This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot deploy Sophos protection to trusted domain

I'm a new Sophos customer and I have a new installation of Sophos Endpoint protection server.  I successfully installed Sophos protection to all my domain1.com computers.  I have a domain2.com that I am trying to deploy it to as well. 

I have a two way trust setup.  I have synchronized the domain with the console.  When I try to protect the computers I get:

   Installation failed                     Date/time                Code      Description                            

                                           12/20/2016 9:23:45 AM    0000002e  The installation could not be started. The computer may need additional configuration before installation. See article 29287.

 

Firewall is turned off

On PC: Service - Task Scheduler (Started), Service - Windows Installer (not Disabled), Service - Remote Registry (Started)

On Enterprise server:Firewall is turned off, Service - Remote Registry (Started)

 

I've ensured a nslookup of the Desktop PC from my SEC server matches the ipconfig result on the Desktop PC.

I can go to \\<SophosServerName>\SophosUpdate from the Desktop PC, it doesn't prompt for credentials

C:\ProgramData\Sophos\Update Manager\Update Manager folder (default location) is shared and the group 'Everyone' has read access.  Ensured these accounts are there with full control permission: SYSTEM, NETWORK SERVICE

From the endpoint computer I can open the central share in Windows Explorer (Start | Run | Type: \\<servername>\SophosUpdate\)

Created and ran a scheduled task on remote PC.

 

 

I have a support ticket but have not gotten anywhere with that.  Any Sophos users have an idea of what to check?  Does Sophos deploy to the computer as Computer.domain2.com?  or just computer?  Where are the logs on the server to see what the issue is?

 



This thread was automatically locked due to age.
Parents
  • Ran into this problem today, the enterprise console would discover the machines when given an IP range but then would fail to deploy to all machines in domain2.com.

     

    Resolution for me was to two fold, the first was on the management server to modify the network adapter DNS search suffix to change to:

    domain1.com

    domain2.com

     

    I was then able to resolve all machines in domain2.com using just their NetBIOS name from the management server.

    This left the requirement for resolution of the management server from all the clients in domain2.com, as the management server had a unique name that was not present in domain2 I added a DNS A record for the server name into domain2 DNS zone. This meant all clients on domain2.com would resolve the FQDN via the DNS conditional forwarder for domain1.com and the NetBIOS name would resolve through domain2 DNS.

     

    This won't help if you have the management server name for 2 different servers in their respective domains but worked for my situation. Hope it helps.

Reply
  • Ran into this problem today, the enterprise console would discover the machines when given an IP range but then would fail to deploy to all machines in domain2.com.

     

    Resolution for me was to two fold, the first was on the management server to modify the network adapter DNS search suffix to change to:

    domain1.com

    domain2.com

     

    I was then able to resolve all machines in domain2.com using just their NetBIOS name from the management server.

    This left the requirement for resolution of the management server from all the clients in domain2.com, as the management server had a unique name that was not present in domain2 I added a DNS A record for the server name into domain2 DNS zone. This meant all clients on domain2.com would resolve the FQDN via the DNS conditional forwarder for domain1.com and the NetBIOS name would resolve through domain2 DNS.

     

    This won't help if you have the management server name for 2 different servers in their respective domains but worked for my situation. Hope it helps.

Children
No Data