Jump to content

Recommended Posts

Posted

Another nail in Sophos Coffin - my server just alerted me to a load of events in the system event log which just maxed out the CPU for 15 mins with a load of these logged:

 

The on access driver failed to check file \Device\Harddiskdmvolumes\physicaldmvolumes\Blockvo

 

A wad of entries which have caused my backup to fail and other scheduled scripts - anyone got any ideas ?

Posted
Rule one of the Sophos Recomendatsions - disable the On-Access scanner on Servers.

 

Heh - not much point in having it installed then !!

If that is what they come back with [ after my E-mail I have just sent, then I think I'll ask for my money back ]

Posted
go Sophos go Sophos its ya birthday and ya know ya hopeless muhahahahaha may i rocomend a diffrent antivirus that works and dose not destroy slow you pc, servers and give you the biggest headake ever??? let me introduce you to your new friend. its a 3 letter word with 2 numbers. let the games of hang man begin
Posted

Nah nod32 aint that brill either, Trend Micro for me :p

 

As for Sophos, I am being serious, you are supposed to turn off the On-Access scanner on all servers to ensure no performance reduction and ensure that you have daily scheduled full scans in quiet time to scan for bugs.

Posted
We use CA eTrust which seems to do alright for performance and stability. One of the places I did some work for had NOD32 and it was a nasty bit of work, they released three seporate updated that killed the Exchange information store. Twice it damaged the information store to the point that it needed to be restored from backups. It only had automatic updates on as the tech before me had it setup that way and they did not want me to change it.
Posted
As for Sophos, I am being serious, you are supposed to turn off the On-Access scanner on all servers to ensure no performance reduction and ensure that you have daily scheduled full scans in quiet time to scan for bugs.

 

I have found the best compromise is to leave the on access scan installed but set it to on write only. This does not slow down the back ups (with it enabled the time taken almost doubles) and as a big chunk of server activity is reading files (particularly on the application and web servers) then it has a lot less impact.

Posted
We have it only set to do daily scans on servers here - anything more is, IMO, overkill, as all clients have on access scanning - so the only way of things getting onto the server would be via one of these.
Posted
all clients have on access scanning

 

I know what you are saying - but I just do not have enough confidence in Sophos that there is not a machine out there where the local software is not working properly!

Posted

I've got a sophos engineer comeing in beacuse i had to download the rootkit tool and a kind pr guy phoned to see how it went. I told him we had lost confidence in the product so now their sending an engineer to site to have a good look at whats happening.

 

On the plus side we had a brand new virus and sophos tech support were excellent. Nod32 couldn't deal with it and their telephone support isn't upto much.

Posted
We have it only set to do daily scans on servers here - anything more is, IMO, overkill, as all clients have on access scanning - so the only way of things getting onto the server would be via one of these.

 

I understand what you are saying but what if Sophos is not running on the client ? At least with both running you get a fall back on a file being checked somewhere.....

Windows Server 2003 has been out now long enough for them to get their product running properly on it.

I have to be careful what I say about Sophos on here though.....

 

I told him we had lost confidence in the product so now their sending an engineer to site to have a good look at whats happening.

 

Good lord, I would not let a Sophos Engineer near a video recorder let alone a live server.....If it has got to a point in which a VERY LARGE software vendor is sending an engineer to a user / business / school or whatever, - it does not really send a message of trust to that particular vendor when its supposed to be a critical security app !! My opinion blah blah blah

Posted
Not really, it is industry practice to turn off on-access type scanning on the servers. Afterall, most servers simply contain inert content and a single daily scan will see these off. The clients SHOULD be running on-access (but with remote file checking switched off) as it is the client which will be opeing the files locally.
Posted
it is industry practice to turn off on-access type scanning on the servers.

 

Well it wasn't in my last job and I was responsible for rolling out an AV solution on 3 citrix farms, a few thousand clients and a stack of file servers. If a client had an out of date sig or a problem with the av product at least the on-access scanning on the server may pick it up.

I suppose it depends on how business critical the industries data is and what their policies are - its something I would never consider though - no matter how large or small the industry was.

Posted
Yes, but your server containing tens of thousands of users files should not be scanning all of them every time a request for access occurs. The clients AV should do that.
Posted
We have it only set to do daily scans on servers here - anything more is, IMO, overkill, as all clients have on access scanning - so the only way of things getting onto the server would be via one of these.

 

I understand what you are saying but what if Sophos is not running on the client ? At least with both running you get a fall back on a file being checked somewhere.....

Windows Server 2003 has been out now long enough for them to get their product running properly on it.

I have to be careful what I say about Sophos on here though.....

 

I told him we had lost confidence in the product so now their sending an engineer to site to have a good look at whats happening.

 

Good lord, I would not let a Sophos Engineer near a video recorder let alone a live server.....If it has got to a point in which a VERY LARGE software vendor is sending an engineer to a user / business / school or whatever, - it does not really send a message of trust to that particular vendor when its supposed to be a critical security app !! My opinion blah blah blah

 

I beleive its called customer service :) and is one of the tools that any business be it large or small can use to guage customer satisfaction etc..

 

They may also tell me that i (go forbid) have made an error with my setup and that is why i am not satisfied. After all were only human and can make mistakes without realising it.

 

I'm far more happy to receive this kind of help from a vendor who can supply it. Bet Nod can't provide that service if you were totaly stuck with their product (or many of the other vendors)

 

Like someone said on another post its not black and white.

Posted
The clients AV should do that.

 

Some AV software on clients don't scan mapped drives...

One of them was Trend's Officescan a few years back, this of course may be different now.

