Jump to content

Recommended Posts

Posted

I've used Sophos on our school network for several years now and have mixed opinions about it.

 

In the central management console, loads of machines are reporting Sophos AV errors, but it's difficult to do anything about it without going to the machine and manually reinstalling Sophos.

 

Last year we had a serious virus infection running on a staff laptop and a server. Sophos detected it, but did nothing about it, causing me to stay behind for hour one evening to perform an off line Sophos AV scan to clean the server.

 

When disinfecting home systems, several time I've seen the free AVG find viruses Sophos has missed. (This was a few years ago, though).

 

I found this thread because I'm looking for a decent AV for a charity I support. Theres no consensus on a good enterprise AV solution.

 

I'm using Eset Smart Security at home, it's OK, but can't get it to play properly with home networking (have to restart it to allow ICS, and it's blocking iTunes sharing on a friend's network, despite being told not to).

 

I've given up on F-Secure and Zone Alarm at home for poor performance (typically taking 5 mins. for the PC to be usable after booting).

 

There seems to be more comments in favour of NOD32, so I'll look into that. Does it have a central management console?

Posted

Just as another slightly OT question in here... A few people have talked about products being resource intensive on downloading updates or scanning as said why this causes a problem during exams / lessons. Perhaps someone could explain why it it is being done during the day and not when people aren't using the machines. I use kaspersky at homes and schedule it foe out of hours. This seems like common sense to me.

 

Resource intensive when doing on access scans is a different problem that a few products do suffer and should be explained differently.

Posted

Our LA used to use Sophos - I can't say I ever had huge problems with it except it let through the odd thing which wasn't great

Now we use NOD32 and have had no issues with it at all

Posted

another sophos user here..

 

mixed feelings at the moment. yep it's easy to setup Enterprise Manager and deploy sophos out to clients (syncs with AD so it basically does it itself)

 

Never had any probs with it removing any nasties etc seems to do its job

 

but... I get so many errors about clients being out of date or the av on the client being 'inactive' when I can dial into one of the PCs that are showing as errors and find there's nothing wrong. I can scan (and detect dummy virus files) and I can manually pull down updates.

 

I also have about 20 clients - different models of pc in different parts of school that won't auto update each morning. I have to select > right click > update. No idea what's going on. Emails sent to Sophos don't even warrant a reply. Sophos are useless with support in my experience.

 

It also does spank the CPU. Never had a 100% cpu since the old 'intercheck' sophos days but it regularly does hit 45%-50% cpu. Updates are scheduled for each morning and a client scan is performed at lunchtime.

 

One last rant about sophos... the error codes / knowledge base articles are a pile of cack. Some of the error codes I've had don't even have an entry on the sophos KB :eek:

 

It's now got to the stage where if I cant reinstall sophos back onto a client within 15 mins I just reimage the client and redploy. I can't be arsed to piss about with Sophos any more.

 

If I could look into using another AV I would but we're tied to it as its LA provided.

 

btw the stand alone version of Sophos is v good in my experience. I use it at home and I install it on 'home use' laptops fro staff - no issues with it all :)

  • Thanks 1
Posted
btw the stand alone version of Sophos is v good in my experience. I use it at home and I install it on 'home use' laptops fro staff - no issues with it all :)

 

So a network of standalone computers it is then. :D

 

I feel I know how Sophos works so I know how to work with it. I also know how I would like Sophos to work; how it could be better. However it currently is what it is (a strong player in computer security) and, I feel, it's getting better all the time - the HIPs protection really helps with Conficker.

 

I get the sense that because the LEA buys a lot of Sophos licences and hands them out to lots of schools quite a few comments here are from members who feel trapped and therefore resentful. And if Sophos offer a good price, a competitive price, it's seen as cheap and nasty.

 

To all I ask...

 

Are you making sure you're planning deployments and pro-actively calling their support to get advice? Do you have a test environment that mirrors (blemish for blemish) your production environment? Have you read all the .pdf files for all the products they run? Have you considered asking Sophos to visit your site for consultancy and best practice?

Sophos case study - Hamilton College

Sophos Professional Services - maximizing your return on investment

Have you seen the whitepapers available on Sophos' website https://secure.sophos.com/security/whitepapers/index.html Have you all subscribed to their email notifications Sophos email notification

 

I'm sure I'm in for some hot replies. Please believe me it's not my intention to provoke people. Instead just lean back from the keyboard for one minute (go on, do it) and think about the last time you truly planned, tested, refined, tested, refined, sort approval from Sophos and then deployed in a phased rollout - monitoring as you go. If any abnormal effects are then seen you can pause and review.

 

Honestly - don't hate me! It's just nice to debate. Isn't it...? :p

  • Thanks 1
Posted
Just got rid of sophos in favour of CA eTrust as our LA provides it for free to us, or we'd have had to buy a new license for sophos this year.

 

Sophos is very resource heavy, and can be very unhelpful when it tells you 'yes, you are infected, no, i didn't stop it or remove it for you'.

