Sophos

Online support

Product maintenance

Contact support

Support services

Download Free hard drive encryption - Download a trial of SafeGuard Easy

Sophos Endpoint Security and Control: command line parameters used by setup.exe

You can perform customized installations of Endpoint Security and Control 9 or Sophos Anti-Virus, Sophos Client Firewall and Sophos NAC, on Windows computers by running the setup.exe program from a command line. This allows you to deploy Endpoint Security and Control to your network using a startup script and the installation method of your choice, as well as invoking some of the special features described below.

Location

By default, setup.exe is located in the root directory of each update location (in Enterprise Console 4) or Central Installation Directory (CID) (in Enterprise Console 3.x).

In Enterprise Console 4, this is at \\servername\Sophos Update\CIDs\Sxxx\[package name]
In Enterprise Console 3.x this is at \\servername\InterChk\[package name].

Command line parameters:

Example: SETUP [-mng yes|no] [-scf] [-nac http://<NACSERVERADDRESS>] [-crt R] [-updp <path>] [-user <username>] [-pwd <password>] [-mngcfg <RMS config path>] [-compname <computername>] [-compdesc <computerdescription>] [-domain <domainname>] [-G <groupname>] -s -ni -?

ParameterDefaultDescription
-mng yes|no yesIs the computer to be managed?
-scfInstall Sophos Client Firewall (Windows 2000+)
-nac http://<NACSERVERADDRESS>Installs network access control and specifies the address of the Sophos NAC server
-crt RRemoves third-party security software automatically
-updp <path> <location of setup.exe>Location of the primary CID from where the computer will get its updates.
-user <username> blankAccount for accessing the primary CID location.
-pwd <password>blankPassword for the above account.
-ouser <username>Obfuscated account name for accessing the CID location, if required.
-opwd <password>Obfuscated password.
-mngcfg <RMS config path> <location of Setup.exe>Location of the RMS configuration files.
-compname <computername>Specify a computer name to override that on the client. This name will appear in Enterprise Console.
-compdesc <computerdescription>Specify a computer description to override that on the client. This description will appear in Enterprise Console.
-domain <domainname>Specify a domainname to override that on the client. This name will appear in Enterprise Console.
-G <groupname>Specifies the group (set up in Enterprise Console) to which the computer will belong.
-rloginStart reinstallalation on Windows 95/98/Me computers from login scripts.
-loginStart installation on Windows 95/98/Me computers from login scripts.
-s No Perform installation silently.
-ni NoPerform a non-interactive installation.
-? Display command line parameter help.

Setup.exe can return one of the following values:

Value Description
0 Installation was successful.
1 A command line parameter value is missing or an unrecognized parameter was specified.
2 Verification of the AutoUpdate package failed. The package files did not match the manifest.
3 AutoUpdate was already installed.
4 AutoUpdate does not support this operating system.
5 AutoUpdate requires Internet Explorer 5.0 or above; the system does not have this version of IE.
6 Installation of AutoUpdate failed.
7 Some file that was required could not be found e.g. an RMS configuration file or Sophos AutoUpdate.msi
99Some other error occurred.

Note: If you run an unknown parameter, the following error message will be displayed:

Setup
Could not find resource string 122
If you do not click 'OK', this message will close automatically after 60 seconds.

Setup.exe requires a directory named 'sau' to exist in the same directory as itself. This directory must contain a valid Sophos AutoUpdate package including manifest.dat (required by setup.exe) and cidsync.upd (required by the AutoUpdate installation).

Setup.exe creates the file 'Sophos EE setup.log' in the %TEMP% directory of each installed computer, where information and errors are logged. Information generated by the Windows Installer during the installation of AutoUpdate is also logged here. Each time setup is run, any previous log file is deleted.

An article on the Protect computers wizard gives an example of how to use the setup.exe command line parameters.

If you need more information or guidance, then please contact technical support.

  • Protect sensitive data from unauthorized use
  • Encrypt data, hard drives and removable media
  • Work uninterrupted with encryption on demand