This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

how to allow the "sophos" update server from the corporate firewall?

just incase the UNC will fail, clients will still  be able to update directly to sophos servers. TIA

:11519


This thread was automatically locked due to age.
  • HI,

    You have a couple of options:

    1. Host a web CID yourself using a webserver.  So in effect you would set the primary in the updating policy to be \\<server>\.... and the secondary location to be http://yourweb/ which is resolvable and accessible over the internet.

    2. Use Sophos as the secondary location.  So you would configure the primary to be:
     \\<server>\... and the secondary to be Sophos.

    Using your own webserver to host the secondary location is really if you want to control the version the clients download more closely (fixed packages).

    Regards,

    Jak

    :11529
  • As I understand the terse post it's about allowing connections from the clients to the Sophos servers through the corporate firewall. You'll find the name that is used in [%ProgramFiles%|%ProgramData%]Sophos\AutoUpdate\Config\iconn.cfg. Usually it is es-web-2.sophos.com and resolves to several addresses. You should check both name and addresses if you encounter an error as they might change.

    Christian

    :11553