    Overwrite=1

    HTH!
    John

    :11663
  • @KnollJRH

    Thanks for your reply.  I changed the -mng option to yes as per your suggestion.  I also used the -G switch to specify the SEC group that the clients are located in and the installation works well.  I can now deploy Sophos via CD using the policies from the SEC server.  It did take a couple of hours for the clients to register themselves within SEC but the management connection did work eventually. 

    Thanks for your assistance.

    Buzz.

    :12865