This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot deploy Sophos protection to trusted domain

I'm a new Sophos customer and I have a new installation of Sophos Endpoint protection server.  I successfully installed Sophos protection to all my domain1.com computers.  I have a domain2.com that I am trying to deploy it to as well. 

I have a two way trust setup.  I have synchronized the domain with the console.  When I try to protect the computers I get:

   Installation failed                     Date/time                Code      Description                            

                                           12/20/2016 9:23:45 AM    0000002e  The installation could not be started. The computer may need additional configuration before installation. See article 29287.

 

Firewall is turned off

On PC: Service - Task Scheduler (Started), Service - Windows Installer (not Disabled), Service - Remote Registry (Started)

On Enterprise server:Firewall is turned off, Service - Remote Registry (Started)

 

I've ensured a nslookup of the Desktop PC from my SEC server matches the ipconfig result on the Desktop PC.

I can go to \\<SophosServerName>\SophosUpdate from the Desktop PC, it doesn't prompt for credentials

C:\ProgramData\Sophos\Update Manager\Update Manager folder (default location) is shared and the group 'Everyone' has read access.  Ensured these accounts are there with full control permission: SYSTEM, NETWORK SERVICE

From the endpoint computer I can open the central share in Windows Explorer (Start | Run | Type: \\<servername>\SophosUpdate\)

Created and ran a scheduled task on remote PC.

 

 

I have a support ticket but have not gotten anywhere with that.  Any Sophos users have an idea of what to check?  Does Sophos deploy to the computer as Computer.domain2.com?  or just computer?  Where are the logs on the server to see what the issue is?

 



This thread was automatically locked due to age.
Parents
  • Error 29287 refers to being unable to being unable to find the network path ( https://community.sophos.com/kb/en-us/29287 )

    Are you using the FQDN in the deployment and server name?

    ie avserver.domain1.com

    Just using avserver would work on the domain1.com domain but not domain2.com

    the other option or hack might be to create a DNS record in domain2.com with the same server name and point it to the IP of the server in domain1.

    Regards,
    Bohdan

  • Hello April Beachy and Bohdan.S,

    if I understand 's post correctly the share can be accessed using the server's NetBIOS name. If the server can't resolve the endpoints name as it appears in the console the symptom will be the same. When you did the nslookup of the Desktop PC from my SEC server did you use this name or did you qualify it? Did you try SCHTASKS /Create /S domain2computer from your SEC server?

    Christian

Reply
  • Hello April Beachy and Bohdan.S,

    if I understand 's post correctly the share can be accessed using the server's NetBIOS name. If the server can't resolve the endpoints name as it appears in the console the symptom will be the same. When you did the nslookup of the Desktop PC from my SEC server did you use this name or did you qualify it? Did you try SCHTASKS /Create /S domain2computer from your SEC server?

    Christian

Children
No Data