This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot deploy Sophos protection to trusted domain

I'm a new Sophos customer and I have a new installation of Sophos Endpoint protection server.  I successfully installed Sophos protection to all my domain1.com computers.  I have a domain2.com that I am trying to deploy it to as well. 

I have a two way trust setup.  I have synchronized the domain with the console.  When I try to protect the computers I get:

   Installation failed                     Date/time                Code      Description                            

                                           12/20/2016 9:23:45 AM    0000002e  The installation could not be started. The computer may need additional configuration before installation. See article 29287.

 

Firewall is turned off

On PC: Service - Task Scheduler (Started), Service - Windows Installer (not Disabled), Service - Remote Registry (Started)

On Enterprise server:Firewall is turned off, Service - Remote Registry (Started)

 

I've ensured a nslookup of the Desktop PC from my SEC server matches the ipconfig result on the Desktop PC.

I can go to \\<SophosServerName>\SophosUpdate from the Desktop PC, it doesn't prompt for credentials

C:\ProgramData\Sophos\Update Manager\Update Manager folder (default location) is shared and the group 'Everyone' has read access.  Ensured these accounts are there with full control permission: SYSTEM, NETWORK SERVICE

From the endpoint computer I can open the central share in Windows Explorer (Start | Run | Type: \\<servername>\SophosUpdate\)

Created and ran a scheduled task on remote PC.

 

 

I have a support ticket but have not gotten anywhere with that.  Any Sophos users have an idea of what to check?  Does Sophos deploy to the computer as Computer.domain2.com?  or just computer?  Where are the logs on the server to see what the issue is?

 



This thread was automatically locked due to age.
Parents
  • I could never get the Sophos system to use the fully qualified domain names so we created a GPO that added both Domains to the DNS settings for computers from Domain2.  Not how I wanted to manipulate the domains, but it worked.

     

    Any hints on how to get better response from Sophos support?  I have a ticket, the support tech is sick and no one else would talk to me.  On multiple issues and multiple calls we could not even get a support tech to remote into the system to take a look.  Is there a Gold support?  Was considering buying more Sophos products, but their support is enough to make me pay twice as much for a competitor's system.

     

     

     

Reply
  • I could never get the Sophos system to use the fully qualified domain names so we created a GPO that added both Domains to the DNS settings for computers from Domain2.  Not how I wanted to manipulate the domains, but it worked.

     

    Any hints on how to get better response from Sophos support?  I have a ticket, the support tech is sick and no one else would talk to me.  On multiple issues and multiple calls we could not even get a support tech to remote into the system to take a look.  Is there a Gold support?  Was considering buying more Sophos products, but their support is enough to make me pay twice as much for a competitor's system.

     

     

     

Children
No Data