 

 

A Bit like CA eTrust then with Spyware lol We have it and i hate it, biggest load of crap i ever bought! Just had a technology guy ring me saying his machine is riddled with Spyware and CA didnt even detect it. Hes not a normal user either, quite experienced and very security concious. the management side of CA is over complicated and the deployment tool is very basic, no tracking of which machines have it installed and which ones dont except for a list you maintain yourself

Posted
So a network of standalone computers it is then. :D

 

I feel I know how Sophos works so I know how to work with it. I also know how I would like Sophos to work; how it could be better. However it currently is what it is (a strong player in computer security) and, I feel, it's getting better all the time - the HIPs protection really helps with Conficker.

 

I get the sense that because the LEA buys a lot of Sophos licences and hands them out to lots of schools quite a few comments here are from members who feel trapped and therefore resentful. And if Sophos offer a good price, a competitive price, it's seen as cheap and nasty.

 

To all I ask...

 

Are you making sure you're planning deployments and pro-actively calling their support to get advice? Do you have a test environment that mirrors (blemish for blemish) your production environment? Have you read all the .pdf files for all the products they run? Have you considered asking Sophos to visit your site for consultancy and best practice?

Sophos case study - Hamilton College

Sophos Professional Services - maximizing your return on investment

Have you seen the whitepapers available on Sophos' website https://secure.sophos.com/security/whitepapers/index.html Have you all subscribed to their email notifications Sophos email notification

 

I'm sure I'm in for some hot replies. Please believe me it's not my intention to provoke people. Instead just lean back from the keyboard for one minute (go on, do it) and think about the last time you truly planned, tested, refined, tested, refined, sort approval from Sophos and then deployed in a phased rollout - monitoring as you go. If any abnormal effects are then seen you can pause and review.

 

Honestly - don't hate me! It's just nice to debate. Isn't it...? :p

 

nope, having used it for years I have to say its cack for the reasons mentioned above....

 

we can pause, review a 'blemish', scratch our heads, consult the sophos KB only to be prompted with 'error code not found', or some bollocks about a deployment timing out because of a slow network connection even though its being piped over a gig switch.

 

perhaps sophos is optimised for deployment on a large hadron collider :)

 

how can any software vendor code into their software error codes and then can't be arsed to have any reference to them on their KB?

 

I have to say sophos KB is as about as useful as capita supportnet :) ...

 

other than that sophos is wonderful :)

Posted (edited)
Just as another slightly OT question in here... A few people have talked about products being resource intensive on downloading updates or scanning as said why this causes a problem during exams / lessons. Perhaps someone could explain why it it is being done during the day and not when people aren't using the machines. I use kaspersky at homes and schedule it foe out of hours. This seems like common sense to me.

 

Resource intensive when doing on access scans is a different problem that a few products do suffer and should be explained differently.

 

My machines update signatures every hour, and do a full scan once a week (out of hours, and if turned on).

 

Signatures really do need updating several times a day now, in the old days it was once a month!

 

24 hours really is a long time in security terms though!

Edited by DMcCoy
Posted

I think I've already said it but I'll repeat the most annoying aspect about Sophos...

 

It's the total lack of regard the code writers had for things like packet loss or slow network while ensuring that Sophos has the highest priority and won't let the computer "go" until it completes a task like a signature update or similar.

 

The combination of the two results in lock ups and freezes which just make it completely un-usable.

  • Thanks 1
  • 2 months later...
Posted
We moved away from Sophos as it was causing us all kinds of issues. We now run Forefront Client Security. It's cheap, not resource hungry and very quick at removing threats.
Posted

We have been running Symantec for years, and are in the process of switching to a new product. SAV 10 had many flaws, SEP11 is terribly bloated, unreliable, complex, and causing many problems for other programs.

 

It looks as though we will be switching to MS Forefront. Have a trial setup in 2 schools, very impressed so far. Workstations are much faster at everything with Forefront (compared to Symantec), and users at those schools have noticed the huge difference and are very pleased.

 

As well, I really like the way it integrates with our existing technologies (AD, policy management, WSUS). Price is fantastic too.

Posted

I used to hate sophos, but I quite like it now.

We have it on our servers and it runs fine.

We have McAfee provided by the LA, but it is total crap - made even worse by the fact we have no access to the management console (we can't have VNC installed anywhere as it is classed as malware ffs).

I refuse to install anything as rubbish as McAfee (which, IMHO, is only fit for home PCs not schools, business, etc) on our servers.

I don't find Sophos is resource hungry

Posted
I used to hate sophos, but I quite like it now.

We have it on our servers and it runs fine.

We have McAfee provided by the LA, but it is total crap - made even worse by the fact we have no access to the management console (we can't have VNC installed anywhere as it is classed as malware ffs).

I refuse to install anything as rubbish as McAfee (which, IMHO, is only fit for home PCs not schools, business, etc) on our servers.

I don't find Sophos is resource hungry

 

There are many that would argue that it is not even fit for Home use. :D

Posted

I am currently running SAV 10.1 on our PDC and clients, and although i have tried the new endpoint MR4 i will be sticking with sav10 when i 're-do' the server this holiday, as i find endpoint to be far too much of a home product, rather than a corporate one. I still put endpoint on the teacher laptops, but those usually stay at home anyway.

Still come licence renewal i will definately be looking for a replacement for endpoint.

I have had no real issues with symatec 10.1 though, its been the best for me.

:)

  • 4 weeks later...
Posted

So from these posts and for the network here, NOD32?

 

All other AV mention has had a good comment followed by several bad comments... and NOD32 seems to just get the +++

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...