Sophos

Online support

Product maintenance

Contact support

Support services

Enterprise Console: configuring message relay computers

A message relay computer relays messages (virus reports, etc.) between computers running Sophos Anti-Virus and your management server. Reasons for using a message relay computer include: increasing the number of workstations that can be managed by the management server, reducing the number of direct connections to the management server, and simplifying firewall configuration.

No separate software is required. The functionality is provided by Sophos Anti-Virus for Windows 2000+, version 6 and above.

Note: On large networks you may need to increase the number of ephemeral ports that Windows can assign.

When setting up a message relay you must:

  1. configure a CID for use by the message relay computer and workstations
  2. create an updating policy and group in Enterprise Console for use with the message relay computer
  3. ensure that the client workstations report to the message relay computer.

In the description below 'workstation' is used to describe all computers that report to the management server via the message relay computer, regardless of whether they are actually servers or workstations. It is also assumed that EM Library and Enterprise Console are located on the management server (the default setup).

These instructions should be used in conjunction with the network startup and upgrade guides.

What to do

You will need to create Central Installation Directories (CIDs) for your workstation packages. So, if you have Windows NT workstations as well as Windows 2000/XP workstations, you will need packages and CIDs for both.

1. Creating the message relay CID

To create an additional CID for a package in EM Library, do as follows:

  1. Open the EM Library console.
  2. In the left hand pane, select 'Packages' then select 'Subscribed'.
  3. Right-click a package (e.g. 'Sophos Anti-Virus for Windows 2000+, v6.0.0').
  4. Select 'Add/Configure CID'.
  5. When asked if you want to create an additional central installation, click 'Yes'.
  6. In the Add CID Wizard give the new CID a different name (e.g. 'MR - Sophos Anti-Virus for Windows 2000+, v6.0.0').
  7. In the CID Location dialog, select 'Custom CID location' and use a custom folder name (e.g. MRESXP instead of the default ESXP).
  8. Right-click the newly created CID.
  9. Select 'Update CID'.

Your newly created CID will be populated, in this example \\[Server1]\InterChk\MRESXP\.

2. Editing mrinit.conf

The file mrinit.conf contains the router configuration information. It must be edited to use the customized settings. As it is identical for all packages in a particular group of CIDs, the edited version can be copied to the other folders.

  1. In Windows Explorer, browse to the root of your new CID (e.g. \\[Server1]\InterChk\MRESXP\).
  2. Copy the file mrinit.conf to the rms subfolder (e.g. \\[Server1]\InterChk\MRESXP\rms).
  3. Open that copy of mrinit.conf in Notepad.
  4. Find the variable:
    "ParentRouterAddress"="[address],[address],[address]"
    where 'address' is probably the domain name or IP address of your management server.
  5. Edit it to take the form:
    "ParentRouterAddress"="[MR-IP],[ MR-FQDN],[ MR-NETBIOS]"
    where:
    • MR-IP is the IP address of the message relay computer.
    • MR-FQDN is the fully qualified domain name of the message relay computer.
    • MR-NETBIOS is the NETBIOS name of the message relay computer.
    In the above example this could be "ParentRouterAddress"="10.1.200.65,MRComputer.Sales.Acme,MRComputer"

Important:

Copy your edited mrinit.conf to the other RMS subfolders (e.g. \\[Server1]\InterChk\MRESNT\rms).

Other platform packages:

3. Using ConfigCID.exe

Obtain an up to date copy of ConfigCID.exe.

Run ConfigCID.exe on all of your newly created CIDs:

ConfigCID.exe "C:\Program Files\Sophos SWEEP for NT\MRESXP"

Check the program output:

These lines confirm that the file mrinit.conf was found, and was added to the catalogue of files to be downloaded by Sophos AutoUpdate on your workstations, and on the message relay computer.

This completes the configuration of a message relay CID.

Repeat these steps for any other message relay CIDs that you will need.

4. Creating a message relay policy and group in Enterprise Console

In Enterprise Console:

See the network startup and upgrade guides for details on setting up policies and groups.

5. Installing Sophos Anti-Virus on the message relay computer

In Enterprise Console:

This computer should now be working as a message relay. It will route messages between the management server and all workstations configured to use it as their parent.

To check that the message relay computer has installed from your new CID, open Sophos Anti-Virus, select 'Update options', and check the path listed in the 'Primary server' tab.

6. Deploying to the workstations

In Enterprise Console:

They will then transmit all messages to the management server via the message relay computer.

You can confirm that a workstation is messaging to the correct computer, by checking the following registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router\ParentAddress. It should contain the MR-IP, MR-FQDN and MR-NETBIOS addresses that you added to mrinit.conf in section 2 (e.g. 10.1.200.65,MRComputer.Sales.Acme,MRComputer).


Technical details

A message relay computer is a Windows 2000/2003 server running a Sophos Message Router as part of Sophos Anti-Virus. This server is placed between the management server and managed workstations (endpoints). No special software is required, as all configuration is done at the management server. The message relay computer transmits Sophos Anti-Virus and Sophos Client Firewall messages between the management server and workstations, as well as Sophos AutoUpdate updating information.

Reasons for implementing a message relay include:

The Sophos Message Routers on the workstations are configured to report to the message relay computer as their parent, rather than directly to the management server. Message relays are thus managed computers which act as parent routers for other computers. No change is required in the configuration of the router to be able to fulfill the role of message relay. However, because a message relay computer is expected to have a potentially large number of connected child routers, server-grade operating systems and hardware are recommended.

Workstations using a message relay need to have the router's ParentAddress setting in the registry changed from the address of the server, to the address of the message relay computer. This is done by changing the configuration centrally, but can be checked locally.

If you need more information or guidance, then please contact technical support.