We are running SEC 5.2.2 and two Message Relay Servers with SophosAV 10.6. All SEC clients are Windows 2012R2 Servers, including SEC and MRS.
One MRS is set up in a different Domain than the SEC Server.
On this MRS enviroment/domain we get those 1326 and 86 windows errors, which say, that SophosUpdate share can not be reached due to authentication failure.
Share permissions on MRS are checkt and OK.
Update user is a domain user - credentials are checked with net use against the update share and are OK
Update Policy is checked and OK. Reentered User und Password into Update Policy just, just in case..
On the Eventlog\security\ on the MRS I can see, that the problem-clients are trying to connect to the SophosUpdate share with their local SophosSAU<Hostname> user account. Event: Audit Failed
In the ALUpdate-Log on the clients is the correct SophosUpdate user shown.
The only machines in this domain which get updates are the two domain controlers, which seem to use their domain\SophosSAU<hostname> user accounts, and the MRS itself, which seem to use its local SophosSAU<hostname> user with success.
Why is Sophos AutoUpdate using this SophosSAU<hostname> user instead of the Sophos Update user from the policy? Where can this be fixed? Anybody seen this before?
regards
Joerg
This thread was automatically locked due to age.