Sophos UTM 9.314-13 Data Disk is filling up

We use the Sophos appliance under Vmware ESXi 5.X Transparent behind our commercial Firewalls (Just some Wireshark replacment ;-)

The box looks real good and is easy to use. The Interface and GUI are just perfect. I like the Realtime options.

Like most of the times when you search for a solution for a linux Problem there seem to be 40 different

Solutions and Rekommandation. Worst case you update Perl, the Kernels and Download 2'000 files. Nobody knows what it does exept the guy who wrote it but thats the same under Windows sometimes.



Here is how to check the space and enable SSH which is more complicated because you have to enable SSH with a key.


After your cleaned up with this method:


Alert E-Mail you get

Data Disk is filling up - please check. Current usage: 98%


System Uptime : 11 days 20 hours 21 minutes

System Load : 0.06

System Version : Sophos UTM 9.314-13


Please refer to the manual for detailed instructions.


First to do that you have to enable SSH and you have to generate a KEY so you can logon with root

They Made that very nice on the Sophos compared to other appliances ;-)

* Enable SSH

* make a private / Public key with PUTTYGEN.exe

* make the key (Save Public and private)

Mark they Public Key fully and paste it into the SOPHOS appliance (Next Screen)



Then give PUTTY.EXE that key to work with:


Now you are able to Logon with root to the Sophos and search for Big files.

cd /var/storage
du -sh *

There was 1.2 Gigabyte of files under: /var/storage/pgsql92/data after 2 weeks.

Got to the Directory:

Cd /pg_archivecleanup /var/storage/pgsql92/data/pg_xlog

List with:



pg_archivecleanup /var/storage/pgsql92/data/pg_xlog 000000010000000000000048


(Number 48 was just the last PLUS one i did have > No idea if this is right ;-)

Here are the large files / TS Logs of PSQL (We don't discuss if this should fill that fast or not or what they are)

pg_archivecleanup: must specify restartfilename

Try "pg_archivecleanup --help" for more information.



frissu:/var/storage/pgsql92/data/pg_xlog # pg_archivecleanup /var/storage/pgsql92/data/pg_xlog 000000010000000000000048

frissu:/var/storage/pgsql92/data/pg_xlog # ls


frissu:/var/storage/pgsql92/data/pg_xlog #


W7: Show hidden Hardware devices

Open a cmd.exe box with Elevated permissions:


set devmgr_show_nonpresent_devices=1

start devmgmt.msc



In Device Manager: click View, then Show Hidden Devices.


Just used in a DLP project where some clients had 94 COM Ports.



LAB: Exchange 2013 , Mail Stuck in Queue, DNS Set wrong in ECP

1st October was Release date Exchange 2016. So we finally take a look at Exchange 2013 in our Labs ;-) Exchange 2016 seems nothing else then Exchange 2013 SP2. Most of the Office365 things are now also available on Premise (On inhouse Exchange 2013).

First bug we had in Exchange 2013 with Outlook 2010.

Error 4.4.1 Mail does not get delivered to 2013 Test mailbox after Update to CU10.

You see E-Mail incoming in Exchange 2013 from 2007/2010 or itself BUT not delivered to Mailboxes.

Becaue of the Outlook Anywhere Proxy the internal and External DNS are important. There are also several Hotfixes

related in that Direction for Outlook 2010 and 2013. Mostly cumulative Hotfixes after SP2.

For Outlook 2010.

Get an Error 4.4.1 in Exchange 2013 GUI Toolbox.

  1. Check DNS Settings under ECP / Server / DNS-Lookups
  2. Check that the Services that work with that are running



The issue was related to having an external DNS server entered in the properties of the servers NIC. I had the internal primary and secondary DNS servers entered in the NIC, and in the advanced porperties I entered the IP address of our ISP's DNS server. I have done this for that past 8 years in my server NIC configurations and it has saved my butt numerous times. It allows the server to still access the Internet if one\both of the internal DNS servers goes offline\has issues, or if there are network issues. Until now I have never had an issue with this configuration.  I do not know if it is an Exchange 2013 or a server 2012 thing or what, but either way we removed the external DNS server from the NIC and the issue has not returned.


