Jump to content

Recommended Posts

Posted
@jamesfed - what do you do regarding AV on your VDI machines?

 

We've got Sophos on our VDIs, it updates automatically in the background (live protection) but I've only got it to do scanning on files that are being written.

 

Its largely fire and forget though as if you ever have a problem with a VDI desktop you just obliterate it and your VDI setup will create a new one.

Posted
We've got Sophos on our VDIs, it updates automatically in the background (live protection) but I've only got it to do scanning on files that are being written.

 

Its largely fire and forget though as if you ever have a problem with a VDI desktop you just obliterate it and your VDI setup will create a new one.

 

That's what i'm thinking at the moment - whether its actually worth it at all? Servers are protected using AV so if client gets one - refresh desktop job done.

Posted
That's what i'm thinking at the moment - whether its actually worth it at all? Servers are protected using AV so if client gets one - refresh desktop job done.

 

Only thing is you have to know something is up with the PC to destroy it - so you could have a virus on a VDI for up to a day (if you have nightly refresh setup) during which it could be silently collecting info about every login to the PC.

 

Its paranoia based security but hey why not :)

 

Have you seen my posts about using PCI-E SSDs? With the IO you can get out of them it makes the whole ‘well AV on VDI chews through my disk IO’ argument almost pointless.

Posted
Only thing is you have to know something is up with the PC to destroy it - so you could have a virus on a VDI for up to a day (if you have nightly refresh setup) during which it could be silently collecting info about every login to the PC.

 

Its paranoia based security but hey why not :)

 

Have you seen my posts about using PCI-E SSDs? With the IO you can get out of them it makes the whole ‘well AV on VDI chews through my disk IO’ argument almost pointless.

 

Yeah I did - I'm doing 7 VDI machines - not sure the IO is going to be to much for SAS drives! I'm no longer in education!

Posted
Yeah I did - I'm doing 7 VDI machines - not sure the IO is going to be to much for SAS drives! I'm no longer in education!

 

Ahh yeah at 7 it would probably be cheaper on SAS anyways :D

Posted
That's what i'm thinking at the moment - whether its actually worth it at all? Servers are protected using AV so if client gets one - refresh desktop job done.

 

It wouldnt help with stuff on pen drives etc.

Posted

....without AV isn't there a risk of propagating the virus all around the organisation, fair point the VM's can be recreated clean - but in theory you would have to delete all VM's at the same time to eradicate the virus...

 

...and as viruses are a definite reality, this scenario is inevitable....?

Posted

@FN-GM - this company Ban pen drives so that shouldn't be an issue (risk of data leaving site as legal firm).

@Axel - its 7 machines and if the servers are protected which are the only machines not to be rebuilt.

 

The base image wouldn't be switched on so in theory would be clean.

Posted
@Axel - its 7 machines and if the servers are protected which are the only machines not to be rebuilt.

 

The base image wouldn't be switched on so in theory would be clean.

 

Is that only 7 PCs (which are your VDIs) in the entire firm?

Posted
Yes - its for a small law firm

 

Interesting situation then!

 

I'd still be concerned about key loggers/ect though which don't 'break your PC' in any obvious way.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...