This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Basic Administration For Sophos question(s)

Hello,

Before I start, be advised I am [currently] NOT a Sophos user.  I am looking for a AV/Malware system.  We have servers with a SCADA system installed to them.  My colleague suggested Sophos wsa really good for SCADA and to give it a look.  So if I say something totally wrong, bear with me.  After all, I am here to learn.

For our servers, I'm guessing we would install Intercept X for Server.  I guess Sophos Central would be installed on a central server somewhere?

For Endpoint protection, I have a need to where we would install a solution on our servers.  Ideally, each client would go back to a central server to retrieve software and virus signature updates.  Basically, we don't want clients to go back to the Internet to get what it wants.  But, we have a need to exclude some folders and files from scans/monitoring.  We need to be able to administer the client locally instead of being forced to apply a policy to all clients.

Is this possible?  We looked at some packages in the past but all of them were basically an either or approach: have the client go back to a server to get updates but the server could only administer the clients via a policy type implementation.  Or, have the client go to the Internet for updates but you get local administration control of each client.  We need a client to go back to a server to get updates but allow full administration on the local server so we can exempt specific files/folders from scans and such.

Is this possible?  Kaspersky (spelling?) allowed us to do this but we had to dump it for various reasons.

Thoughts on this?

Chris Smith

 



This thread was automatically locked due to age.
Parents
  • Hi Chris,

    Sophos Central is the cloud based management platform.  Once you have a Sophos Central account you run the installer on the computer, be it a server OS or a client OS.  The machine will register with Sophos Central, download and install the software. The software by default will download updates from the cloud (Sophos' CDN).  Messaging, for alerts/policy will go to the cloud again (AWS).

    If you have a Windows Server, that is protected, you can set it up via Sophos Central as a message relay and update cache.  The local computers will then be able to update from that cache and message to AWS (Sophos Central) via that.

    You can of course add process, file or directory exclusions.#

    Does this help?

    Regards,

    Jak

Reply
  • Hi Chris,

    Sophos Central is the cloud based management platform.  Once you have a Sophos Central account you run the installer on the computer, be it a server OS or a client OS.  The machine will register with Sophos Central, download and install the software. The software by default will download updates from the cloud (Sophos' CDN).  Messaging, for alerts/policy will go to the cloud again (AWS).

    If you have a Windows Server, that is protected, you can set it up via Sophos Central as a message relay and update cache.  The local computers will then be able to update from that cache and message to AWS (Sophos Central) via that.

    You can of course add process, file or directory exclusions.#

    Does this help?

    Regards,

    Jak

Children
  • Yeah, that response helped a lot.

     

    One finer detail to clear up.

     

    When you setup Sophos Central on a Windows Server so a local computer can go back to it, can you still setup exclusions from the console on the local computer?  Or, do you have to define some kind of policy or whatever for the exclusions from Sophos Central and push it to the specific computer?

     

    Chris Smith

  • Glad it helped. 

    Yes, all policies are defined in Sophos Central. 

    The managed endpoints check in with the AWS MCS servers to see if they have any new policies/commands. If they do they pull them down.

    In the case of a message relay being introduced, the local clients will message via that to get the policy and send the events to Sophos Central.  So the client's aren't talking directly to the Central APIs but via the relay.

    Regards,

    Jak