Cannot Upgrade VMware View Client 5.X / Windows Installer Error


Cannot Upgrade VMware View Client 5.X / Windows Installer Error.

You try to install View Agent 5.X on Windows 6 64BIT.

Error: Event 1013, Msinstaller "Product View Agent -- The System must be rebooted before installation can continue.

Existing Versions

  • Every time you install it should reboot
  • Option /c to clean does not do something
  • You did remove VMware Tools
  • You did uninstall old Version of View
  • The account has enough permission and is Local Admin


MSI Windows Installer Logfile you get with:

VMware-viewagent-x86_64-5.3.5-3038335.exe /V"/l c:\drivers\viewlog.txt REBOOT=Reallysuppress"

MSI (c) (EC:E4) [13:12:26:910]: Doing action: VM_MustReboot

Aktion 13:12:26: VM_MustReboot.

Aktion gestartet um 13:12:26: VM_MustReboot.

Das System muss neu gestartet werden, bevor die Installation fortgesetzt werden kann.

MSI (c) (EC:E4) [13:12:29:317]: Transforming table Error.


Check if there are pending reboots ore name of files:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired


Normally there is something really wrong in the Windows Installer Database then or the Installer is missing some MSP/MSI Source Files or Transforms.

Here is how to fix the German client, Do the Reboots as it wants it

:: VMWARE Repair VIEW Client

:: V1.0, 24.09.2015, M. Butsch



@echo off

:: Vmware tools remove

MsiExec.exe /X{0240CD90-92F5-46EA-AF6D-E9E4092FDCE9} /quiet

MsiExec.exe /X{057921DD-9895-48EE-8094-8274956086B1} /quiet

:: Uninstall View Agent

MsiExec.exe /X{C9E58A5B-0C62-42D3-9303-2131F66C1BD3} /quiet

MsiExec.exe /X{E1BF8D0F-3C8E-43F8-93E7-9E779B2F25AB} /quiet

MsiExec.exe /X{FE2F6A2C-196E-4210-9C04-2B1BC21F07EF} /quiet


reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress" /f

reg delete "HKLM\SYSTEM\CURRENTCONTROLSET\Control\Session Manager" /v PendingFileRenameOperations /f





Reboot the client 1) Install VMWARE Tools from Vcenter Command REFRESH > Reboot > Then RUN the command

:: ----------------------------------------------------------------------------

:: Installieren aktuelle Version

\\server\sw$\vmware\view_agent_5.3.5\VMware-viewagent-x86_64-5.3.5-3038335.exe /s/v/qb+ DESKTOP_SHORTCUT=0 VDM_SERVER=gzfvdm2 REBOOT=Reallysupress






End final target:

Files used:


Silent Uninstall Norman Endpoint Protection with Batch / Mcafee Migration

One of the products Endpoints which does not get automatic de-installed while migrating a customer to Mcafee VSE Enterprise via EPO-deployment is Norman Endpoint Protection. Here is how to uninstall their Agent silent.

  • Mcafee VSE P6 and Norman 9.10.1500 can RUN on same W7 client temporary until Reboot

Here is what it looks in actual version:



:: Uninstall Norman 9.X Silent



@echo off


if Exist "c:\Program Files\Norman\Nse\bin\zlh_nse.dll" "c:\Program Files\Norman\Npm\Bin\delnvc5.exe" /quiet

if Exist "c:\Programmme\Norman\Nse\bin\zlh_nse.dll" "c:\Programme\Norman\Npm\Bin\delnvc5.exe" /quiet


You could run this on a client with PSEXEC remote:

psexec @d:\deployment\noch_norman.txt -u domain\administrator -p password -c d:\deployment\removenorman.cmd

  • Make a Textfile with all PC names under d:\deployment\noch_norman.txt (One PC name per LINE then CR)
  • psexec.exe (Systernals) and the removenorman.cmd have to be in d:\deployment for this


Some Links: