This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Low Spec devices failing to update.

We have a problem with Sophos AV on an increasing number of (slow) Windows Tablets - currently we have 40 in Error state (not up to date)

Also - I am starting to see an increasing number of laptops with the same problem

They are not left running for long enough to collect the full AV signature files from Sophos and constantly end up in the Protection Error box in the Enterprise console

It could not be, simply the size of the update signature files (only around 50kb) or slow connection (we have a 75+Mbps fibre connection - so am wondering whether anyone else has the same issue ?

The overall installation package requirements seems too large - I don't think that Sophos was designed for low spec / low resource tablets

Is there some way to reduce this requirement, through installation options - without reducing the effectiveness of the protection ?

On my Desktop, Sophos uses about 40Mb RAM - Just sitting there doing nothing !

What size is the download of Sophos Endpoint ?

I know that Sophos home is about 250Mb !

Our tablets download the updates via the console - is there an option to do otherwise on a particular set of devices with Sophos - NOT the whole lot (we have 500 + normal PC`s as well)

They are Linx (so low spec) - 2Gb RAM - running a minimum set of progs - mainly office 365 and a few low resource educ utilities

They are used, mainly by students for web browsing / email.

They tend to be used once in a blue moon and spend 95% of their time - sitting in a secure cabinet - so are unable to connect most of the time !

Is there any way that a group can be set up to download updates direct from Sophos.com - rather than our server - but just for the tablets (our 500+ normal PC's update OK - but they are left running all day !)

Would this improve matters ?

We are currently looking at all of our options - including WEBROOT - Which appears to be much more suitable for our needs than Sophos (with whom we have remained for over 6 years)

Thanks



This thread was automatically locked due to age.
Parents
  • Hello Weeboo,

    the System Requirements article states 2GB RAM and two cores as minimum. This doesn't guarantee lightning performance as there are other factors, architecture, chipset, type of RAM, disk to name a few.

    An update starts with an update check - first comparing the local cache's catalogs with the update location, if there's a difference synchronization will be performed. This is not only the download but also implies verification of the local cache and a recalculation of the hashes. For the SAVXP component this takes just a few seconds on a decent machine with an SSD but considerably longer on a low-end system. For a major update (not only the addition of a few IDEs) an uninstall and reinstall has to be performed, this again will take several minutes. The size of the update is not the deciding factor here. Also it doesn't matter whether the updates are from the local server or from Sophos - actually it does matter and the latter is expected to take longer as the download speed is lower and additional computation is required for a "warehouse" update.

    You can control major software updates by using fixed versions but you can't schedule the (roughly monthly) detection data (VDL) updates which also require a major update. Thus the devices have to be switched on for a adequate amount of time, one hour should be sufficient.

    Christian   

  • Why has nobody even suggested Sophos Cloud as a possible solution to our current problems ?

    I would have thought that it was a cert ?

  • Hello Weeboo,

    it was a cert
    you've lost me here - what's a cert in this context?
    Anyway, I can't see how Central (Cloud) would help as the Endpoint software is basically the same and not some thin client.

    Christian

  • "Cert" - is a phrase implying "Certainty"

    And I believe that using the Cloud - uses less resources on each individual device - which "should" help with the installation and update issues that we are still having ??

  • Hello Weeboo,

    thanks.
    the Cloud - uses less resources
    I might be wrong but I don't think so. As said, the actual endpoint software (AKA SAV) is the same, any updates have the same size as for the on-premise version. The communication system (MCS) is similar to RMS (actually it "talks" to management more often than RMS). Additional components differ but compared to the on-premise SESC the Central Cloud Agent isn't lightweight.

    Christian

  • QC said:

    Hello Weeboo,

    thanks.
    the Cloud - uses less resources
    I might be wrong but I don't think so. As said, the actual endpoint software (AKA SAV) is the same, any updates have the same size as for the on-premise version. The communication system (MCS) is similar to RMS (actually it "talks" to management more often than RMS). Additional components differ but compared to the on-premise SESC the Central Cloud Agent isn't lightweight.

    Christian

     

    Thanks Christian,

    You have been very helpful - we will have to decide what the way forward is.....

  • One of my work collegues had an on-line chat with Sophos support (Maddy) who told him :

    "If you already have AV and it is too heavy you can look at an MDM solution.
    or you could route all traffic through a small XG firewall or SG to reduce footprint on device"

    How is this actually achieved ?

    We have tried MDM before (Meraki) - but found that it was too difficult to use - so gave up on it

    Are you saying that Sophos operates an MDM system ?

    If so - why would that help ?

    And how does it actually work ?

    Sorry - so many questions ...

  • Hello Weeboo,

    I have no experience with this product line. But see the Sophos Mobile product page.

    Christian

  • QC said:

    Hello Weeboo,

    I have no experience with this product line. But see the Sophos Mobile product page.

    Christian

     

    Why was I not even aware of Sophos mobile ?

    It is almost as if Sophos didn't want to advertise the fact that Sophos mobile existed ?

    I have asked for more details/pricing etc....

    Since we already have a contract for Enterprise and have done for many years - I assume that mobile will be a "no charge" addon ?

    Thanks

  • Hello Weeboo,

    I'm not Sophos and not a partner or of that ilk. But just go to your Downloads page and see what's available. Can't tell what you see.

    Christian

Reply Children
No Data