fiza Posted March 14, 2019 Posted March 14, 2019 What is best practice for Anti-Virus on File Servers? Should on-access scanning be disabled and a scheduled scan done every night?
Rob_D Posted March 15, 2019 Posted March 15, 2019 We do scheduled scan every night to reduce server load. And all the end-user PCs have OAS enabled so that should be scanning the shares anyway. 1
chazzy2501 Posted March 15, 2019 Posted March 15, 2019 I put in the server version of the AV program and accept the defaults. 1
Zoom7000 Posted March 15, 2019 Posted March 15, 2019 What is best practice for Anti-Virus on File Servers? Should on-access scanning be disabled and a scheduled scan done every night? Wouldn't you want on-access scanning switched on given ransomware attacks? I know the historical arguments about causing delays when opening files, but in this case it's better safe than sorry right? 1
fiza Posted March 15, 2019 Author Posted March 15, 2019 We have Sophos Central and our problem seems to be that Sophos scanning is taking up all the RAM (16GB) on the File Server which then grinds to a halt. The Scan is activating on write and on read which we thought might be the reason its hogging the RAM.
mikemcsharry Posted March 27, 2019 Posted March 27, 2019 Have you asked Sophos for any ideas? Isuspect if you put more RAM in it will eat that as well. Just trying to think this logically.. If you are scanning as the file is written, at the server level, then you're also scanning it on any modifications. If that's so then the bulk of reads are actually done by clients, so if they have on access scanning in place then maybe you don't need read at the server level. I'm not entirley sure if my logic is correct there, what does anyone else think?
TwistedHelixis Posted March 27, 2019 Posted March 27, 2019 I think we do it the other way round and disable clients from scanning network drives but have on access for any drives on the server.
CHiLL Posted March 27, 2019 Posted March 27, 2019 We have OAS disabled on the servers, with a scheduled scan every night. Our clients have OAS enabled and specifically excluded network shares from the scheduled scan.
TechMonkey Posted March 27, 2019 Posted March 27, 2019 We have OAS disabled on the servers, with a scheduled scan every night. Our clients have OAS enabled and specifically excluded network shares from the scheduled scan. This. All recommendations I have seen have said disable OAS as it could grind your server to a halt or disrupt file actions. If a client is uploading a dodgy file then it would detect it and act, rather than the server. The nightly scans are a belt and braces measure.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now