Showing posts with label sophos. Show all posts
Showing posts with label sophos. Show all posts

Sunday, 11 March 2012

Sophos Enterprise Console 5 displays clients as "Awaiting policy transfer" after upgrade

I am yet to have a smooth Sophos Enterprise Console (EC) upgrade, there is always some certificate, configuration or downright weird issue. This time after upgrading from 4.7 to 5.0 everything seemed perfect, I should of known that was too good to be true.

After a policy change didn't find its want to my endpoint's I did some digging in EC and found nearly all of my endpoints were hanging at "Awaiting policy transfer". The only clients that were the "Same as policy" had been rebuilt since the EC upgrade took place.

Immediately I though of the dreaded Sophos certificate problem but further investigation ruled out this theory, fortunately the resolution was much easier.



Please update my policy changes!

1. Fire up EC 5

2. Right click any computer that is turned on but still "awaiting policy transfer", then select "View Computer Details"

3. Here you find the the status of all the policies on the selected client. For example "Anti-Virus and HIPS Policy", "Updating Policy" and "Application control policy".

Take note of all the policies that are "awaiting policy transfer", these are the ones we will need to fix.

4. The fix is ridiculously easy, edit one of the policies that are "awaiting policy transfer" and change one option. After changing the option, change it back to your original setting then press OK. Repeat for all policies hanging at "Awaiting policy transfer".

Huh? Hold on, I didn't change anything right? All I did was check an option then un-check it. Correct! But what I did do was trigger a policy update of old EC 4.7 policies. I am not sure if this changes some underlying configuration or perhaps updates an out of date check sum, regardless of what is happening behind the scenes it resolves my problem.

In the below image I opened my "Tamper Protection Policy" which was "awaiting policy transfer". I then checked "enabled tamper protection", then immediately unchecked it and clicked OK. Shortly after my clients begin receiving the updated policy.
 

Savour this fix, it's the easiest Sophos resolution you will ever get.

Sunday, 5 February 2012

Changing locked update settings on Sophos Endpoint Security and Control 9.7

When debugging Sophos updating configurations at times you may need to regularly change the primary or secondary update settings. This can be done via the Enterprise Console but this can be slow and messy.

By default these settings are locked when you apply them via policy, restricting even administrators from manually changing them for testing.

Fortunately Sophos have included a mechanism allowing a local administrator to change these settings on an as required basis.



Unlocking the update fields

1) Open explorer to C:\ProgramData\Sophos\AutoUpdate\Config\

2) Open iconn.cfg in your favourite text editor

3) If you want to edit the primary update location look for the following heading.
[PPI.WebConfig_Primary]

4) Under the [PPI.WebConfig_Primary] heading there is a field named.
AllowLocalConfig = 0

Allowing local update changes is as simple as changing that field from 0 to 1. Easy as that, oh and Sophos, please allow https based updating soon, we NEED it!

Sunday, 1 January 2012

Sophos Update Manager stops updating, downloading binaries hangs forever

I was recently doing some maintenance on my Sophos Enterprise Console 4.7 when I noticed that updates had not been downloading for nearly a full month. Nothing in my environment had changed, so this was something I didn't expect.

After rebooting, re-entering my upstream update server credentials and deleting the relivent SUM directories I still had no luck.



The Problem

I first noticed there was something wrong as the "Last Updated" field was nearly a month old, which would indicate something was blocking the updates. Checking further I found the following logs/error messages.

In the Sophos Update Manager (SUM), the "Download status" was "Downloading binaries". Even 2 hours later, this status didn't change. I was not able to find any file system activity with Process Monitor so I presumed this was a hung process.

In the SUM I found the following error:

CODE: 80040406
Description: Delivery failed for software subscription 'Recommended'. Access to the source update location is denied or the location is otherwise available.

In the Windows Application Event Log I found the following error:

Log Name: Application
Source: SophosUpdateManager
EventID: 16443
Level: Error
Product release 'A845A8B5-6532-4EF1-B19E-1DB2B3CB73D1' could not be updated because the synchronize operation has failed due to an earlier error.

The SUM trace logs, which was located in "C:\ProgramData\Sophos\Update Manager\Logs", displayed the following error:

2011-12-29 19:46:31 : EventLog: 3758112769 1 Inserts:> "F26F7EC0-1302-4DA7-8B6B-A5383051D41A" "EXCEPTION_ACCESS_VIOLATION at 0x74BB4500" "RECOMMENDED" "http://contoso.com/databank/Warehouse"

There are a number of error messages associated with "access violation" or "source denied", all pointing to a permissions issue with the upstream update server. So I opened up a web browser, put in the upstream update server address and my username and password with no problems. The SUM is reporting a permissions error, yet my web browser can access the update source with no problems. Then whats going on?



The Resolution

Unfortunately these error messages are extremely misleading. If you were to purely troubleshoot SUM on its error messages you would never fix your problems.

After some google detective work by my mate Simon (thanks for your help with this one), he was able to uncover this Sophos forum thread. This thread gives some good tips on how to fix the problem, but I will break it down into easy to follow steps.

1. Stop the Sophos Agent Service, Sophos Message Router Service and the Sophos Update Manager Service.

2. Open Task Manager and kill the "SophosUpdateMgr.exe" and "SUMService.exe" processes if they are running. This will kill SUM if it has hung.

3. Open regedit and navigate to
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2C7A82DB-69BC-4198-AC26-BB862F1BE4D0}]

or if your on 64bit
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2C7A82DB-69BC-4198-AC26-BB862F1BE4D0}]

4. Check the "UserData" value.

"UserData"="YourServer;YourDomain;SophosUpdateMgr;0;0"

The first part of this value (to the left of the first semi-colon) should be that of your SUM server. On my server (and it seems by the above linked Sophos forum the same applies to a number of other users) this "YourServer" value reads as a domain controller and not the Sophos server.

If the "YourServer" value does not reflect your SUM server then change it to reflect the correct server name.

5. Start the Sophos Update Manager service and wait 5 minutes. (The wait is important)

6. Start the Sophos Agent service and the Sophos Message Router service.

Voila, your SUM should be working again, at least it will be if you had the same error I did.

The "UserData" registry value is very interesting. Most of the time it doesn't matter if it reads as the domain controller and not the SUM server itself, in fact as soon as I updated again it changed back to the domain controller, yet I had no problems in the update process.

I believe a problem may arise when the "UserData" value is incorrect and there is a pending update to Sophos Update Manager itself, either way the above short process should resolve your issue.