Jump to content

Recommended Posts

Posted

We have 17 Windows Servers, the usual mix of file servers, print servers, sims etc etc.

 

I have two physical servers for backup;

 

Server V : vRanger Backup & Replication Server which has a large D:\ drive for storing the virtual machine snapshots.

 

&

 

Server B : Backup Exec Server attached to our HP AutoLDR.

 

These servers are new since the recent half-term.

 

 

QUESTION:

 

Would you put anti-virus on these?

 

Our A/V of choice in Sophos and it's on all the other servers with on-access scanning disabled. (Clients have this turned on!)

 

I'm just concerned having A/V on these two backup servers might slow them down significantly....

Posted
I would, you can never tell what someone else might come along and do on them :doh: . We use Sophos endpoint and have just setup exclusions for certain servers but not all. Most have On-Access enabled.
Posted

In the past I have found leaving on-write worked well enough for Sophos but that was a while ago. It means nothing at least gets onto the server from say a personal laptop with a staff user on it.

I would exclude the directories/drives you backup to though.

Posted

this has got me thinking...

 

would across all my servers it be better to turn on-access to ON - but then exclude data drives so at least the OS files are being scanned in real-time...

Posted
We have AV on all our servers. On-access disabled and various recommended exclusions. A scan is set for overnight.

 

Hi, do you manually check the results of the nightly scans as I cannot see a way to be emailed the results...

 

Do your nightly scans CLEAN UP or just LOG any viruses?

I'm slightly worried about clicking CLEAN UP in case there is ever a massive false positive and random files get deleted....

Posted
I have Sophos on all my servers including Backup server , I have on-access-scanning switched off on nearly all servers. They will get scanned on schedule which I think (hope) is enough.
Posted
The only servers you shouldn't AV are your virtual hosts - or if you do, make sure you get every required exception into the anti-virus, as scanning the virtual guest folders can really drag everything down. There's some MS TechNet articles about on which folders to exclude for Hyper-V, at least, I presume VMWare have similar info available.
Posted
Sophos here install on 2 physical hosts. On access scanning enabled and behaviour monitoring enabled. In Authorization manager - nothing under authorized adware and PUAs - Sophos live protection enabled and our VM store excluded from scans.
Posted
Hi, do you manually check the results of the nightly scans as I cannot see a way to be emailed the results...

 

Do your nightly scans CLEAN UP or just LOG any viruses?

I'm slightly worried about clicking CLEAN UP in case there is ever a massive false positive and random files get deleted....

 

We get emailed of any positive matches and everything is set to quarantine. That is a concern but so is letting a virus sit there for, potentially, 2 and a half days with no action.

Posted (edited)

I'm clearly in the minority here, but I don't tend to put AV on things that don't have user data on them, or are service only servers. For example, I have 2 dc's, neither of them have AV on them because I would rather not have peering into my AD, I've had issues with AV screwing up sysvol with a false positive before.

 

My rule is, does it have user file data on it? Does it go on the internet? if neither of those conditions are true then I don't usually put AV on it.

 

Oh, and another thing... On servers that contain user data, those areas are set to clean automatically. Anywhere else I set to quarantine only and as part of mt daily backup/updates checks I also check virus scan results. Everything that has AV runs a deep scan right before the backup starts.

Edited by Oaktech
Posted

I have Forefront AV running on all servers - paranoia i guess!

However, i'm going to remove it and switch to Avast cloud (free). Anyone got this installed on a server yet?

Posted

My predecessor didn't believe in putting AV on servers either. It was one of the first things I did when he left!

 

I use ESET NOD32 File Security for Windows Server. Pretty lightweight, easy to manage and install and I've never noticed any problems.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...