This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Web Appliance & Endpoint network traffic

My company is in the process of testing the Sophos Virtual Web Appliance being integrated with Endpoint and have run into a lack of information and was hoping someone here is running a similar setup and had some statics to share.

We are in the middle of rolling out Endpoint v10 and also purchased the Virtual Web Appliance to do logging/filtering to around 3,000 users spread out over 100+ remote sites of varying size and internet connections.  We haven’’’’t been able to find any information online or from Sophos about what type of network traffic we can expect all of these Endpoints to generate.

The most information I’’’’ve gotten from tech support is the endpoints send the logs back to the appliance once every 45seconds.  However, the size amount of traffic generated varies based on how much surfing was done, and if the site was blocked, allowed, or warned.  They have no whitepapers or information giving even a general ballpark range of network traffic the Endpoint would be sending back to the appliance for low/medium/high internet users.

I’’’’m hoping someone here has deployed the Web Appliance with Endpoint and has some data they are able to share regarding the load this puts on the network, or any issues they have had with this setup.

Thanks,

Joe

:27923


This thread was automatically locked due to age.
Parents
  • Tom - Thanks for clarifying the way the filter works.  Is any of this documented anywhere for review? 

                I’’’’m also a little curious as to why the endpoint doesn’’’’t do the filtering locally on the workstation?  It seems odd that it updates it policies at the endpoint level once every 60seconds and also verifies with the appliance every time someone goes to a website.  Wouldn’’’’t it be less network load and just as effective to have the endpoint do the heavy lifting?

                Also, can you please verify the location of the logs for windows XP systems? 

    :28287
Reply
  • Tom - Thanks for clarifying the way the filter works.  Is any of this documented anywhere for review? 

                I’’’’m also a little curious as to why the endpoint doesn’’’’t do the filtering locally on the workstation?  It seems odd that it updates it policies at the endpoint level once every 60seconds and also verifies with the appliance every time someone goes to a website.  Wouldn’’’’t it be less network load and just as effective to have the endpoint do the heavy lifting?

                Also, can you please verify the location of the logs for windows XP systems? 

    :28287
Children
No Data