tkultschar Posted January 8, 2014 Posted January 8, 2014 Hi all, Having a problem with getting our Sophos endpoints up and running. If a client is protected with the endpoint software and a user logs in that has software restriction GPO's applied to it, something blocks access to Internet browsing. I've narrowed it down to a single GPO that contains the software restrictions, and if they are disabled (or changed to unrestricted) then the user can browse the Internet. The message that appears is that the browser cannot connect to the proxy server. Is there a clash somewhere? or a setting that needs amending? I've tried fully disabling all policies but there still isn't any connection. Strangely, as an Admin I can browse the Internet if I run Chrome with my credentials, but I'm assuming it's because there are no active software restrictions imposed on my account, and the proxy settings are taken from the registry. Sophos Enterprise Console 5.1 Windows Server 2008 R2 - Standard users no admin rights Thanks in advance Tom
tkultschar Posted January 9, 2014 Author Posted January 9, 2014 If anyone has any suggestions I'd be grateful. Slowly running out of ideas and at the moment have to choose between Internet Access and Anti-Virus... Thanks Tom
Steve21 Posted January 9, 2014 Posted January 9, 2014 What's your SRP looking like? Sounds like you're blocking some of the sophos exe's and seeing they create an internal proxy once it's blocked you'll lose access etc. Steve
tkultschar Posted January 9, 2014 Author Posted January 9, 2014 Thanks for the replies! The only thing I can see that could block it is the path rules, and as \Program Files and \Program Files(x86) is unrestricted it shouldn't stop anything running - unless the exe's are somewhere else that I can't see. Just discovered that the effected users can't resolve any DNS names - which may be why they cannot connect to the network proxy, as I used the FQDN and it can't resolve it manually. Will attempt using an IP a bit later - might be a temporary fix. Had a quick gander at Sophos knowledge base and it does say that the firewall can block windows services, but the Sophos firewall is currently allowing all traffic which is stranger still. We're a school so our Sophos licensing etc. is managed by the local authority helpdesk, and they haven't got back to me yet. I might just send a request to Sophos anyway explaining...
jmak Posted January 9, 2014 Posted January 9, 2014 We're a school so our Sophos licensing etc. is managed by the local authority helpdesk, and they haven't got back to me yet. I might just send a request to Sophos anyway explaining... My comment isn't the most enlightening you'll ever receive but don't bother phoning Sophos unless you can get all of the account details from your LA. Their CRM won't let them open a case without it, so they won't help you at all (personal experience). You'd be better spending the time nagging your LA support.
MordyT Posted January 9, 2014 Posted January 9, 2014 You can check the event viewer logs and see what srp is blocking...
tkultschar Posted January 10, 2014 Author Posted January 10, 2014 Still waiting to hear back from LA. Checked the Event Viewer - There is nothing relating to either Sophos or what SRP is up to. I can't understand how it would block DNS name resolution though. I can ping IP addresses but not hostnames. Baffling!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now