TwistedHelixis Posted December 19, 2016 Posted December 19, 2016 Hello, I have just been informed that I will need to replace our old McAfee virus software with Sophos endpoint. Our LA get us the license cheaper (bulk) but will not help me install it. Our LA have said the Mcafee licence expires next week, so I have very little time to learn this new system. I have been given a username / password for the online Sophos control but have no instructions. I know I could visit Sophos forums etc but know that a few edugeekers use Sophos, so thought I would make this my first stop. I am not concerned at the moment with installing Sophos on to the clients, only the server. Are there any major changes I need to make to the server installer software before deploying on to my server or is the Sophos base server installer setup with good base settings.
speckytecky Posted December 19, 2016 Posted December 19, 2016 I'd give Sophos support a call. I have found them incredibly helpful in the past and as they are capturing you from one of the biggies I wouldn't be surprised to find they are very keen to help you as well. Is it the terrestrial or cloud version you have been given? Ours is currently the Enterprise Console but I'd love to move over to their cloud based version to take advantage of their Intercept X anti ransomeware tool.
TwistedHelixis Posted December 19, 2016 Author Posted December 19, 2016 We have been given the cloud version.
kennysarmy Posted December 19, 2016 Posted December 19, 2016 Hello, I have just been informed that I will need to replace our old McAfee virus software with Sophos endpoint. Our LA get us the license cheaper (bulk) but will not help me install it. Our LA have said the Mcafee licence expires next week, so I have very little time to learn this new system. I have been given a username / password for the online Sophos control but have no instructions. I know I could visit Sophos forums etc but know that a few edugeekers use Sophos, so thought I would make this my first stop. I am not concerned at the moment with installing Sophos on to the clients, only the server. Are there any major changes I need to make to the server installer software before deploying on to my server or is the Sophos base server installer setup with good base settings. Not sure what you mean "make changes to the server installer software" .... You just install the SEC (Sophos Enterprise Console) which is used to download and then track the client installs etc.
TwistedHelixis Posted December 19, 2016 Author Posted December 19, 2016 Not sure what you mean "make changes to the server installer software" .... You just install the SEC (Sophos Enterprise Console) which is used to download and then track the client installs etc. What about protecting your servers (not clients) and all the exclusions etc that Microsoft recommend? I had a look around the online console and have found a section called policies / server. This looks like the place I can add folder exclusions etc. I was told by the LA that I would not need to make many changes but under the exclusions section nothing is listed, which I find a bit odd, as Microsoft list a load of exclusions needed for virus software on a server.
kennysarmy Posted December 19, 2016 Posted December 19, 2016 (edited) What about protecting your servers (not clients) and all the exclusions etc that Microsoft recommend? I had a look around the online console and have found a section called policies / server. This looks like the place I can add folder exclusions etc. I was told by the LA that I would not need to make many changes but under the exclusions section nothing is listed, which I find a bit odd, as Microsoft list a load of exclusions needed for virus software on a server. I've got real-time scanning turned off for my Servers. Once installed just create a Server and Computer policy which you can then "tag" to your groups. I do it manually in that I created the groups in the console and then sync. them with the AD groups. I'll get you a screenshot - hold on. I've also got Application policies in place to stop certain software from running as an extra precaution even though we have SRP and Applocker on Windows 10 Edited December 19, 2016 by kennysarmy
Davit2005 Posted December 19, 2016 Posted December 19, 2016 Give Sophos a call, as others have said they are helpfull. They have guide for a startup script which we used to deploy the client, we did initially use OU sync to install but that would not allways install. Setup OU sync still so it matches your AD structure but do not have it auto install AV, do that with the startup script., that way you can have different policies for HIP in different areas if need be. I had specific OU's for servers that had exclusions for instance and for those such as file servers didn't need exclusions. Doing a C scan seemed to slow the PC's down but you could leave that on with servers, setup exclusions for any server processes according to guidelines. I'd also set up a second repository if you have a number of clients, so clients do not attempt to download updates directly from Internet or turn off the secondary update settings if possible. Setting up a secondary repository is'nt too difficultto do
kennysarmy Posted December 19, 2016 Posted December 19, 2016 Give Sophos a call, as others have said they are helpfull. They have guide for a startup script which we used to deploy the client, we did initially use OU sync to install but that would not allways install. Setup OU sync still so it matches your AD structure but do not have it auto install AV, do that with the startup script., that way you can have different policies for HIP in different areas if need be. I had specific OU's for servers that had exclusions for instance and for those such as file servers didn't need exclusions. Doing a C scan seemed to slow the PC's down but you could leave that on with servers, setup exclusions for any server processes according to guidelines. I'd also set up a second repository if you have a number of clients, so clients do not attempt to download updates directly from Internet or turn off the secondary update settings if possible. Setting up a secondary repository is'nt too difficultto do We've never had any issues with the clients installing automatically.....it removes any other A/V software, installs and updates itself.
