For more information, see http://www.sophos.com/en-us/support/knowledgebase/121071.aspx.
Product retirements
Please note that SEC 4.5 and 4.7 are now retired, and at the end of December 2014, SEC 5.0 will retire. After this date, if you call Sophos Support with any issues relating specifically to SEC 5.0, then you will be told that it is unsupported and will be asked to upgrade to a supported management console version.
For more information on product retirements, see http://www.sophos.com/en-us/support/knowledgebase/119147.aspx.
For operating system requirements and supported SQL Server versions, see http://www.sophos.com/en-us/support/knowledgebase/113278.aspx.
If you don't have a supported SQL Server version (SQL Server 2005 Express or later) already installed, the Enterprise Console installer attempts to install SQL Server 2008 R2 Express Edition with Service Pack 1 (SP1).
The installer also attempts to install the following software (unless already installed):
You will need to have the following software installed:
For more information about installing required system software, refer to the Enterprise Console startup documentation published at http://www.sophos.com/en-us/support/documentation/enterprise-console.aspx.
Enterprise Console requires certain ports to be open. For more information, go to http://www.sophos.com/en-us/support/knowledgebase/38385.aspx.
In addition to this, you will need around 200 MB - 350 MB per endpoint product you are downloading from Sophos. For example, if you download three security software products - for Windows, Mac, and Linux - then around 700 MB would be required.
If you want to install Sophos Update Manager on a computer other than the one where Enterprise Console is installed, you will need at least:
Minimum database size
The computer where you place the database (which may be the same computer as the computer where Enterprise Console is installed or a different one) needs a minimum of 1 GB disk space for data.
Maximum database size
You can upgrade to Enterprise Console 5.2.2 directly from:
To upgrade from Enterprise Console 4.x or Enterprise Manager 4.7, you must upgrade to Enterprise Console 5.1 first.
For more information about possible upgrade paths, go to http://www.sophos.com/en-us/support/knowledgebase/119105.aspx.
For more information about upgrading, see the Sophos Enterprise Console upgrade guide.
For distributed installations of Enterprise Console (with SQL Server on a different server) the Sophos Management Service may not start if the "SOPHOS" database instance was created by PureMessage for Microsoft Exchange, or if the chosen SQL Server instance has TCP/IP protocol disabled.
To work around this problem, do the following.
For information on how to prevent other users from logging on to the server during the upgrade, see http://support.microsoft.com/kb/186504/en-us.
This issue does not appear when upgrading to Enterprise Console 5.2.2 from Enterprise Console 5.1 or later.
To work around this issue, do either of the following:
For more information about issues with upgrading Enterprise Console, see http://www.sophos.com/en-us/support/knowledgebase/114627.aspx.
For more information and instructions on how to enable deployment, see http://www.sophos.com/en-us/support/knowledgebase/118354.aspx.
When creating an Update Manager distribution, you cannot reference new shares named SophosUpdate because "SophosUpdate" is a reserved share name used for the default share.
Workaround: When creating new shares, use other names such as "Update".
In updating policies, when you are selecting a primary or secondary update location, the drop-down list shows the default share paths only in NetBIOS format, for example \\Server\SophosUpdate, although you may need to use the Fully-Qualified Domain Name form, for example \\server.de.acme\SophosUpdate.
Workaround: Type the FQDN path into the server location update path field.
To work around this problem, do one of the following.
Do not synchronize any Active Directory groups that contain machines which have identically-named computers. Manage the computers manually.
Workaround: Do not delete encrypted endpoints from the console.
When a Firewall policy is applied, all application rules are removed and then re-added. During this time, if an application that is allowed by the new policy tries to make an outbound connection, the application is blocked until the new policy is applied completely.
For release notes and other documentation for managed endpoint software, follow these links:
Before using Sophos Reporting Interface, read the Sophos Reporting Interface user guide.
Sophos documentation is published at www.sophos.com/en-us/support/documentation.aspx.
You can find technical support for Sophos products in any of these ways:
Copyright © 2014 Sophos Limited. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any means, electronic, mechanical, photocopying, recording or otherwise unless you are either a valid licensee where the documentation can be reproduced in accordance with the license terms or you otherwise have the prior permission in writing of the copyright owner.
Sophos, Sophos Anti-Virus and SafeGuard are registered trademarks of Sophos Limited, Sophos Group and Utimaco Safeware AG, as applicable. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.