This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Changing IP address on Sophos Enterprise Console 4.5?

Hi folks,

I run two Sophos Enterprise Consoles for a university department. One is a 3.0 console with a few hundred clients, while the other is a freshly installed 4.5 console with only a test client.

Due to the unique network security environment in this department (all computers are on a private network, as they are connected to scientific instruments and should not be connected to the outside world), only a single IP-based exception was made in the firewall so that the clients can communicate with the console (which is located outside of the private network). Presently, the 3.0 console uses the IP with the exception. Allowing a second outside IP address (e.g. the second console) to connect to the network is infeasible for numerous reasons. The server for the 3.0 console is also in dire need of replacement, so upgrading it to 4.5 in-place is not an option either.

My intention is to configure the 4.5 console with the same groups, policies, etc. as the 3.0 console, only on a separate computer with a different IP address, then replace the 3.0 console with the 4.5 console by changing their respective IP addresses. Naturally, any certificates needed to authenticate with clients would be copied over to the appropriate places on the 4.5 console so clients could communicate with the 4.5 console.

Unfortunately, when I did a dry run using virtual machines, the 4.5 console didn't like having its IP address changed. The management console GUI couldn't connect to the management service running on the same system. Unfortunately, I've found no information on this topic on the Sophos website, nor any information in the help files. The backend of the Enterprise Console seems to be a dark, mysterious place and it's not obvious how to make these changes.

Does anyone have any tips or tricks to making this transition work? I realize that my particular setup is not exactly a common task, but surely there's some mechanism to change a console's IP address without everything dying horribly.

:5047


This thread was automatically locked due to age.
Parents
  • I need to re-deploy the clients

    This should not be necessary as the clients should "talk" to the management server and therefore - as I said - receive the new updating policies and upgrade automatically.

    Christian

    :5092
Reply
  • I need to re-deploy the clients

    This should not be necessary as the clients should "talk" to the management server and therefore - as I said - receive the new updating policies and upgrade automatically.

    Christian

    :5092
Children
No Data