<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Sophos Enterprise Console Server Not listening on 8194 so clients are reporting as offline</title><link>https://community.sophos.com/on-premise-endpoint/f/sophos-enterprise-console/122777/sophos-enterprise-console-server-not-listening-on-8194-so-clients-are-reporting-as-offline</link><description>Hello All 
 
 Since attempting to upgrade our customers pre-production Sophos 5.5.1 SEC, SUM and DB to 5.5.2 Ive been having no end of problems. Following been finally able to access the SEC via the creation of the IORSenderPort registry key and the unticking</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Sophos Enterprise Console Server Not listening on 8194 so clients are reporting as offline</title><link>https://community.sophos.com/thread/446764?ContentTypeID=1</link><pubDate>Thu, 10 Sep 2020 11:15:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5606ea4d-7bc2-47ae-a487-ef0ff5035716</guid><dc:creator>QC</dc:creator><description>&lt;p&gt;Hello &lt;span class="field-item-name label"&gt;SimpleTechie&lt;/span&gt;,&lt;/p&gt;
&lt;p&gt;&lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup"&gt;&lt;span class="uiOutputText" dir="ltr"&gt;&lt;span style="color:#008000;"&gt;&lt;em&gt;the best course of action right now would be to wipe everything completely and reinstall&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;while one can learn quite a lot by trying to get this right an install from scratch isn&amp;#39;t a bad idea. Wonder how CM could have &lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup" style="font-family:courier new, courier;"&gt;[Msgr:RM]Logged on to Message Router&lt;/span&gt; when the Router isn&amp;#39;t listening on 8194. And normally RouterNT should listen on ports 8192-8194 (and no other). Just for completeness - several management processes establish loopback (127.0.0.1) connections, both intra- and interprocess, on ephemeral ports.&lt;/p&gt;
&lt;p&gt;Christian&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos Enterprise Console Server Not listening on 8194 so clients are reporting as offline</title><link>https://community.sophos.com/thread/446742?ContentTypeID=1</link><pubDate>Thu, 10 Sep 2020 08:44:35 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0dcd3719-bead-43ef-9120-382a9dd5500b</guid><dc:creator>SimpleTechie</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;Thank you for the advise I had alook at the CertificationManager logs and the Router logs on the SEC but find anything of use, while the errors are occurring on the child SUM all the time that last update on the SEC&amp;nbsp;CertificationManager LOG is 08/09&lt;br /&gt;&lt;br /&gt;26.08.2020 12:44:49 09D0 I SOF: C:\ProgramData/Sophos/Remote Management System/3/CertificationManager/Logs/CertManager-20200826-114449.log&lt;br /&gt;26.08.2020 12:44:49 09D0 I [CertMgr]Certification Manager starting...&lt;br /&gt;26.08.2020 12:44:52 09D0 I [CertMgr]Certification Manager started&lt;br /&gt;26.08.2020 12:44:52 09D0 I [CertMgr]Enabling request processing&lt;br /&gt;26.08.2020 12:44:52 0A14 I InitialiseClientLibraryLocal CM, SOFTWARE\Sophos\Certification Manager\MessengerStore, CMConfig.reg, 0, ... &lt;br /&gt;26.08.2020 12:44:53 0A14 I Initializing ...&lt;br /&gt;26.08.2020 12:44:53 0A14 I [Msgr:RM]Logged on to Message Router&lt;br /&gt;08.09.2020 08:28:10 0A14 I [Msgr:RM]Lost session with Message Router:err=system exception, ID &amp;#39;IDL:omg.org/CORBA/TRANSIENT:1.0&amp;#39;&lt;br /&gt;OMG minor code (2), described as &amp;#39;*unknown description*&amp;#39;, completed = NO&lt;br /&gt;08.09.2020 08:28:12 0A14 N [Msgr:RM]Logged off Message Router&lt;br /&gt;08.09.2020 08:28:17 0A14 I Initializing ...&lt;br /&gt;08.09.2020 08:28:17 0A14 I [Msgr:RM]Logged on to Message Router&lt;br /&gt;08.09.2020 16:28:53 0A14 I [Msgr:RM]Lost session with Message Router:err=system exception, ID &amp;#39;IDL:omg.org/CORBA/TRANSIENT:1.0&amp;#39;&lt;br /&gt;OMG minor code (2), described as &amp;#39;*unknown description*&amp;#39;, completed = NO&lt;br /&gt;08.09.2020 16:28:55 0A14 N [Msgr:RM]Logged off Message Router&lt;br /&gt;08.09.2020 16:29:00 0A14 I Initializing ...