steveg Posted September 13, 2022 Posted September 13, 2022 Since September I have had an number of computers (about 5 so far) that have serious issues with network speed at random times. I thought at first it may be cabling issues, but there are too many of them on different parts of the network / different switches. It's not server issues, as other computers work fine at the same time. It appears to be predominantly when accessing network shares, the speed of the connection can drop to only a few kb a second, or completely stop so files cannot be opened. Most of the time you can browse the internet at the time and downloads even still work without issue. One computer I seem to have resolved by updating network and other drivers, but may just have been a coincidence that it got better. There are at least 2 different models of Dell computer that is affecting so far. I will start stripping off Virus scanners (sophos) and other apps like Senso to see if this makes any difference, but any other suggestions are welcome!
siuko Posted September 13, 2022 Posted September 13, 2022 Once you mentioned Sophos and Senso I knew it was the same as our issue https://support.sophos.com/support/s/article/KB-000044418?language=en_US It is an incompatibility with Sophos and Senso with relation to Windows WFP We have currently had to disable the senso wfp to get things back to normal (I believe senso provide a script to use) 1
Koldov Posted September 13, 2022 Posted September 13, 2022 (edited) There was another thread about this... Gets interesting for you about here: http://www.edugeek.net/forums/security/228753-sophos-antivirus-intercept-erroneously-blocking-continuous-multiple-file-transfers-2.html#post1964014 It appears to be resolved by turning off parts of Sophos, but that isn't a long term fix and turning off parts of Sophos probably isn't recommended... It may also have affected Senso, SIMS deployments, PDQ Deploy and Follow-me, Lightspeed Relay and also SCCM deployments, file transfers, OneDrive/O365 downloads and other software like Target Tracker. Edited September 13, 2022 by Koldov 1
steveg Posted September 13, 2022 Author Posted September 13, 2022 Thanks! Good to know what it is, not so great to know that there isn't a proper fix yet and we have to disable parts of Senso to make it work! https://support.senso.cloud/support/solutions/articles/79000133634-sophos-core-agent-2022-x-and-senso-cloud-windows-agent It does say on here: Sophos have supplied further information which appears to allow our product to be re enabled: Please disable SntpService (Sophos Network Protection) in your services - You will need to disable tamper protection before you are able to disable this service Testing with our customers these changes appear to allow functions of Senso and other affected 3rd parties to be re enabled! We are still monitoring - With this element of Sophos disabled, you will not require any changes to our product! Just wonder how much of a security risk disabling this service is, and am i better of still disabling part of Senso?
Cat_Jam148 Posted September 13, 2022 Posted September 13, 2022 I decided to run the command and disable part of Senso I'd rather have Sophos running at full strength
siuko Posted September 13, 2022 Posted September 13, 2022 Disabling the senso bits you lose things like broadcasting etc which in a school is a bit of an issue Our central MAT team choose that rather than a less secure Sophos
steveg Posted September 13, 2022 Author Posted September 13, 2022 Does sound like the better way to do. Does keyword monitoring still work?
Guest Posted December 14, 2022 Posted December 14, 2022 Has anyone upgraded to the new Sophos update 2022.3 ? has this made any difference?
Stringent Posted February 23, 2023 Posted February 23, 2023 Hi It did, then something else went awry and it messed up again. We are currently on Sophos Version 2022.4.2.1 for clients and it now seems to be OK, although Senso now has another issue with Fast User switching where the Internet Browser just doesn't work for another logged in user. Has proliferated to our RDS too (Now on Windows 2022 Server). Senso are aware of a fast user switch issue (have disabled it for now on clients, cue complaints!), but didn't think it expanded to Server. Had to remove it off the server, not going to remove Sophos for obvious reasons to test it out.
Guest Posted February 24, 2023 Posted February 24, 2023 Thanks for the info. i'm not totally convince the issue has been resolved since our sophos updated to 2022.4.1.1, im more leaning towards it being more Senso than Sophos
Stringent Posted February 24, 2023 Posted February 24, 2023 Companies are quick to blame others. I think Sophos did change their scanning method last year which led to issues, our PDQ took a massive hit as well. But this has mostly been resolved and I am seeing better transfer rates than I used to. Debating to fire up my old Heimdal Trial on the Remote Desktop JUST to rule out Sophos. It was fine on our old 2016 RDS server so I am also wondering if Microsoft have done something in an update as well which has messed Senso up.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now