sidewinder Posted May 8, 2007 Posted May 8, 2007 Maybe its just me but the Sophos knowledgebase seems hopeless and doesnt even seem to understand the term migrate So how do I do it? Enterprise Console v2 we're running Is there a migration tool or a guide on doing it manually? Also once its done I assume its just a case of changing the updating policy to reflect the new server so clients can find updates
GoldenWonder Posted May 8, 2007 Posted May 8, 2007 I tried this a while ago, and it didn't go very well and Sophos weren't a great deal of help. Basically it seems to involve a fresh installation, and then running a startup script (provided by Sophos) on the clients to redirect to the new server and force them to get a new certificate to allow them to connect to the remote management system. It all worked as soon as the scripts ran on the PCs. This was on the older version 1.0 console, but I would assume the process is similar.
Kyle Posted May 8, 2007 Posted May 8, 2007 We just installed it on another server and then redirected the clients. Took a while ofr them to come over but it was all done ina few days. We jsut turned the other server off then
john Posted May 8, 2007 Posted May 8, 2007 Ok really simple guys, one of the few simple things! You need to ensure that the new server gets the name and IP of the old one, so thats easy done. So install Server 2003, SP2 etc updates etc, download Sophos from Sophos webby. Disconnect Old Server, remove from domain, network etc. Rename new server old serves name and give it its IPs, then reboot, install Sophos EC2, EMlib etc on that, give the shares the same names as the old servers had, then bobs your uncle, it should all come back through and work fine within a few hours, or it did for me when I moved it once. Must admit its the only thing thats gone well for me with Sophos!
mattx Posted May 9, 2007 Posted May 9, 2007 What if the server you are moving it from has other network related apps / shares / home directories etc which people are using ?
sidewinder Posted May 9, 2007 Author Posted May 9, 2007 I would really prefer not to call the server the same name If I do that, I cant do any work on it until holidays, and it needs to go in at half term to replace an unreliable one I would much prefer to work on it during term time and do as much as I can, and do the swap at half term I think I'll go the route of installing it fresh
contink Posted July 8, 2007 Posted July 8, 2007 Word of warning on this that I discovered the hard way... It may seem obvious but worth noting for anyone who has a dense moment too. You can't have Sophos EC installed on more than one server.. If you do you're likely to screw up your ability to get status reports from your clients. Yep... I managed to get two EC's on the network and didn't realise for ages... The clients were installing fine but once Sophos started installing it would sit with the hourglass icon and not change. Solution was to uninstall EC, the library, etc... from all machines and then reinstall on the machine that should have it... After that most of the client machines picked up the proper EC install and status updates worked fine.
john Posted July 8, 2007 Posted July 8, 2007 Hmmm maybe your unlucky, I have 2 versions of Enterprise Console on my Lan. Fine one is the new V7 Sophos one with the dashboard and the other is the older one (forgot the version numbers) but they play very happily together so long as you dont try and talk to the same machines in both consoles, which I don't as i moved the ones i dont want in each console to the Unassigned Computers folder.
Sophos-Support-5 Posted July 9, 2007 Posted July 9, 2007 Maybe its just me but the Sophos knowledgebase seems hopeless and doesnt even seem to understand the term migrate So how do I do it? Enterprise Console v2 we're running Is there a migration tool or a guide on doing it manually? Also once its done I assume its just a case of changing the updating policy to reflect the new server so clients can find updates Hi Sidewinder, The Sophos Enterprise Console (SEC) and Sophos Enterprise Manager (SEM) will need to be uninstalled and reinstalled - but they are not as important as the database storing all the data regarding the installations of Sophos Anti-Virus (SAV) on each of your client machines. You can "migrate" the SOPHOS2 (or SOPHOS3 for SECv3) database from one machine to another. It is explained in appendix B of: http://www.sophos.com/sophos/docs/eng/esav_20_uen.pdf (SEC v2) http://www.sophos.com/sophos/docs/eng/esav_30_uen.pdf (SEC v3) Once the database is moved to the new machine you will also retain all of your groups and policies (SAV and Updating) inside the SEC. In order for all the client machines to talk successfully with the new server make sure you backup from the old server the registry key: HKEY_LOCAL_MACHINE\Software\sophos\Certification Manager ...and import into the registry of the new server. Reinstating this key means the security keys that allow communication between clients and the Sophos management server have been preserved. If the IP address is the same on the new server as it was on the old all the client installations will not notice a different. If however the IP address/ hostname of the Sophos management server has changed the clients will send their status messages to the wrong server. The following registry key dictates where the messages are sent: HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router - ParentAddress If it is still looking to the old server initially try re-protecting a test group of clients and check in their registry again. If this continues to point to the old server please raise a support request and we can troubleshoot further: http://www.sophos.com/support/query Regards, Sophos Technical Support
psydii Posted July 9, 2007 Posted July 9, 2007 Does that Certification Manager / Router Parent address trick work if you want to move the clients from a v1.2 to a v2/3 server with out moving the DB?
