Sophos

Online support

Product maintenance

Contact support

Support services

Sophos Anti-Virus for Windows: using SMS to deploy Sophos Anti-Virus, current versions

This article is intended for use by network administrators who already use Microsoft Systems Management Server (SMS) to manage, deploy, and update network components, and who now want to use SMS to deploy and manage current versions of Sophos Anti-Virus on their network.

More information about SMS is available from the Microsoft SMS web pages.

The following procedures assume that the user is already familiar with the functionality, components and terminology of SMS 2.0.

What to do

Deploying Sophos Anti-Virus

  1. Creating a new package and program
    Open the SMS Distribute Software Wizard and Create a new package and program for a collection of computer systems. Give the package an appropriate name, for example, "Sophos Anti-Virus for XP".
  2. Defining a source directory
    In 'Source Files' select 'Obtain files from a source directory'. In 'Source directory:' select 'Network path (UNC name)'. Enter the location of the Sophos Central Installation Directory (CID) files. Typically this could be any of the following defaults:

    \\servername\InterChk\ESXP - for Windows 2000/XP/2003
    \\servername\InterChk\ESNT - for Windows NT4
    \\servername\InterChk\ES9X - for Windows 95/98/Me

    If you want groups of computers to update from different locations, these groups and locations can be specified after deployment. This is described more fully below. Click 'Next'.
  3. Selecting distribution points
    Select appropriate distribution points for the package. Click 'Next' to display the Program Identification dialog box, check that the 'Name' field displays the program name that you defined in step 1 above.
  4. Using the Command line
    You will use the Command line to define two areas:
    1. Where computers obtain updates. One of the following will apply:
      • You have groups of computers, and you need to define an update location for each group. You can define these locations either before or after deployment.
      • You want all computers to update from a single location. You can specify this location before deployment, by entering the primary server address in the command line
    2. The information required to identify the new program. This must include:
      • the setup.exe file from the source file specified above
      • the user name and password required to access the server from which you will get updates.
  5. Entering the Command line
    Enter a command into the Command line field. According to whether you want to specify the primary server address before or after deployment of Sophos Anti-Virus to the computers, your text should resemble one of the following examples:
    • if you intend to specify the primary server address AFTER deployment:
      setup.exe -user <username> -pwd *****
      Where <username> is an account with read-access to the CID.
      When you enter a command in this format, after Sophos Anti-Virus is deployed to the computers, the primary server address in the AutoUpdate Configuration on the client computers defaults to the UNC path of the shared SMS package folder on the SMS server, for example \\[SMSservername]\SMSPKGC$\ 12300001\ .
      The client computers will appear in the 'Unassigned' folder of the Enterprise Console as managed and connected. However, as the primary server location is not pointing to a managed CID, the computers will not get Sophos updates. You must specify this later.
    • if you intend to specify the primary server address BEFORE deployment:
      setup.exe -user <username> -pwd ***** -mng yes -updp \\servername\InterChk\ESXP
      Where <username> is an account with read-access to the CID.
      When you enter a command in this format, the client computers will appear in the 'Unassigned' folder of the Enterprise Console, as managed and connected, and will get Sophos updates. Click 'Next'.
  6. Running the program
    In 'Program properties', choose to run the program, and select 'Whether or not a user is logged on' from the dropdown options.
    Note: After running the program on Windows 95/98/Me platforms, the computer may require rebooting.
  7. Advertising the program
    Advertise the program. Select appropriate advertisement targets.
  8. Assigning the program
    Assign the program. Choose the option that makes installation mandatory on the computers.
  9. Completing the software distribution
    Click 'Next', then 'Finish' to complete and exit the software distribution wizard. If necessary, you can now adjust the properties of the advertisement appropriately, such as making assignments mandatory over slow links.

Managing client computers after deployment

For computers to receive Sophos Anti-Virus updates, you must ensure that the address you want them to update from is correctly set to the CID on the server. One of the following will apply:

Note: The Protect computers wizard that appears when computers are moved from the 'Unassigned' group can be cancelled.

If you need more information or guidance, then please contact technical support.