This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Server Endpoint Impacting Backup Duration

Windows Server 2012 R2 / Symantec Backup Exec 14.0

Recently migrated from Enterprise Console to Sophos Central Intercept X agent, previous backup time was around 7 / 7.5 hours before the new agent was installed. 

I have transferred the exclusions that were configured in Enterprise Console to a new Threat Protection policy and applied to the backup server but the throughput has halved and the backup is now taking 15 hours to complete. 

Removing Intercept X Endpoint and reverting back to the the previous Sophos Endpoint Protection returns the backup to previous performance so the problem is undoubtedly with  Intercept X.

Has anyone suffered similar issues and been able to resolve?

Regards



This thread was automatically locked due to age.
Parents
  • Hello Ian_W, 

    Thank you for reaching out to the Sophos Community. 

    There is a commonly used scanning feature that may be contributing to the performance issues you are experiencing, the feature is known as "Remote file scanning". Is it possible for you to try turning this feature off to see if it improves the results you are getting? It is also possible to choose to apply certain policies at set times, so that this only goes into effect when your backups are scheduled to occur. 

    I recommend applying this change on the backup server specifically so that when data is being received it will not need to be scanned in transit. 

    Another option would be to exclude the Veritas Backup software from Intercept X's scanning. This can be done by using the guidance in the following KBA.
    https://support.sophos.com/support/s/article/KB-000039185?language=en_US

    Let me know if this helps.

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
  • Hi, 

    Thank you for the reply. 

    Remote scanning is already disabled. I have added the Backup as a global exclusion for Exploit Mitigation.

    Currently, I have every element of Intercept X Agent disabled (using the Admin Sign In) and performance is still terrible, appears to be a fundamental issue with Sophos that is cannot successfully ignore safe applications.

  • even if the BE version you are using is very old, this should work with Intercept-X. Cannot report huge impacts if the exclusions are set correctly.

    There are a lot of dependencies based on you backup settings.

    Agent based? VM-based?

    Deduplication enabled? B2D?

    You will need to follow the recommendations of Veritas about AV exclusions.

    Most Exclusions will be  Process Exclusions in "Policy type: Threat Protection : Device", not Exploit Mitigation or whatever.

    Note that you will need exclusions on the BE Agent machines AND exclusions on the BE Server machine(s).

    Also you will need folder exclusions for the backup target folders if backup to disk is the type of your backup on your BE Server.

    just one part of possible exceptions for the BE Agents:

    https://www.veritas.com/support/en_US/article.100002421

    "It is recommended that the antivirus software be configured to exclude the Deduplication Storage Folder or at least by ensuring that it won't automatically delete or quarantine files in the Deduplication Storage Folder."

Reply
  • even if the BE version you are using is very old, this should work with Intercept-X. Cannot report huge impacts if the exclusions are set correctly.

    There are a lot of dependencies based on you backup settings.

    Agent based? VM-based?

    Deduplication enabled? B2D?

    You will need to follow the recommendations of Veritas about AV exclusions.

    Most Exclusions will be  Process Exclusions in "Policy type: Threat Protection : Device", not Exploit Mitigation or whatever.

    Note that you will need exclusions on the BE Agent machines AND exclusions on the BE Server machine(s).

    Also you will need folder exclusions for the backup target folders if backup to disk is the type of your backup on your BE Server.

    just one part of possible exceptions for the BE Agents:

    https://www.veritas.com/support/en_US/article.100002421

    "It is recommended that the antivirus software be configured to exclude the Deduplication Storage Folder or at least by ensuring that it won't automatically delete or quarantine files in the Deduplication Storage Folder."

Children