&lt;br /&gt;08.09.2020 16:29:01 0A14 I [Msgr:RM]Logged on to Message Router&lt;br /&gt;08.09.2020 16:40:33 0A14 I [Msgr:RM]Lost session with Message Router:err=system exception, ID &amp;#39;IDL:omg.org/CORBA/TRANSIENT:1.0&amp;#39;&lt;br /&gt;OMG minor code (2), described as &amp;#39;*unknown description*&amp;#39;, completed = NO&lt;br /&gt;08.09.2020 16:40:35 0A14 N [Msgr:RM]Logged off Message Router&lt;br /&gt;08.09.2020 16:40:40 0A14 I Initializing ...&lt;br /&gt;08.09.2020 16:40:41 0A14 I [Msgr:RM]Logged on to Message Router&lt;/p&gt;
&lt;p&gt;The Router log on the SEC isn&amp;#39;t showing an issues either and the RouterNT.exe service really does look to be only listening on 1 port wehich seems strange.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/16/pastedimage1599725869338v1.png"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/16/pastedimage1599725869338v1.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Im trying to query our teams on how this was all setup, from what I can see and looking at their production environment the child SUM would pull updates from the SEC.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Looking at the&amp;nbsp;mrinit from the SUM that would have been pulled from the SEC when it could connect which I presume was before the upgrade the ports differ to the&amp;nbsp;mrinit on the SEC and the&amp;nbsp;mrinit&amp;nbsp; on a client appears to match the SUM one rather than the SEC one&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;SEC&amp;nbsp;mrinit&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Sophos\Update Manager\CIDS\S000\SAVSCFXP&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&amp;quot;ClientIIOPPort&amp;quot;=dword:00002001&lt;br /&gt;&amp;quot;ClientSSLPort&amp;quot;=dword:00002002&lt;br /&gt;&amp;quot;ClientIORPort&amp;quot;=dword:00002000&lt;br /&gt;&amp;quot;MRParentAddress&amp;quot;=&amp;quot;&amp;#39;SEC IP&amp;#39;,&amp;#39;SEC FQDN,&amp;#39;SEC HOSTNAME&amp;#39;&amp;quot;&lt;br /&gt;&amp;quot;ParentRouterAddress&amp;quot;=&amp;quot;&amp;#39;SEC IP&amp;#39;,&amp;#39;SEC FQDN,&amp;#39;SEC HOSTNAME&amp;#39;&amp;quot;&lt;/p&gt;
&lt;p&gt;00002001 - 8193&lt;br /&gt;00002002 - 8194&lt;br /&gt;00002000 - 8192&lt;/p&gt;
&lt;p&gt;SUM&amp;nbsp;mrinit (Appears to be before the upgrade:&lt;/p&gt;
&lt;p&gt;Sophos\Update Manager\CIDS\S000\SAVSCFXP&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&amp;quot;ClientIIOPPort&amp;quot;=dword:00002001&lt;br /&gt;&amp;quot;ClientSSLPort&amp;quot;=dword:00001FFE&lt;br /&gt;&amp;quot;ClientIORPort&amp;quot;=dword:00002000&lt;br /&gt;&amp;quot;IORSenderPort&amp;quot;=dword:00002000&lt;br /&gt;&amp;quot;MRParentAddress&amp;quot;=&amp;quot;&amp;#39;SEC IP&amp;#39;,&amp;#39;SEC FQDN,&amp;#39;SEC HOSTNAME&amp;#39;&amp;quot;&lt;br /&gt;&amp;quot;MRParentAddress&amp;quot;=&amp;quot;&amp;#39;SEC IP&amp;#39;,&amp;#39;SEC FQDN,&amp;#39;SEC HOSTNAME&amp;#39;&amp;quot;&lt;/p&gt;
&lt;p&gt;00002001 - 8193&lt;br /&gt;00002002 - 8190&lt;br /&gt;00002000 - 8192&lt;/p&gt;
&lt;p&gt;Client side&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&amp;quot;ClientIIOPPort&amp;quot;=dword:00002001&lt;br /&gt;&amp;quot;ClientSSLPort&amp;quot;=dword:00001FFE&lt;br /&gt;&amp;quot;ClientIORPort&amp;quot;=dword:00002000&lt;br /&gt;&amp;quot;IORSenderPort&amp;quot;=dword:00002000&lt;br /&gt;&amp;quot;MRParentAddress&amp;quot;=&amp;quot;1&amp;#39;SEC IP&amp;#39;,&amp;#39;SEC FQDN,&amp;#39;SEC HOSTNAME&amp;#39;&amp;quot;&lt;br /&gt;&amp;quot;ParentRouterAddress&amp;quot;=&amp;quot;&amp;#39;SUM IP&amp;#39;,&amp;#39;SUM FQDN,&amp;#39;SUM HOSTNAME&amp;#39;&amp;quot;&lt;/p&gt;
&lt;p&gt;00002001 - 8193&lt;br /&gt;00002002 - 8190&lt;br /&gt;00002000 - 8192&lt;/p&gt;
&lt;p&gt;It does seem that maybe&amp;nbsp;8190 was been used instead of&amp;nbsp;8194 but as the RouterNT.exe isn&amp;#39;t even listening on 8194 Im guessing that the focus point to start with and it Im not sure on how to get it to start listening on that port.&lt;/p&gt;
&lt;p&gt;Also I was able to compareHKLM&amp;gt;SOFTWARE&amp;gt;WOW6432Node&amp;gt;Sophos&amp;gt;Message System&amp;gt;Router on the Pre-Prod SEC (The one having the issue) and our customers Production SEC (WOrking and not connecting to Pre-Prod) and there are many registry keys present in production that are not in pre-prod:&lt;/p&gt;
&lt;p&gt;&lt;span class="uiOutputText" dir="ltr"&gt;Not in pre-prod&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="uiOutputText" dir="ltr"&gt;ConnectRetriesPause&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;GetterInterval&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;GetterShortInterval&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;HostIPToParent&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;LegacyProtocolSupport&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;NotifyClientUpdate&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;NumNotificationThresholdThreads&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;ServiceArgs&lt;br /&gt;&lt;/span&gt;&lt;span class="uiOutputText" dir="ltr"&gt;TotalConnectRetryTimeSecs&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="uiOutputText" dir="ltr"&gt;I have Support involved but Im wondering if the best course of action right now would be to wipe everything completely and reinstall the SEC and SUM afresh.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Sophos Enterprise Console Server Not listening on 8194 so clients are reporting as offline</title><link>https://community.sophos.com/thread/446643?ContentTypeID=1</link><pubDate>Wed, 09 Sep 2020 12:04:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:12e66ca4-0a37-4a43-92bb-e636b1ec1223</guid><dc:creator>QC</dc:creator><description>&lt;p&gt;Hello &lt;span class="field-item-name label"&gt;SimpleTechie&lt;/span&gt;,&lt;/p&gt;
&lt;p&gt;there seems to be a lot of things that aren&amp;#39;t correct.&lt;/p&gt;
&lt;p&gt;Question: &lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup"&gt;&lt;span style="color:#008000;"&gt;&lt;em&gt; client lookings to be pointing to the SUM rather than SEC&lt;/em&gt;&lt;/span&gt; - so there is a &amp;quot;child&amp;quot; SUM in addition to the SEC server, why, what is the intended setup? All endpoints updating from a share/WebCID on the SUM instead of the SEC, and endpoints should communicate via the SUM, i.e. it is set up as a message relay?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup"&gt;Anyway, the SUM should be able to communicate with the SEC. Apparently the SUM gets a valid IOR when using the HOSTNAME but neither with the IP nor the FQDN. This is a little bit strange and suggests that the &lt;em&gt;MRParentAddress&lt;/em&gt; values in &lt;span style="font-family:courier new, courier;"&gt;mrinit.conf&lt;/span&gt; are not ideal (from the SUM&amp;#39;s POV).&lt;br /&gt;There&amp;#39;s a delay of 40 seconds after the &lt;em&gt;Getting a new router certificate&lt;/em&gt;. Not sure if this is a timeout. Please check the Router and the CertificationManager logs on the SEC server, they should give some insight what&amp;#39;s going on.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup"&gt;As the (apparent) message relay does not have a certificate its router is not in a state to commence communication, therefore the endpoints are unable to connect to the SUM&amp;#39;s Router. BTW: They similarly fail to obtain an IOR using IP or FQDN. &lt;br /&gt;Someone must have deliberately change the port to 8190 for whatever reason, either by means of &lt;span style="font-family:courier new, courier;"&gt;mrinit.conf&lt;/span&gt; or &amp;quot;manually&amp;quot; by modifying the registry keys.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="field-item-description user-defined-markup"&gt;Last but not least: RouterNT.exe should listen on 8192-8194 (unless someone has modified the ports but anyway should be three).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup"&gt;Christian&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>