Posted

The debate re: on-access for servers on/off seems to boil down to just how confident you are with your infrastructure and how you lock down access.

 

If you have a rather loose network with stuff like teachers laptops that may or may not be up to date or using some other AV scanning then you'd probably want it on (and I can hear people ready to jump and say BUT..., so let me finish :))

 

... or you can have a very structured setup where anything you don't control or have tied down with AUP's (enforced ones, etc..) is locked out. Then you can afford to loosen the internal security a little... although in fairness I think even then I'd go for still retaining on-access for write processes.

 

That about sum things up?

Posted

I went to a arc distribution day the other week (karting was involved so i thought why not :p ). Anyway they had a bloke from kaspersky, they show some "independent reviews" of AV products. Based on % of Viral/spyware cuaght. Kaspersky was first, then nod32 and then sophos, then loads more with symantec at the bottom (no suprise there!!). Anyways, we have sophos on about 30 networks with about 1500 clients in total (mainly primary schools and on-access turned off as suggested by sophos).

 

We've never really had any problems. But i want to try some alternatives to see if there any better. I use nod32 at home, but not sure what there networked versions are like. Anyone have any views on kaspersky?

 

On a side note, if you do go against recommended advice from the makers of the AV, you are asking for trouble else they wouldnt of recommended it!

Posted
Odd i've found Nod32 to be an excellent light weight client it makes Symantec look laughable and their support has always been excellent when i've talked to them. The only downside is that it does take some expertise to configure compared to other packages but that’s ok when you have a well managed network.
Posted
Yes, but your server containing tens of thousands of users files should not be scanning all of them every time a request for access occurs. The clients AV should do that.

 

Agree 100% here

 

If the clients have on access sacnning - which they should have - what's the point of having on access scanning on the server where the user areas are located too? You're scanning them twice!

 

I have daily scans on the servers, and on access on the clients. With 2000+ users, 600 PC's and 20 or so servers we've never had a serious problem yet. Then again I would say that as I'm the Sophos guy at the school :)

 

Sophos is far from perfect - i have to manually delve into the sql database sometimes to remove 'errors and warnings' but thats another story - but if it's set up right and if you spend some time getting the exclusions right on the servers it works!

 

But don't have on access turned on on your file servers - or you'll have major performance issues!

Posted
what's the point of having on access scanning on the server where the user areas are located too? You're scanning them twice!

 

The point is that the client's AV may be either out of date, not working properly, not even installed possibly.

At least with on access scanning on the server you have a double layer of protection.

In an idea world and if possible, I would have a different AV product all together on the server / client just as it has been reported in the past that some AV products pick up on stuff and others miss....

Problem is that would be a bit of a nightmare to configure and manage...

 

i have to manually delve into the sql database sometimes to remove 'errors and warnings'

 

Hmmm, yes I have noticed on our server there are warnings and errors that won't allow you to clear them. Having to manually dive into the database in my opinion to clear them is quite an amazing 'feature' and does not really give me the confidence that what ever the console reports is actually true !! If there are problems with removing entries then what else is wrong ? I dread to think....

As usual - my opinion blah blah blah

Posted

I got fed up with sophos, its a real resource hog. It made most of the laptops unusable. Its a shame, the support I got was pretty good.

 

Nod 32 is working like a charm so far. 8O

Posted
Not really, it is industry practice to turn off on-access type scanning on the servers. Afterall, most servers simply contain inert content and a single daily scan will see these off. The clients SHOULD be running on-access (but with remote file checking switched off) as it is the client which will be opeing the files locally.

 

Not in the industry I work in!!

 

Not sure what kind of servers you run, but all of ours have pretty volatile content - particularly the ones which students save their files on.

 

We have all machines scanning local files - that way a file (eg) copied in from a USB stick, downloaded from the web or email gets scanned on the machine where it's being created. A file being created on a network drive is scanned on the server's local hard drive - minimising network traffic but giving a reasonable level of security.

Posted
Another nail in Sophos Coffin - my server just alerted me to a load of events in the system event log which just maxed out the CPU for 15 mins with a load of these logged:

 

The on access driver failed to check file \Device\Harddiskdmvolumes\physicaldmvolumes\Blockvo

 

A wad of entries which have caused my backup to fail and other scheduled scripts - anyone got any ideas ?

 

Have you looked at the actual file(s) it's failing to scan?

 

the only time we get errors like this is when someone sticks something like an ISO image in a folder which gets scanned or a huge zip file (eg the backup of our student SQL database is about 800Mb; in order to scan it, it has to be extracted which generates a file of about 8GB - that takes too much time so the scanner fails to check it)

 

Another possibility is that the file was in use while the scan took place - for example, if you have a backup process running then as it opens each file to back it up the virus scanner will try to scan the file. If that file can't be scanned because it's open by a user then you'll get the error shown (and you may also find that the backup fails - depends on how it deals with open files).

 

The last thing I can think of is permissions; if somehow the permissions have been changed on a file so that the account which Sophos uses can't read it then it will fail to scan it.

 

When you checked the files which failed to scan, did any of these seem like possible options?

Posted

Thanks for the advice Steve, I checked the sav.txt log [ which is now with Sophos as I am determind they tell me what caused this problem ] - nothing strange was happening on the server that it shouldn't have.

I thought about the backup too as I have a backup taking place around 11pm but the log did not show anything pointing towards this.

There are no large files [ .ISO, .IMG etc ] and the database that it does scan I stop SQL server an hour before the backup and Daily Scan.

 

When I get something back from Sophos [ which is credible ] I'll let you know.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...