Davit2005 Posted December 19, 2016 Posted December 19, 2016 We've never had any issues with the clients installing automatically.....it removes any other A/V software, installs and updates itself. We mostly had issues when re-imaged 25+ PC's at once, it was like the enterprise server couldn't cope. The script is much simpler, it checks for a file and if there backs off, had the script method running for approx 2 years no issues :-).
mavhc Posted December 19, 2016 Posted December 19, 2016 You can have multiple places to store the updates, I use DFS to map one server for each site, but don't replicate, using ESM to send to all 4 locations. Only issue I have with AD sync is it tries to install at the same time as other windows updates, and then fails and never retries
mukz Posted December 19, 2016 Posted December 19, 2016 Ours is currently the Enterprise Console but I'd love to move over to their cloud based version to take advantage of their Intercept X anti ransomeware tool. Intercept x works with the enterprise console, obviously doesn't give all the advanced reports due to the way sophos are now going with their sophos central linking all their products so they all work as one. Do you have Intercept X? IMO this piece of a software is a godsend!
kearton Posted December 19, 2016 Posted December 19, 2016 I was under the impression InterceptX required Sophos Cloud? Others have mentioned installing SEC but you don't use this with the Cloud version, which the OP has said he's got...
Stormborn15 Posted December 19, 2016 Posted December 19, 2016 I've just been given the username and password for the cloud version of sophos ... will be having a go at installing in January. Would be good to compare notes ...
mukz Posted December 19, 2016 Posted December 19, 2016 I was under the impression InterceptX required Sophos Cloud? Others have mentioned installing SEC but you don't use this with the Cloud version, which the OP has said he's got... Nope, it works in addition to SEC. Having Sophos Cloud allows you to do the more reporting functionality alongside root cause analysis.
eddyc Posted December 19, 2016 Posted December 19, 2016 We've just bought intercept X two weeks ago and were forced to move to the cloud offering as we were categorically told by both SWGFL and Sophia that Intercept X cannot be used with on premise Sophos Enterprise Console. But if a pain to uninstall and reinstall on all devices but it's done now and I'm more than happy with it
mukz Posted December 19, 2016 Posted December 19, 2016 We've just bought intercept X two weeks ago and were forced to move to the cloud offering as we were categorically told by both SWGFL and Sophia that Intercept X cannot be used with on premise Sophos Enterprise Console. But if a pain to uninstall and reinstall on all devices but it's done now and I'm more than happy with it Really!! When the chap from Sophos, John something who is the product manager said we don't need cloud. Oh well. The Cloud Version is much better anyway.
kennysarmy Posted December 20, 2016 Posted December 20, 2016 Can you install Intercept X on your Servers or does it just protect local files on endpoints?
kennysarmy Posted December 20, 2016 Posted December 20, 2016 Really!! When the chap from Sophos, John something who is the product manager said we don't need cloud. Oh well. The Cloud Version is much better anyway. See from 45:14 ish 1
eddyc Posted December 20, 2016 Posted December 20, 2016 Can you install Intercept X on your Servers or does it just protect local files on endpoints? At the moment it only protects your endpoints. We tried to install the Intercept X client on a server but it just installed the regular Endpoint Protection Product (old logo and all!).
mukz Posted December 20, 2016 Posted December 20, 2016 See from 45:14 ish Looks like John Shaw VP of Product Management has told us the future! sorry for confusing everyone. He just replied back to me, Intercept X will soon be coming to SEC. I have mentioned that it could be mistakenly during our meeting.
TwistedHelixis Posted January 4, 2017 Author Posted January 4, 2017 OK, installed on all my servers so now looking at settings for my clients. Do you have scan local & remote enabled which is the default or just local?
TwistedHelixis Posted January 4, 2017 Author Posted January 4, 2017 Also does the scheduled scan use the same settings from the local / remote scan settings? or does it just do a local scan? Currently the server is set to scan any accessed files, does that include files accessed from clients? Just don't want the same file to be scanned a billion times each time it is accessed.
TwistedHelixis Posted January 4, 2017 Author Posted January 4, 2017 For the moment I have set scanning to local only in both the client and server profiles.
kennysarmy Posted January 4, 2017 Posted January 4, 2017 On access scanning is disabled on ALL my Servers...as the clients are set to do real-time scanning - there is no need to do it twice in my opinion. 1
TwistedHelixis Posted January 4, 2017 Author Posted January 4, 2017 On access scanning is disabled on ALL my Servers...as the clients are set to do real-time scanning - there is no need to do it twice in my opinion. So are the clients set to do local and network scanning?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now