Sophos-Support-5 Posted July 9, 2007 Posted July 9, 2007 Does that Certification Manager / Router Parent address trick work if you want to move the clients from a v1.2 to a v2/3 server with out moving the DB? Hi Psydii, Sophos Enterprise Manager Library (EM Library) had a version 1.2. I assume you mean Sophos Enterprise Console v1. Yes: the same registry key should be exported from the old installation and imported to the new server/ installation. Regards, Sophos Technical Support
sidewinder Posted July 10, 2007 Author Posted July 10, 2007 Sophos-Support-5 - Where were you 2 months ago?!? lol In the end, as the old server was also running IAS and KS3 tests, I couldnt remove it (its still running now) So I changed the update location on the old server to match the one on the new server So all clients are updating but obviously Ive lost the ability to see their status. Bit by bit Im going through and 're-protecting' them on Enterprise manager which does work but is going to take ages as we have 700 PC's and its hard to deploy to laptops from there because they often arnt on for long I will have a look at those reg keys though as that may be an easier way
psydii Posted July 11, 2007 Posted July 11, 2007 SS5, You are of course correct that is what I meant! Does this work if BOTH the ip and hostname of the server are different? p.
Sophos-Support-5 Posted July 12, 2007 Posted July 12, 2007 SS5, You are of course correct that is what I meant! Does this work if BOTH the ip and hostname of the server are different? p. Hi Psydii, What you are asking can be done; it's just a tad more complicated. As an overview... Reinstating the Certification Manager key means messages recieved from clients are allowed (NOTE: RMS communication is secure) to be passed to the Management service and then written to the database. If you did not back up the key and simply reinstalled the SEC on a new server the new SEC would have a different secure key and all the clients requests to send messages would be refused because the key they are using is unknown to the new SEC. The above is based on the messages actually getting to the Sophos management server to be accepted/ refused in the first place. If your new Sophos management server has a different IP address/ hostname then the clients need to be told about it before you decommission the old Sophos management server - it's all done through the Central Installation Directory (CID) that they are currently updating from. While all the clients are updating from \\oldServer\InterChk\ESXP\ you have to use that CID to re-configure them and tell them to not only look at \\newServer\InterChk\ESXP\ but also send all their status messages to the newServer from now on. If you would like more details feel free to submit a support request. http://www.sophos.com/support/query Regards, Sophos Technical Support
psydii Posted July 23, 2007 Posted July 23, 2007 SS5 I'll probably log this later on in the week. Thanks.
mhmamun Posted August 12, 2009 Posted August 12, 2009 I tried this a while ago, and it didn't go very well and Sophos weren't a great deal of help. Basically it seems to involve a fresh installation, and then running a startup script (provided by Sophos) on the clients to redirect to the new server and force them to get a new certificate to allow them to connect to the remote management system. It all worked as soon as the scripts ran on the PCs. This was on the older version 1.0 console, but I would assume the process is similar. Thanks a lot. Can you give me the startup script PLZ. Mamun
walkden-high Posted December 8, 2009 Posted December 8, 2009 I moved our Sophos setup to a new server and followed these steps which Sophos support sent to me. 1.Close Enterprise Console. 2.Export the registry key HKLM\SOFTWARE\sophos\CertificationManager to a file called SophosCertificates.reg, and back this up. 3.Stop the service 'Sophos Management Service'. (This should close the management service connection to the database, this may take a couple of seconds). 4.Detach the database 'Sophos' using SQL Enterprise Manager, where possible. (See below if you need to use osql instead.) 5.Backup the files: C:\program files\microsoft sql server\mssql$sophos\data\sophos.mdf (do If this was an Upgrade from Enterprise Console 1.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\sophos_log.ldf (do If this was an Upgrade from Enterprise Console 1.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS2.mdf (do If this was an Upgrade from Enterprise Console 2.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS2_log.LDF (do If this was an Upgrade from Enterprise Console 2.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS3.mdf C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS3_log.LDF 6.Re-attach the database ‘Sophos’ to continue using it using SQL Enterprise Manager, where possible. (See below if you need to use osql instead.) 7.Export the EM Library config by issuing the EMLExp.exe command: {This command is in C:\Program Files\Sophos Enterprise Manager\Library\bin} "emlexp export "\\\sophosem" c:\emlexp.xml" 8.Restart 'Sophos Management Service' 9.Shut down the old server and over on the new server assuming you kept the same Name and IP, you will want to import the registry key you exported in Step 2 10.Download the lastest version of Enterprise Console from the Sophos website (currently 3.0 in a file named ES30SFX.EXE) and do a complete install (very important that the registry key be imported BEFORE you do this install). *** I actually used 3.1 *** 11.Stop the service 'Sophos Management Service'. (This should close the management service connection to the database, this may take a couple of seconds). 