This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Moving clients to a new server with A NEW name from a 2003 server to 2012

we want to move from our Sophos enterprise console to another machine this will have a new Name

the old one must keep running until we have all the clients moved to the new server ID DONT WANT THE HISTORY we want to start again!

Installed the new server as per the KB articles

All seemed well but the clients seem to have an issue, I deployed the client from the new console Over the top of the old managed server client it reinstalled but came back with this error

 

   Sophos AutoUpdate status                Date/time            Code      Description                            
                                           17/01/2017 11:56:44  0000006b  Download of Sophos Endpoint Defense failed from server \\NEW SERVER\SophosUpdate\CIDs\S000\SAVSCFXP\

If I uninstall the Sophos Av from the client and remove all reg entries and left over dll files then deploy from the new server I do not get this error it works ok !

help would be appreciated I tried goggling the description error but haven't found anything useful

so its just How to redirect windows endpoints to a new server

I followed this KB even trying the scripted routes but it still fails with the same error



This thread was automatically locked due to age.
  • this is the log file from the client

     

     

    Time: 17/01/2017 13:17:40
    Message: AutoUpdate finished
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:39
    Message: Installation of Sophos System Protection skipped
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:39
    Message: Installation of Sophos AutoUpdate skipped
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:39
    Message: Installation of Sophos Network Threat Protection skipped
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:39
    Message: Installation of SAVXP skipped
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:38
    Message: Installation of RMSNT skipped
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:38
    Message: Downloading phase completed
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:38
    Message: Product cache update from primary server successfully finished
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:38
    Message: Downloading product Sophos System Protection from server \\ new server\SophosUpdate\CIDs\S000\SAVSCFXP\
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:37
    Message: Product cache update from primary server successfully finished
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:37
    Message: Downloading product Sophos AutoUpdate from server \\ new server\SophosUpdate\CIDs\S000\SAVSCFXP\
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:36
    Message: Product cache update from primary server successfully finished
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:36
    Message: Downloading product Sophos Network Threat Protection from server \\ new server\SophosUpdate\CIDs\S000\SAVSCFXP\
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:35
    Message: Could not connect to the server. Check that this computer is connected to the network and that Sophos AutoUpdate is configured to update from the correct location with the correct credentials and proxy details (if required)
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:35
    Message: Downloading product Sophos Endpoint Defense from server \\ new server\SophosUpdate\CIDs\S000\SAVSCFXP\
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:34
    Message: Product cache update from primary server successfully finished
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:34
    Message: Downloading product SAVXP from server \\ new server\SophosUpdate\CIDs\S000\SAVSCFXP\
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:34
    Message: Product cache update from primary server successfully finished
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:34
    Message: Downloading product RMSNT from server \\ new server\SophosUpdate\CIDs\S000\SAVSCFXP\
    Module: CIDUpdate
    Process ID: 1156
    Thread ID: 3272

    Time: 17/01/2017 13:17:34
    Message: ***************          Sophos AutoUpdate started          ***************
    Module: ALUpdate
    Process ID: 1156
    Thread ID: 3272

  • Hello nigel parker,

    Sophos Endpoint Defense is new with 10.6.4. Looks like you've subscribed to Preview on the old server. If you re-protect with 10.6.3 the associated information for AutoUpdate isn't cleared, subsequently it's searching for the product but fails.

    Christian

  • Hi

    thanks the new server is showing its running

    sophos enterprise console 5.4.1 if I go help about

    the clients (on the new server) show they are running 10.6

    Thanks

  • Hello nigel parker,

    it's not just 10.6 but the minor that's important - 10.6.4 does have SED, 10.6.3 doesn't. So you should check the version of the endpoints (clients) on the old server (tab Anti-virus Details, column Anti-virus version). The SEC version doesn't matter, the subscription does. If it's indeed the case that 10.6.4 was already in use you can either subscribe to Preview on the new server or ignore the message until 10.6.4 is GA.

    Downgrading of the components is supported when you re-protect but only known features are uninstalled. 10.6.3 isn't aware of the new SED so its installer doesn't uninstall it.
    [Edit] Not sure now if above this is correct - just tested a downgrade by assigning Recommended to an endpoint running 10.6.4, the SED is correctly uninstalled. Haven't tested a re-protect from the console though. [/Edit]

    [just saw your other post]
    The normal updating log doesn't really help in troubleshooting an error that's not immediately obvious. For this purpose the detailed ALUpdate log is required. Anyway I think the Could not connect to the server is misleading here. So please check the involved endpoint versions. Apart from this - I daresay: rather minor - issue everything seems to work.

    Christian

  • Hi thanks

    when I deploy from the old server the client reports

    sophos av 10.6.4.1150

    deploying from the New server
    sophos av 10.6.3.537

    so I have downloaded an older console is that what your saying? Thought I picked the latest version available and cant understand therefore how the old server is on a newer version than the new one !

    I will look around the downloads again to see what I can find, we need to remove errors before we move the other clients as I want a nice clean start

     

    Regards

    Nigel

  • OH I see on the subscriptions on the NEW server I can select Preview Early access

    and someone has selected this on the old server !

    what to do - do I go for the preview or wait and ride out the errors

    Hmmmm

  • If I set the old server back to recommended versions will they roll back to the supported recommended versions from the preview versions ?

    He askes rather more hopefully than should be thought ................

  • just thought

    If I put them on recommended will they stay on the version they are and then eventually they will be on the same version as the NEW server

    at that point I can move them over without issues

    Thanks

  • Hello Nigel,

    you can set the subscription on old to the 10.6 Recommended package, wait for the endpoints to downgrade, then move them. Or change your subscription on new to Preview, 10.6.4 apparently ran without issues so why not just stay (it'll be released soon as recommended anyway).
    BTW: Someone must have selected the Preview package

    BTW: The Endpoint software version is independent of the SEC version. When you install SEC it (or to be exact: SUM) is configured to look for Recommended - whether you install the current SEC (5.4.1) or a legacy version (5.2.2) and will right now download 10.6.3. A current version of SEC is required to manage new Endpoint features (i.e. configure the policies accordingly) - if you have an older SEC you can't for example configure MTD (malicious traffic detection), though the endpoints will accept the policy and use the defaults for unconfigured items.

    Christian 

  • Thank s

    set the old server to recommended and will wait until the preview goes live then try a few migrations

    Hopefully :-)

    I will be up and working

     

    Thanks