Sorry, typing in a hurry. The update server was on a separate network segment, not the internet (like I thought it was). The request came across on port 139 and was showing as such in the log-- that helped me identify where Sophos was going to get it's updates. I added that segment to the trusted zone and it allowed access on port 139. Hopefully that's a little more clear. Sorry, when I try to type things to fast, to avoid too much time on the internet, they don't come out like they should.