12. Once the complete install is done, detach the empty database that got created following the detach database instructions below and then move the database files you backed up in step 5 into the C:\program files\microsoft sql server\mssql$sophos\data\ directory 13.Re-attach the database ‘Sophos’ to continue using it using SQL Enterprise Manager, where possible. (See below if you need to use osql instead.) 14.Import the EM Library config by issuing the EMLExp.exe command: {This command is in C:\Program Files\Sophos Enterprise Manager\Library\bin} "emlexp import "\\\sophosem" c:\emlexp.xml" 15.Restart 'Sophos Management Service' All of this worked until step 15 as the service will not start. Clients are updating and the server is pulling down updates but the Management console will not work as the service is stopped. Sophos are now ignoring my emails. Brilliant! 1
techie08 Posted February 10, 2010 Posted February 10, 2010 I moved our Sophos setup to a new server and followed these steps which Sophos support sent to me. 1.Close Enterprise Console. 2.Export the registry key HKLM\SOFTWARE\sophos\CertificationManager to a file called SophosCertificates.reg, and back this up. 3.Stop the service 'Sophos Management Service'. (This should close the management service connection to the database, this may take a couple of seconds). 4.Detach the database 'Sophos' using SQL Enterprise Manager, where possible. (See below if you need to use osql instead.) 5.Backup the files: C:\program files\microsoft sql server\mssql$sophos\data\sophos.mdf (do If this was an Upgrade from Enterprise Console 1.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\sophos_log.ldf (do If this was an Upgrade from Enterprise Console 1.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS2.mdf (do If this was an Upgrade from Enterprise Console 2.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS2_log.LDF (do If this was an Upgrade from Enterprise Console 2.0 at one point) C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS3.mdf C:\program files\microsoft sql server\mssql$sophos\data\SOPHOS3_log.LDF 6.Re-attach the database ‘Sophos’ to continue using it using SQL Enterprise Manager, where possible. (See below if you need to use osql instead.) 7.Export the EM Library config by issuing the EMLExp.exe command: {This command is in C:\Program Files\Sophos Enterprise Manager\Library\bin} "emlexp export "\\\sophosem" c:\emlexp.xml" 8.Restart 'Sophos Management Service' 9.Shut down the old server and over on the new server assuming you kept the same Name and IP, you will want to import the registry key you exported in Step 2 10.Download the lastest version of Enterprise Console from the Sophos website (currently 3.0 in a file named ES30SFX.EXE) and do a complete install (very important that the registry key be imported BEFORE you do this install). *** I actually used 3.1 *** 11.Stop the service 'Sophos Management Service'. (This should close the management service connection to the database, this may take a couple of seconds). 12. Once the complete install is done, detach the empty database that got created following the detach database instructions below and then move the database files you backed up in step 5 into the C:\program files\microsoft sql server\mssql$sophos\data\ directory 13.Re-attach the database ‘Sophos’ to continue using it using SQL Enterprise Manager, where possible. (See below if you need to use osql instead.) 14.Import the EM Library config by issuing the EMLExp.exe command: {This command is in C:\Program Files\Sophos Enterprise Manager\Library\bin} "emlexp import "\\\sophosem" c:\emlexp.xml" 15.Restart 'Sophos Management Service' All of this worked until step 15 as the service will not start. Clients are updating and the server is pulling down updates but the Management console will not work as the service is stopped. Sophos are now ignoring my emails. Brilliant! Did you resolve this??? i basically want to build a brand new domain on a new server and migrate sophos across. The new server will obviously have a new name, IP and new domain name. The school only has two servers, A domain controller and SIMS member server. Would i follow your instructions? Thanks
TomTomGo Posted October 12, 2010 Posted October 12, 2010 I've just finished a migration from an old DC to a new one on the same Domain. Following the above instructions it also worked fine up until point 15.Restart 'Sophos Management Service'. I then realised i had not restarted the Sophos SQL instance in "SQL Server Service Manager", once this was done, the "Sophos Management Service" restarted successfully. Clients are now updating and communicating with the new DC. Other things to note: i) Change the CID directory to the new Server after importing the emlexp.xml. Download your packages and check the Message Log to make sure the download was successful ii) Disable the following shares on the old server "\EmLibInstaller, \InterChk and \SophosEM" iii) Stop the Sophos SQL instance on teh old server. HTH
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now