This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Parent SUM not updating child SUMs

Hello - 

We have four Sophos servers on prem.  One parent SEC and three child SUMs.  The parent SEC gets updates from Sophos and the child SUMs update from the parent.  The SEC and SUMs are configured to use WebCIDs for updating.  This has been the configuration for our Sophos environment for the last 10 years.  All of the necessary ports on the SEC's firewall have been configured correctly.  On August 24, 2021, the child SUMs stopped getting updates from the parent SEC.

If I turn off the host firewall on our SEC, the child SUMs update successfully.  When the host firewall on SEC is on, the child SUMs can no longer receive updates from the SEC.  AFAIK, no changes have been made on the SEC or SUMs.  Most of the firewall exceptions have been pushed to the SEC and SUMs via group policy. 

I have an opened support request with Sophos and we are unable to solve the issue after a couple of Zoom sessions.

I guess the work around will have to do for now, which is turning off the firewall on the SEC.



This thread was automatically locked due to age.
Parents
  • Hello dluneau,

    there has been a change, I'm pretty sure that SUM has updated to 1.7.2.that day. The article makes no mention of significant changes in the updating mechanism.
    You publish the WebCID over HTTPS using IIS? Firewall logs would be the first place to look but with the on-beard firewall it's, not a, hm gratifying exercise. Perhaps the SUMTrace log (on the childs) has some useful information.

    Christian

  • Hi QC,

    Yes.  SUM 1.7.2 is the current version installed.  I publish the WebCID over HTTP using IIS.  I will grab the SUMTrace log from one of the child SUMs.  Perhaps there would be a particular section of the log that would be helpful?

    Thank you

  • FormerMember
    0 FormerMember in reply to dluneau

    is the https certificate self-signed? Signed by your internal CA? What happens if you nav to the webcid from one of the child sums? Do you see a cert warning pop-up in the browser?

Reply Children