This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Best Practice for On Access Scanning on MS Servers?

Have a question on the best way to handle On Access Scanning on our Windows 2003 servers.

I'm sure  I read in the sophos docs (prob a long time ago!) that On Access Scanning should be turned off on a server?

But can't find it now..... in fact the sophos KB says there are no recommendations for a server!

Is that correct?

I leave our sophos installs as default on both our PC's and servers....

(we use endpoint 9.5)

We have a problem now that I noticed when the backups run on some of our severs - using Backup Exec 12 agent, that SAVSERVICE goes to 99% and the backups take forever.

If you cancel on access scanning they fly through.

So what are peoples thoughts on this? Do you run OAS on your servers, or just run a scheduled scan regularly?

Should all our servers be in a new group with different settings?

Cheers for any advice... TED

:10007


This thread was automatically locked due to age.
Parents
  • Tedster,

    Our organization disables On-Access scanning on servers. Although it may be unadvisable, we decided to do this since we have critical processes which require applications to access a large amount of files regularly. During testing, performance improved greatly when disabling it. There is also the option to not include network location scanning, such as traffic from mapped drives or UNC paths.

    To compensate, we have elevated security on the servers in other areas, including web access and HIPS (HIPS through Sophos and another whitelisting vendor) and increased the Scheduled Scan frequency on the servers during downtime hours.

    :10049
Reply
  • Tedster,

    Our organization disables On-Access scanning on servers. Although it may be unadvisable, we decided to do this since we have critical processes which require applications to access a large amount of files regularly. During testing, performance improved greatly when disabling it. There is also the option to not include network location scanning, such as traffic from mapped drives or UNC paths.

    To compensate, we have elevated security on the servers in other areas, including web access and HIPS (HIPS through Sophos and another whitelisting vendor) and increased the Scheduled Scan frequency on the servers during downtime hours.

    :10049
Children
No Data